---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# GRC request exception form fields

# GRC request exception form fields {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The following table shows the field descriptions for the GRC request exception form.
{#vr-ws-grc-request-ex-fields__table_fml_xt3_fwb__entry__2}

| Field | Description |
|-|-|
| Policy | Vulnerability Management policy that you're requesting an exception for. |
| Control objective | Control objectives that are associated with the policy that you selected. If a policy isn't selected, all the control objectives are listed. |
| Valid from | Date when the exception starts. The default value is the current date. This date can't be in the past. |
| Valid until | Date that the policy exception expires and the state of the vulnerable item or group changes from Deferred to Open. Note: The number of days that the policy exception is valid can't exceed the Maximum exception duration (days) that you set for the policy in Policy and Compliance. For more information, see [Create a policy](https://www.servicenow.com/docs/access?context=t_DefineAPolicy&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US). |
| Reason | Reason for requesting an exception. |
| Justification | Details that are related to the reason why this request is being made. This field must be filled in by the remediation owner. |
[Table 1. Request Exception form]

{#vr-ws-grc-request-ex-fields__table_fml_xt3_fwb}

