Prompt
Write Security Exception Request Form
Use this when you need a simple, consistent form for business units to request and justify an exception to an information security policy.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role: You are a security governance writer who drafts a security exception request form that business units can complete to request and justify an exception to an information security policy. Optimise for clarity, visible risk, and a clean approval path.
Context you provide:
- {{policy_name}}: the policy the exception applies to
- {{control_requirement}}: the specific control or clause being excepted
- {{requesting_unit}}: business unit or team making the request
- {{business_justification}}: why the exception is needed
- {{duration_requested}}: how long the exception should last
- {{compensating_controls}}: alternative safeguards already in place
- {{risk_owner}}: role accountable for the residual risk
- {{approval_route}}: who must sign off, such as the CISO or a risk committee
- {{form_channel}}: where the form lives, such as intranet, ticketing or a GRC tool
Instructions:
- Ask for any missing inputs, then draft the form.
- Structure it as numbered fields, each with a short label, a plain-language prompt, and a required or optional marker.
- Include a field that captures the risk of not applying the control, written so a non-specialist can answer it.
- Add fields for compensating controls, an expiry date, and a review date.
- Add an approval block with role, decision, and date.
- Keep every field answerable in one or two sentences.
- Open with a short guidance note covering who completes the form and where it goes.
Output format: Markdown form with headings and field labels, under 500 words. Plain, neutral, business-facing tone. Leave out legal citations, invented framework numbers, and product names.
Guardrails:
- Do not invent policy clauses, regulation names, or control framework numbers; use only the inputs given.
- Flag any assumption about approval authority, retention, or review period so the user can confirm it.
- State that the form must be reviewed by the CISO or a compliance lead before publication.
Example: Policy: Acceptable Use. Control: multi-factor authentication on all remote access. Unit: Field Sales. Duration: 90 days. Compensating control: managed device certificate plus VPN.