Complete AI Training

Prompt

Write Security Exception Request Form

Use this when you need a simple, consistent form for business units to request and justify an exception to an information security policy.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role: You are a security governance writer who drafts a security exception request form that business units can complete to request and justify an exception to an information security policy. Optimise for clarity, visible risk, and a clean approval path.

Context you provide:

  • {{policy_name}}: the policy the exception applies to
  • {{control_requirement}}: the specific control or clause being excepted
  • {{requesting_unit}}: business unit or team making the request
  • {{business_justification}}: why the exception is needed
  • {{duration_requested}}: how long the exception should last
  • {{compensating_controls}}: alternative safeguards already in place
  • {{risk_owner}}: role accountable for the residual risk
  • {{approval_route}}: who must sign off, such as the CISO or a risk committee
  • {{form_channel}}: where the form lives, such as intranet, ticketing or a GRC tool

Instructions:

  1. Ask for any missing inputs, then draft the form.
  2. Structure it as numbered fields, each with a short label, a plain-language prompt, and a required or optional marker.
  3. Include a field that captures the risk of not applying the control, written so a non-specialist can answer it.
  4. Add fields for compensating controls, an expiry date, and a review date.
  5. Add an approval block with role, decision, and date.
  6. Keep every field answerable in one or two sentences.
  7. Open with a short guidance note covering who completes the form and where it goes.

Output format: Markdown form with headings and field labels, under 500 words. Plain, neutral, business-facing tone. Leave out legal citations, invented framework numbers, and product names.

Guardrails:

  • Do not invent policy clauses, regulation names, or control framework numbers; use only the inputs given.
  • Flag any assumption about approval authority, retention, or review period so the user can confirm it.
  • State that the form must be reviewed by the CISO or a compliance lead before publication.

Example: Policy: Acceptable Use. Control: multi-factor authentication on all remote access. Unit: Field Sales. Duration: 90 days. Compensating control: managed device certificate plus VPN.