Policy exception rate
How often controls are bypassed or risks formally accepted.
Formula
Exception rate
(exceptions or bypasses / total governance reviews or controlled actions) * 100
Unit
percent
Direction
Lower is better
Cadence
Monthly in governance review.
Numerator
Exceptions, bypasses, or accepted variances
Denominator
Governance reviews or controlled actions
Worked Example
Control review across policy-governed requests.
Exceptions
18
Reviews
120
Calculation
18 / 120 * 100
Result
15%
Interpretation
Exceptions are common enough to inspect policy fit and control design.
Recommended action
Categorize exceptions by policy friction, risk acceptance, and owner behavior.
Why it matters
This metric helps leaders see whether the governance layer is healthy enough to support execution and AI readiness.
What it reveals
Whether governance is being followed, bypassed, or used to document accepted risk.
Manual assessment method
Review exceptions, bypasses, and accepted risks over a period. Compare them to total governance reviews.
Lapemo calculation path
Supported by bypass events, accepted risks, and control evaluation records when governance activity is captured.
Interpretation Bands
Healthy
0-10%
Low and manageable.
Watch
11-20%
Rising signal that should be reviewed.
Risk
21-35%
High enough to indicate structural friction.
Critical
>35%
Likely blocking execution or governance quality.
Required inputs
- Exception log
- Bypass reason
- Review count
- Risk tier
Data sources
- Governance workflow
- Risk register
- Audit records
- Control map
Common pitfalls
- Treating all exceptions as failures
- Not separating approved risk from bypass
Recommended actions
- Review repeated exception reasons
- Update unrealistic policies
- Escalate risky bypasses
Measure Before You Scale
Measure the operating model before AI amplifies it.
Use the Metrics Library to understand what to diagnose, what to monitor, and where Lapemo can turn framework metrics into operating intelligence.
