---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Define policy exception verification rules

# Define the policy verification rules {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Configure granular approval rules for policy exceptions and extensions by using the GRC Approval Configurator. This allows you to manage approvals with precise rule definitions and support multi-level
approval workflows.

## About this task

Verification rules validate policy exception or extension requests before they proceed to review or approval. These rules are configured using the Verification Configuration template, allowing you to define conditions based
on status, sub-status, and other filters. When a policy exception is created, it enters the New state, triggering verification approvals. Upon successful verification, the request advances to the Analyze state for further
evaluation.

## Before you begin

Role required: sn_compliance.manager to create the policy verification rules.

## Procedure

1. Navigate to AllAssignment and Approval ConfigurationsApproval Configurations.  
   The GRC Approval Configurator is shipped with default template for verification called Policy Exception - Verification Config.
2. Select Policy Exception - Verification Config.
3. On the form, fill in the fields.  
   {#define-policy-exception-verification-rules__table_klc_gq4_plb__entry__2}

   | Field | Description |
   |-|-|
   | Priority | By default, the verification configuration is set with priority 1. Note: The verification configuration is set to priority 1 by default and should be retained to ensure initial verification approval before |
   | Filter Condition | Filter conditions to define when the configuration should be activated. The available values are sourced from the Policy Exception table. By default, State is set to New. This is a mandatory condition. You can set other filter conditions as well. Use logical operators such as AND or OR to build complex condition sets. |
   | Domain | Functional group or role that should be associated with the approval flow. |
   | Applies to | Verify that the Policy exception (sn_compliance_policy_exception) option is selected. |
   | Active | Option to enable the configuration. |
   | Name | Name of the verification configuration. By default, the template name is Policy Exception - Verification Config. You can change the template name. |
   [Table 1. Verification Configuration form]

   {#define-policy-exception-verification-rules__table_klc_gq4_plb}
4. Add approval levels to the configuration in the Approval Levels table.  
   A default approval level called Verification Config - Level 1 is already set up. You can add multiple levels for the configuration. Each level can have its own rules, assigned users or groups, and triggering conditions.
5. Select Verification Config - Level 1.
6. On the form, change the following fields:  
   {#define-policy-exception-verification-rules__table_zgr_qyx_rgc__entry__2}

   | Field | Description |
   |-|-|
   | Name | By default, the name provided is Verification Config - Level 1. You can retain the same name or change the name. |
   | Level | Keep the level as 1, as this is the first level that we are configuring. |
   [Table 2. Verification Level form]

   {#define-policy-exception-verification-rules__table_zgr_qyx_rgc}
7. Select Submit.
8. Add additional approval levels to the configuration by selecting New in the Approval Levels table.  
   {#define-policy-exception-verification-rules__table_wmb_jzx_rgc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Provide a name to the new level. |
   | Level | Assign the level. |
   [Table 3. Verification Level form]

   {#define-policy-exception-verification-rules__table_wmb_jzx_rgc}
9. Select Submit.  
   After adding the required approval levels, add verification rules to each level.
10. To add verification rules, select the configured verification level, and do the following:
    1. In Approval Rules, select New.
    2. On the form, fill in the fields.  
       {#define-policy-exception-verification-rules__table_ecj_kkz_bgc__entry__2}

       | Field | Description |
       |-|-|
       | Name | Name for this rule. |
       | Description | Description for the rule. |
       | Source | Source table for rule evaluation. |
       | Additional condition | Option to refine the source table by applying additional filters. |
       | Query using field | Field on the source record to query for matching approval conditions. |
       | Approve type | Approval type options: * Specific approvers: Select individual users, groups, or both as approvers directly. This option enables you to assign approvers manually without relying on dynamic or source-based logic. * Approver from source: Select approvers that are based on values from the source table. You can select a user field, a group field, or both to determine approvers dynamically from the source record. * Dynamic approvers: Define approvers dynamically using the source. Apply static or advanced dynamic conditions to filter approvers. You can select a user field, group field, or both to determine who should approve. * Scripted approvers: Use a script to determine the approvers programmatically. The script must populate the users and groups variables. {#define-policy-exception-verification-rules__ul_ibb_yf1_cgc} |
       | Approval required from | Approval options: Select All to make it required for all the selected users to approve the exception. Select Anyone to enable a single user to approve on behalf of all approvers. |
       [Table 4. Rule configuration form]

       {#define-policy-exception-verification-rules__table_ecj_kkz_bgc}
    3. Select Submit.
    {#define-policy-exception-verification-rules__substeps_y5x_d1y_rgc}

*[\>]: and then


