---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Deferring findings automatically without manual intervention using exception rules

# Deferring findings automatically without manual intervention using exception rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Deferring findings automatically without manual intervention using exception rules

ServiceNow's Security Exposure Management Workspace offers exception rules that enable automated deferral of security findings without manual intervention.
These rules help manage findings that cannot be remediated or deferred immediately by identifying impacted vulnerabilities, configuration items (CIs), or vulnerability instances (VIs) and automatically deferring matching findings.
This automation helps maintain compliance with service level agreements (SLAs) and simplifies managing multiple findings.
Show full answer Show less  

## Key Features

* **Automated Deferral:** Exception rules automatically defer new and existing findings that meet defined criteria for a specified period, reducing manual work.
* **Rule Prioritization:** Deferral rules are ordered by priority; the highest priority rule is applied first and blocks subsequent rules from applying to the same finding.
* **Exception Rule Lifecycle:** Includes creation, approval, activation, deferral period management, and expiry.
* **Two-Level Approval Process:** Exception rules require approval, which can be single- or two-level depending on approver availability. Change Approval (CA) records are created during submission to ensure traceability.
* **Impacted Findings Metric:** Before approval, users can view how many findings are affected by the rule and inspect detailed matching findings to assess rule impact.
* **Activation and Execution:** Rules begin running on the "Valid from" date, evaluating both new findings and reopened findings. An option exists to execute the rule once on existing data at activation.
* **Deferral Period and Expiry:** Findings matching the rule conditions are deferred until the "Deferred until" date, after which associated remediation tasks close and findings revert to open state. Expired rules no longer apply to new or reopened findings.

## Practical Benefits for ServiceNow Customers

* Automates deferral workflows, improving efficiency by reducing manual approvals and interventions.
* Helps maintain compliance and SLA adherence by ensuring timely and consistent handling of exceptions.
* Provides visibility into the impact of exception rules via metrics and filtered findings lists, aiding informed decision-making.
* Supports governance through a structured approval process integrated with Change Approval workflows.
* Enables orderly management of exception rules with lifecycle tracking and prioritized rule execution.  
Exception rules for Security Exposure Management Workspace enable you to automate the deferral process for findings. Request an exception for the findings that can't be remediated or deferred immediately, by identifying the impacted vulnerabilities, configuration
items (CIs), or VIs. Defer the matching findings based on the rule when the system identifies them by automating the finding deferral process.
Using exception rules in your organization

Use exception rules to automatically defer new and existing findings for a specific period if they match the approved rule condition. Automation minimizes the risk of missing service level agreements and makes it easier to manage
multiple items, because you're eliminating manual intervention.

Deferral rules support ordering, that is, the rule with the highest priority is run first. When a high-priority rule is applied on a finding, no subsequent rules are applied on it again even if the condition matches the
Finding.  
The life cycle of an exception rule is as follows:

* Creating an exception rule
* Approving an exception rule request
* Activating an exception rule
* Deferring an exception rule
* Expiry of an exception rule
{#sem-exception-rules-overview__ul_mhc_1nn_2nb} Creating an exception rule

You can create an exception rule to automatically defer the findings that match the defined conditions for the specified period. After you create an exception rule, submit it for approval.
Approving an exception rule request  
Approving an exception rule request is a two-level process. If only the first-level approver is present, the exception rule can be assessed and approved by a single approval. However, if there's no first-level approver, an exception rule approval can't be approved. See [Approve an exception rule request](https://servicenow-prod.fluidtopics.net/dS91BM2DIyB2r2TsHhkCEQ "Assess exception rule requests from users so that you can approve or reject these requests.") for more information.  
Note:  
The Change Approval (CA) is now also created during exception rule submission. This enhancement ensures consistency across exception workflows and improves traceability.  
When you review an exception rule request, you can view the Impacted findings metric, which shows how many existing findings match the rule's conditions as of the last calculated time. Use this metric to assess the impact of the rule before approving or rejecting the request. Select the count to view a filtered list of matching findings or select Refresh to recalculate the count.  
Note:  
The Impacted findings count may change over time as the active exception rule continues to evaluate findings.  
After an exception rule request is approved, you can perform the following actions:

* Cancel
* Delete
{#sem-exception-rules-overview__ul_h32_y22_4lb} Activating an exception rule  
Starting from the "Valid from" date, the exception rule runs on all the findings that are created and also on the ones that are moved from the Closed to the Open state.  
Note:  
If you enable the Execute on existing data option, a scheduled job runs once on the existing data on the "Valid from" date. Deferring an exception rule

You can defer findings that match the conditions defined in this exception rule, up to the "Deferred until" date that is defined for the rule. On this date, the remediation task that you created for the exception rule is closed and
all the findings in this group move back to the Open state.
Expiry of an exception rule

After the exception rule expires, it no longer runs on new or reopened findings.
**Related concepts**   

* [Configuring an exception rule](https://servicenow-prod.fluidtopics.net/80ILX3SZYShJ8Pt106ZVWg "You can request an exception for findings that can't be remediated or deferred immediately. By automating the finding deferral process, you can defer the matching findings based on the rule when the system identifies them.")

