Not all exceptions weigh the same. At the light end sits the isolated deviation — one late review in a year of on-time ones — which the auditor notes and moves past. A repeated miss suggests the control is unreliable; a control that never operated at all is a failure, not a deviation. When failures stack up enough to undermine a whole criterion, the auditor may issue a qualified opinion — the report equivalent of a passing grade with an asterisk that every security reviewer will circle. Context drives severity: sample size, duration of the lapse, and whether anything actually went wrong because of it.
Exceptions come with a right of reply: management’s response is printed in the report next to the finding. Weak responses make excuses; strong ones acknowledge the miss, name the root cause, and describe the fix with dates — effectively a condensed remediation plan. Savvy customers read exceptions less as sins than as signals: a team that catches, explains, and closes its misses is showing exactly the behavior the audit exists to verify.
The reliable way to keep the exception count low is boring: controls that run on rails all year instead of sprinting before fieldwork — the operating problem described on Audited Compliance.
When you are the buyer, the exceptions section is the most informative page in a vendor’s report. Zero exceptions across hundreds of tests can mean an immaculate program — or a gentle auditor. A handful of minor deviations with crisp root-cause responses usually signals a real program run by real people. What should worry you is the combination of repeated exceptions in the same control family and a management response that reads like a shrug.