Deferral is a governance decision
A deferred finding remains an open compliance issue. Recording a risk acceptance does not satisfy the underlying obligation, establish compliance or constrain a competent authority's response. It records that the organisation understands the position and has made an authorised decision about how it will be managed for a defined period.
This distinction matters at programme close. A finding supported by a documented rationale, interim mitigation, accountable owner and committed remediation date remains governed. One that leaves the programme because time or budget has run out becomes an unmanaged gap, even if the programme reports it as deferred.
What a defensible decision contains
Every deferred finding should leave the programme with a decision record covering six things.
- The precise gap
- The record identifies what remains incomplete, the obligation involved, and the entities, services or jurisdictions affected. A broad description prevents decision-makers from understanding the exposure they are being asked to accept.
- The reason for deferral
- The record states why remediation could not be completed within the programme, and why carrying the exposure for the stated period is acceptable.
- The remaining exposure
- The decision explains the regulatory and operational consequences of leaving the gap open, including the potential effect on critical services and the organisation's ability to demonstrate its compliance position.
- Interim treatment
- Temporary measures reduce the exposure while full remediation is pending. Where none is available, that fact is made explicit because it changes the decision being taken.
- Ownership and timing
- A named owner carries the finding into business-as-usual operation with a funded remediation approach, milestones and a target completion date. The date is a governance commitment.
- Approval and review
- The record identifies who approved the deferral, when the position will be reviewed and where a delay or material change must be escalated.
Approval follows the significance of the gap
The programme mandate should define which deferrals the steering committee can approve and which require escalation. Every deferral is a risk acceptance, and the approval level should follow its consequence. A finding with limited legal or service impact can sit within the committee's authority. A material gap affecting legal compliance, a critical service or significant cyber risk warrants management body visibility and, where the governance framework requires it, approval.
Article 20 requires the management body to approve the organisation's cybersecurity risk management measures and oversee their implementation. It does not prescribe an internal approval route for every programme finding. Effective oversight nevertheless requires the management body to receive the material position. It cannot assess the adequacy of the measures while significant known limitations remain outside its view.
An acceptance has an expiry date
The decision remains valid only within the conditions on which it was made. If the remediation deadline passes, the finding must be closed, escalated or reassessed and approved again at the appropriate level. Allowing the date to pass without action converts a controlled deferral into an unmanaged compliance gap.
The gap register therefore continues beyond programme close. The sustained compliance owner tracks deferred findings, challenges overdue remediation and keeps material items visible through management body reporting. Each finding remains open until remediation is complete and supported by evidence.