Compliance Exception Management: A Guide for Investment Organizations

Compliance exception management is an essential part of running a sophisticated investment organization. Exceptions are inevitable: a portfolio manager may request temporary relief from an internal restriction, a business unit may be unable to follow a standard procedure because of an unusual transaction, or a supervisory control may not be practical for a particular workflow.

In other cases, a vendor limitation may require an interim workaround, or a policy may allow the Chief Compliance Officer to approve deviations under specific circumstances.

Sometimes an exception is entirely appropriate.

The risk isn’t necessarily in granting it. Instead, the risk is approving an exception without creating a clear record of what was approved, why it was appropriate, who accepted the risk, what controls remain in place, and when the decision must be revisited.

For Chief Compliance Officers and Chief Operating Officers, this distinction matters.

An exception can look reasonable when discussed in a meeting or described in an email. Six months later, however, the individuals involved may remember the facts differently. After twelve months, the business circumstances may have changed. During an examination or internal audit, the firm may then need to reconstruct why it allowed a deviation from standard policy in the first place.

That is where disciplined compliance exception management becomes essential.

The goal isn’t to eliminate exceptions. In a complex investment organization, doing so may be unrealistic and could even create unnecessarily rigid processes.

Rather, the goal is to make exceptions intentional, controlled, temporary where appropriate, reviewable, and defensible.

Before approving the next exception, CCOs should ask a more important question than simply, “Can we allow this?”

Instead, they should ask:

“What would we want the record to show if someone reviewed this decision a year from now?”

Why Compliance Exception Management Matters

Compliance programs are designed around policies, procedures, controls, and defined responsibilities.

Exceptions, by definition, sit outside the normal path, making them inherently important from a governance perspective.

An exception may represent a conscious decision that applying the standard requirement is impractical or inappropriate under a particular set of facts. However, once a firm departs from its ordinary process, the reasoning behind that departure becomes important.

The SEC’s Compliance Rule requires registered investment advisers to adopt and implement policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules, and to review their adequacy and the effectiveness of their implementation at least annually. The Commission has also said advisers should consider compliance matters that arose during the year, changes in business activities, and regulatory developments when performing that review.

That does not mean every exception is a violation, nor does it mean regulators prescribe a universal exception-approval checklist.

It does, however, reinforce a broader principle: firms need compliance frameworks that work in practice, not only on paper.

An exception is one of the moments when that distinction becomes particularly visible. For example, if the firm’s policy says one thing while the organization has repeatedly allowed something different, compliance needs to understand why.

Was each departure individually justified?

Did the firm intend for the exception to be temporary?

Were mitigating controls identified?

Has the same exception occurred so frequently that the underlying policy may need to change?

Strong compliance exception management helps CCOs answer those questions.

1. Start With the Requirement Being Excepted

The first thing an exception record should identify is deceptively simple:

What exactly is the exception from?

That may be:

  • A compliance policy
  • A written supervisory procedure
  • An internal investment restriction
  • A control requirement
  • A business procedure
  • A contractual guideline
  • A firm-imposed risk limit
  • A regulatory requirement, where legally permissible
  • A standard operating process

The distinction is critical because not every requirement is equally flexible.

For instance, some internal policies explicitly allow exceptions with CCO approval. Certain contractual restrictions may require client consent. By contrast, some legal or regulatory obligations may leave no room for discretionary exception at all.

Therefore, before the firm decides whether it can approve an exception, the request should be tied to the underlying requirement.

This gives compliance the first link in the governance chain:

Requirement → Exception Request

Without that connection, organizations can accumulate standalone exceptions without understanding which parts of the compliance framework they are modifying in practice.

2. Document the Business Rationale

“Business requested exception” isn’t enough.

Neither are descriptions such as:

“Operational need.”

“Approved by CCO.”

“One-time issue.”

Those explanations may make sense to the people involved today, but they provide little context for someone reviewing the decision later.

Instead, a stronger exception record explains the circumstances that made the standard process impractical or inappropriate.

For example:

What is the specific business situation?

Why can’t the normal control or procedure be followed?

What would happen if the exception were denied?

Is a client request, transaction structure, operational limitation, technology constraint, or another factor driving the request?

Is the circumstance genuinely unusual, or could it recur?

The goal isn’t to write a legal brief for every exception. Rather, it is to capture enough information so an independent reviewer can understand why the request was reasonable at the time.

This becomes especially important in larger firms, where the person reviewing the exception later may have had no involvement in the original decision.

3. Define the Scope Precisely

One of the most common governance risks is allowing an exception to become broader than the circumstances that justified it.

For example, a request concerning one portfolio shouldn’t unintentionally cover an entire strategy. Similarly, an exception involving one transaction shouldn’t automatically become a standing operating practice. If an exception applies to one business unit, employees elsewhere shouldn’t assume it applies to them as well.

The documentation should therefore define the boundaries clearly.

That may include:

  • Legal entity
  • Business unit
  • Fund or account
  • Strategy
  • Security or transaction
  • Employee or team
  • Geographic jurisdiction
  • System
  • Procedure
  • Client
  • Time period

Precision protects both the firm and the individual approving the request.

Most importantly, it establishes what was authorized and, just as importantly, what was not.

4. Record the Compliance and Risk Analysis

An exception request should not move directly from business rationale to approval.

Instead, the firm should document the compliance analysis that sits between them.

What risks does the exception create?

Could it affect clients?

Does it introduce a conflict of interest?

Could it affect books and records?

Does the deviation change a supervisory process?

Are regulatory filings or disclosures implicated?

Could it create additional operational, cybersecurity, privacy, or vendor risk?

For broker-dealers, the importance of reasonably designed supervisory processes is embedded in FINRA Rule 3110, which requires member firms to establish and maintain supervisory systems and written procedures reasonably designed to achieve compliance with applicable securities laws, regulations, and FINRA rules. FINRA’s guidance also repeatedly emphasizes identifying responsible persons, defining supervisory activities, and evidencing reviews.

For investment advisers, the same governance principle can be valuable even where the specific FINRA rule does not apply.

Ultimately, effective compliance exception management should reflect an informed assessment of the risk created by a deviation from an established process.

5. Identify the Controls That Remain in Place

Approving an exception does not necessarily mean removing all controls.

Often, a better question is:

What can the firm do differently to manage the risk?

Suppose a standard control cannot operate as designed. Another person might review the activity manually. The firm could increase monitoring temporarily or require additional approval for the transaction. In other cases, reporting frequency might increase, activity could be limited to a defined threshold, or the firm could conduct a retrospective review.

These are compensating or mitigating controls.

Documenting them demonstrates that the firm did not simply waive a requirement and move on. Instead, the firm considered how it would continue managing the underlying risk.

An exception record might therefore include:

Standard control: Pre-approval required before activity occurs.

Exception: Pre-approval process unavailable for this specific transaction due to timing constraints.

Compensating control: CCO approval before execution, followed by documented next-day review and reconciliation.

The appropriate control will depend entirely on the circumstances. However, the governance principle remains consistent:

If the normal control is changing, identify what risk management remains.

6. Make Ownership Explicit

Every exception should have an owner and, in some cases, more than one.

For instance, a business owner may be responsible for the activity receiving the exception. A compliance owner could oversee monitoring, while a control owner performs a compensating control. Additionally, an executive or committee may hold ultimate approval authority.

This matters because exceptions can easily become orphaned.

Consider a common scenario: A person requests an exception, and the CCO approves it. Later, the requester changes roles. Months pass, and eventually no one remembers that the exception remains active.

For CCOs and COOs overseeing large organizations, ownership should be explicit enough that the firm can answer several questions:

Who is responsible for complying with the terms of the exception?

Who monitors it?

Who is responsible for escalating issues?

Who decides whether it should be renewed?

FINRA’s supervisory framework provides a useful parallel. Rule 3110 emphasizes the designation of individuals with defined supervisory responsibilities and requires certain reviews to be evidenced in writing.

Exception governance benefits from the same clarity.

7. Put an Expiration Date on It

One of the most important fields in an exception record may be the expiration date.

Without one, a temporary exception can quietly become permanent.

For example, a team gets permission to follow a different process “for now.” Three years later, everyone assumes that’s simply how the process works.

This creates what could be called exception drift: a one-time deviation gradually becoming an undocumented alternative policy.

Of course, not every exception needs to expire in thirty days. Some may appropriately remain in place for a longer period.

Nevertheless, each should have one of the following:

  • A defined expiration date
  • A scheduled review date
  • A specific event that ends the exception
  • A requirement for formal renewal

Doing so forces the organization to revisit whether the original rationale still applies.

It also creates an important distinction between:

temporary deviation

and

permanent policy change.

If an exception continually requires renewal, the real question may no longer be whether the exception should continue. Instead, compliance may need to consider whether the underlying policy or control should be reconsidered.

8. Capture Approval and Decision-Making Authority

An exception is only as controlled as its approval process.

Accordingly, firms should define who has authority to approve different categories of exceptions.

A low-risk operational deviation may have one approval path, while an exception affecting client obligations, conflicts, trading restrictions, or supervisory controls may require senior compliance or legal involvement. Particularly significant exceptions may also warrant escalation to a committee or senior management.

The record should show:

  • Who requested the exception
  • Who reviewed it
  • Who approved or denied it
  • Date of approval
  • Any conditions attached to approval
  • Any dissent or required escalation

This matters beyond basic recordkeeping because it establishes accountability.

As a result, a future reviewer should be able to understand not only what decision was made but also who had authority to make it.

9. Maintain the Evidence Supporting the Decision

One of the easiest mistakes is recording the final decision while losing the evidence behind it.

Relevant supporting material could include:

  • Legal analysis
  • Communications
  • Client documentation
  • System limitations
  • Testing results
  • Risk assessments
  • Committee materials
  • Outside counsel advice
  • Supporting transaction information
  • Screenshots or configuration evidence
  • Remediation plans

Not every exception will require extensive attachments. However, when documentation materially influenced the decision, the firm should be able to find it.

For large investment organizations, this is where centralized compliance exception management becomes particularly valuable.

Otherwise, firms frequently end up with a fragmented trail across email, shared drives, ticketing systems, spreadsheets, and individual inboxes. Although those systems may technically preserve pieces of the record, they do not necessarily make the full record easy to understand.

10. Monitor What Happens After Approval

The governance process shouldn’t end when the CCO clicks “approve.”

At that point, the exception exists within the compliance environment and requires appropriate oversight.

Did the business comply with the conditions?

Did compensating controls operate as intended?

Were any issues identified?

Have the circumstances changed?

Did the exception expire when expected?

Was renewal requested?

The SEC’s 2026 Examination Priorities continue to emphasize whether advisers’ policies and procedures are actually implemented and enforced, along with evaluation of annual reviews of compliance-program effectiveness.

That distinction is central to compliance exception management.

After all, a beautifully documented approval is not sufficient if no one monitors whether the business follows the terms of the exception.

11. Look for Patterns Across Exceptions

Individual exceptions tell you about individual situations.

Collectively, however, they can reveal important information about your compliance program. This may be one of the most valuable reasons for managing exceptions centrally.

Imagine, for example, that a CCO sees:

  • 19 exceptions tied to one policy
  • 14 generated by the same business process
  • 11 involving the same technology limitation
  • Repeated renewals of the same “temporary” exception
  • Several exceptions depending on the same compensating control

At that point, the issue is no longer limited to exception management.

Instead, it provides information about the design of the compliance program.

Perhaps a policy no longer reflects how the business operates. Alternatively, the organization may need technology investment, or the control may be too rigid. Training could be insufficient. The organization might also be tolerating a risk that should be formally reconsidered.

The SEC’s adopting release for Rule 206(4)-7 explains that annual reviews should consider compliance matters that arose during the previous year, changes in business activities, and regulatory changes that may suggest a need to revise policies and procedures. It also notes that significant compliance events may warrant interim review rather than waiting for the annual cycle.

Therefore, exception trends can be an important input into that process.

What Should a Compliance Exception Management Record Include?

For CCOs and COOs looking for a practical framework, a strong compliance exception management record should generally be able to answer the following:

What?
Which policy, control, restriction, procedure, or requirement does the exception concern?

Why?
What facts or circumstances justify the exception?

Where?
Which entity, account, strategy, system, transaction, employee, or business area does it affect?

What is the risk?
What compliance, client, operational, regulatory, or other risks result?

What controls remain?
Which mitigating or compensating measures will manage the risk?

Who owns it?
Who is responsible for the activity, monitoring, and escalation?

Who approved it?
Who had authority to make the decision?

For how long?
When does the exception expire or require reassessment?

What evidence supports it?
Where is the analysis and supporting documentation?

What happened afterward?
Were conditions satisfied, controls performed, issues identified, or renewal required?

If the record clearly answers those questions, the firm is in a far stronger position than if the entire rationale lives in an email that simply says:

“Approved.”

The Goal Is Not More Documentation. It’s Better Governance.

There is a danger in turning exception management into a paperwork exercise, but that isn’t the goal.

CCOs do not need longer forms simply for the sake of having longer forms. Instead, they need enough structured information to make informed decisions, maintain accountability, monitor risk, detect patterns, and demonstrate the reasoning behind those decisions later.

For large investment organizations, that becomes increasingly difficult when teams manage exceptions through email chains, spreadsheets, messaging platforms, or isolated business systems.

The issue is not merely where the request is stored. More importantly, it is whether the organization can connect:

Exception → Requirement → Risk → Control → Owner → Approval → Evidence → Review

That connection creates something more valuable than a collection of approvals.

It creates a structured compliance exception management program.

Before You Approve the Next Exception, Think About the Future Reviewer

Most exception requests are evaluated in the context of today’s facts. Strong governance, however, considers tomorrow’s questions too.

Six months from now, will someone understand what was approved?

A year from now, will the organization know whether the exception is still necessary?

During the annual review, will compliance be able to identify patterns?

During an examination, could the firm explain why the deviation was reasonable and what it did to manage the resulting risk?

If the answer depends on finding the right email or asking the person who remembers what happened, the process may not be durable enough.

The best exception records allow the decision to stand on its own. They make the rationale visible while preserving accountability and establishing clear boundaries. In addition, they document risk and create a path back to standard operations, or toward a deliberate change in policy when an exception reveals that change is necessary.

Bring Structure to Compliance Exception Management With TillieStar

Exceptions are part of running a complex investment organization. Fragmented exception governance, however, doesn’t have to be.

TillieStar helps investment compliance teams create a more connected approach to compliance exception management by linking requests and approvals to the rules, policies, controls, owners, documentation, and review processes behind them.

For CCOs and COOs, that means greater visibility into what’s been approved, why it was approved, when it needs to be revisited, and whether recurring exceptions are signaling a larger compliance issue.

Instead of rebuilding the history of an exception months later, firms can maintain the governance record as decisions are made.

Before you approve the next exception, make sure the decision will still make sense when someone reviews it a year from now.

Ready to strengthen exception governance across your compliance program?

Contact TillieStar at sales@tilliestar.com or (617) 865-3550 to start the conversation.

Leave a comment

Your email address will not be published. Required fields are marked *