What this is
What is a waiver and concession record?
What is a waiver and concession record?
It is the documented decision to proceed outside a stated requirement for a defined period, with the risk named, assessed, and accepted by someone with the authority to accept it. It is not a workaround logged after the fact — it is a control applied in advance of the deviation.
What is the difference between a waiver and a concession?
A waiver is granted before the nonconforming work happens, accepting a defined deviation for a limited time or run. A concession is granted after output already exists that does not meet requirements, accepting that specific output as fit for use. Both need the same rigour of risk assessment and above-the-benefit approval; the difference is only timing relative to the work.
Who can approve a waiver?
Anyone with the authority to accept the residual risk on behalf of the organisation, provided they sit above the person or team benefiting from the exception. A supervisor cannot approve their own team's shortcut, and a plant manager cannot approve a waiver against a customer or legal requirement without that party's sign-off.
Scope
When is a waiver and concession record required?
This engine is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- A team needs to proceed outside a defined requirement or specification for a limited, named period
- The deviation has not started yet — the waiver is being raised in advance of the work, not after it
- The risk of proceeding can be assessed and alternative controls proposed, even if imperfect
- You are running the Management System Governance programme and this is one of its steps
- A linked record needs this one to exist: links change control, risk register
Do not use it for
- Management of Change, which is for a permanent alteration to a requirement, process or specification rather than a time-limited exception.
- Risk Assessment, which is the single risk assessment used across the whole business, not a waiver-specific risk call.
- Corrective and Preventive Action, which is the single action record used everywhere, not the vehicle for authorising a deviation.
- Temporary Change Authorization, where the quality workspace already runs a process-specific version of the same idea.
- Anything outside General, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 9001 cl.8.7 requirements does this satisfy?
The form maps onto ISO 9001 cl.8.7's requirement to control nonconforming or exceptional outputs through a documented, authorised decision — not a verbal nod from whoever needed the exception.
| Clause | Requirement | Where it lands |
|---|---|---|
| cl.8.7 — identify and control | The requirement being deviated from, and its source, must be named | Header |
| cl.8.7 — authorisation before use | The waiver is raised, and reasoned, before the deviation is acted on | The request |
| cl.8.7 — risk-based thinking | Risk is assessed and residual risk is stated, not assumed acceptable | Assessment |
| cl.8.7 — record of concession and person authorising | The decision and the approver, sitting above the benefit, are both recorded | Decision |
| cl.8.7 — extent and time limitation | Validity dates are set and expiry is actively enforced, not left open | Decision |
| cl.9.1 — monitoring for trends | Repeat waivers against the same requirement are flagged rather than silently renewed | Assessment |
| cl.6.3 — planning of changes | Where a waiver reveals a requirement is wrong, it is routed into a permanent change record | Assessment |
What it does not cover
- Approved By, where the approver is the same person or role who benefits from the exception rather than someone above them.
- Raised Before The Deviation, which is marked 'After' because the work had already started when the record was written.
- Expiry Enforced, where a validity end date exists on paper but nothing actually closes or escalates the waiver when it passes.
- Similar Waiver In Last 12 Months, showing 'more than once' with no linked action to fix the requirement or the process behind it.
- Legal Requirement Affected, answered 'yes' with the waiver still proceeding as if an internal sign-off were sufficient to waive a legal obligation.
Global
Waiver and Concession Record requirements by country
ISO 9001 sets the baseline expectation everywhere it is certified, but the practical weight of a waiver differs sharply by sector — aerospace and automotive both run harder, sector-specific versions of the same control.
AS9100D
Concession management is a named, auditable process with its own approval chain, often requiring customer or design-authority sign-off before use.
A waiver that would clear an internal ISO 9001 audit can still fail an AS9100 audit if the customer or design authority was not party to the decision.
IATF 16949
Deviations against specification are typically tracked through a formal deviation-permit process linked to customer notification requirements.
A waiver against a customer specification usually needs the customer informed and, in many supply agreements, their explicit approval — not just an internal one.
ISO 9001:2015
Cl.8.7 requires nonconforming or exceptional outputs to be identified and controlled, but leaves the approval hierarchy and time limits to the organisation to define.
Everything the record enforces beyond identification — above-the-benefit approval, expiry, escalation on repeats — is the organisation's own discipline, not a clause requirement, which is exactly where it tends to erode first.
How to complete it
How to complete a waiver and concession record, step by step
Filling in the fields is mechanical. The judgement calls are what decide whether the record holds up when someone questions the decision months later.
A second or third waiver against the same requirement is rarely bad luck. If the underlying process cannot reliably meet the requirement, the honest move is a Management of Change, not another dated exception — the record's own 'Permanent Change Should Be Considered' field exists to force that call.
The test is not seniority in general, it is distance from the outcome. A shift supervisor waiving their own team's overdue check, approved by the same supervisor's manager who also owns that shift's output, is not above the benefit in any way that matters.
Residual risk should reflect what is left after the alternative controls are actually in place, not what it would be if they worked perfectly. A 'partly adequate' set of alternative controls cannot honestly produce a 'low' residual risk rating.
An expiry date with nobody accountable for closing or escalating it on the day is decorative. If closure depends on someone remembering, the record should route to an owner with a task, not just a date field.
What auditors find
Most common waiver and concession record findings
The patterns below are the ones that turn up repeatedly when waiver registers get audited, and each one traces back to a specific weak field.
| Finding | Clause | What fixes it |
|---|---|---|
| Waivers raised and approved the same day the deviation was discovered, not before it | cl.8.7 authorisation before use | Require 'Raised Before The Deviation' to gate the record from moving to Decision until answered 'Yes'. |
| Approver and requester are the same person, or one reports directly to the other for this specific benefit | cl.8.7 authorisation independence | Route approval through the workflow engine so the approver role is determined by hierarchy above the benefiting team, not selected manually. |
| Indefinite or open-ended waivers with no review date | cl.8.7 extent and time limitation | Make 'Duration Requested' of 'Indefinite' trigger a mandatory escalation to a more senior approver plus a forced 90-day review checkpoint. |
| Legal or customer requirements waived with only an internal sign-off | cl.8.7 scope of authority | Hard-block the Decision step when 'Legal Requirement Affected' is 'Yes', and require a linked external approval reference before the record can close. |
| Repeated waivers against the same requirement with no linked permanent fix | cl.9.1 monitoring for trends | Report on 'Similar Waiver In Last 12 Months' at the register level and require an MOC ID once the same requirement appears a second time. |
| Expired waivers left open in the system with work continuing under them | cl.8.7 extent and time limitation | Auto-flag any record where 'Expires' has passed and 'Closed On Expiry' is still 'No', and stop new work referencing it. |
Case in point
Case in point: the waiver that outlived the reason for it
A site raised a waiver against a torque-check interval because a calibration backlog meant the correct tool was unavailable for three weeks. It was raised in advance, risk was assessed as low, and it was approved by a manager two levels above the line supervisor requesting it — a clean record by every field on the form.
The calibration backlog cleared in ten days, but nobody closed the waiver early or reset it to the original interval. Fourteen months later an auditor found torque checks still running on the waived interval, with no expiry ever enforced and no one able to say why the shorter interval had stopped. The record was correct on the day it was written and wrong for the following year — which is the part a one-time sign-off cannot catch on its own.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- FDN-030
- Archetype
- Engine
- Record ID
- WVR-2026-000
- Scoring
- Waivers open
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 9001 cl.8.7
- Links
- Links Change control, Risk register
- Tags
- Engine, Waiver
- Sections
- 4
- Fields
- 40
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
10 fieldsWaiver ID*
Auto sequence. Format WVR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Before, Never After
A waiver written after the deviation is not a waiver, it is an excuse. Raise it in advance, put a date on it, and have somebody above the benefit sign it.
Requirement Being Waived*
Source Standard Or Procedure
Requested By*
The request
7 fieldsReason For The Waiver*
Raised Before The Deviation*
- Yes3 pts
- After0 pts
Alternative Controls Proposed
Duration Requested*
- Days3 pts
- Weeks2 pts
- Months1 pt
- Indefinite0 pts
Product Safety Affected*
- No3 pts
- Possibly1 pt
- Yes0 pts
Legal Requirement Affected*
A legal requirement cannot be waived internally, only complied with or breached.
- No3 pts
- Yes0 pts
Customer Requirement Affected*
- No3 pts
- Yes0 pts
Assessment
6 fieldsRisk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Residual Risk*
- Low3 pts
- Medium1 pt
- High0 pts
Alternative Controls Adequate*
- Yes3 pts
- Partly1 pt
- No0 pts
Similar Waiver In Last 12 Months*
Repeated waivers mean the requirement is wrong or the process cannot meet it. Fix one of those.
- No3 pts
- Once1 pt
- More than once0 pts
Permanent Change Should Be Considered*
- Not needed3 pts
- Yes1 pt
MOC ID
Links to FDN-020 MOC ID
Decision
17 fieldsDecision*
Approved By
Approver Above The Benefit*
- Yes3 pts
- No0 pts
Valid From*
Expires*
Expiry Enforced*
- Yes3 pts
- No0 pts
Communicated To Affected Teams*
- Yes3 pts
- Partly1 pt
- No0 pts
Closed On Expiry
- Yes3 pts
- No0 pts
Extended
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Requested By*
Signature*
Approver*
Second Signature*
FDN-030 · record IDs look like WVR-2026-000 · Links Change control, Risk register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping the expiry honest, chasing the communication step, and catching the second waiver against the same requirement is the work that actually slips.

Watches every open waiver against its expiry date, flags anything still active past 'Expires' with 'Closed On Expiry' unanswered, and holds any write back to the record for your approval.
Links the waiver to the specification or requirement it deviates from, and surfaces repeat waivers against the same clause before a third one gets raised.
Checks whether a waived requirement traces to a legal or customer obligation, and blocks internal-only sign-off where an external approval is actually required.
Rolls open waivers into the shift handover so the team on the floor knows what is currently running outside spec and until when.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Glossary
Waiver and Concession Record definitions and key terms
- Waiver
- Authorisation, given in advance, to proceed outside a stated requirement for a defined period or run, with the risk explicitly accepted.
- Concession
- Authorisation to accept output that already exists and does not meet requirements, granted after the fact rather than before.
- Above the benefit
- The principle that the person accepting the risk of a deviation must sit outside and above whoever gains from the exception being granted.
- Residual risk
- The risk that remains once any alternative or compensating controls proposed alongside the waiver have been applied, not the risk of the original deviation alone.
- Deviation permit
- The automotive-sector term for a time-limited authorisation to supply product outside specification, typically requiring customer notification.
FAQ
Frequently asked questions about waiver and concession record
Can a waiver be approved retroactively if the deviation was unavoidable?+
Not as a waiver. If the deviation has already occurred, the correct record is a concession against the specific output, plus a nonconformance if it affected product already released. Calling a retroactive decision a waiver just hides the timing problem from anyone reading the register later.
Does a waiver need a risk assessment every time, even for something minor?+
Yes, though the depth should match the exposure. The form requires 'Risk Assessed' and 'Residual Risk' on every record because the alternative — skipping assessment for anything that looks minor — is exactly how a genuinely significant deviation slips through unexamined.
What happens if a waiver expires while the underlying problem still exists?+
It should not simply be extended by editing the date. The record has an 'Extended' field precisely so an extension is visible and re-justified, and repeated extensions against the same requirement should trigger the same 'permanent change' question as a repeated fresh waiver.
Who should be notified when a waiver is granted?+
Everyone whose work is affected by the deviation, tracked through 'Communicated To Affected Teams'. A waiver that is approved but not communicated protects the approver on paper while leaving the people actually doing the work unaware the requirement has changed.
Can a waiver be used to avoid raising a Management of Change?+
It should not be. A waiver is scoped to a defined period; if the same exception keeps being requested, 'Permanent Change Should Be Considered' exists to force the conversation about a real MOC instead of another renewal.
Is a waiver register auditable evidence for ISO 9001 certification?+
Yes — it is direct evidence of cl.8.7 control, and auditors typically sample it for the patterns this template is built to catch: late raising, self-approval, unenforced expiry.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Management System Governance
One integrated system rather than four running in parallel and exhausting the same people.
Master Data and Foundations
One place for each thing, so a change updates everywhere rather than in eight lists.
Change Control
Changes assessed before they happen rather than investigated afterwards.
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
More in Engines
Risk Assessment
The single risk assessment used across the whole business
Root Cause Analysis
Finds out why something happened rather than who was involved
Corrective and Preventive Action
The single action record used everywhere
Finding
Records a single deficiency picked up during an audit, inspection or check
Effectiveness Verification
Checks whether an action actually worked, some time after it was put in place
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 9001:2015 — cl.8.7 Control of nonconforming outputs
- ISO 9001:2015 — cl.9.1 Monitoring, measurement, analysis and evaluation
- ISO 9000:2015 — Quality management systems: fundamentals and vocabulary
- AS9100D — Quality management systems for aviation, space and defense organizations
- IATF 16949:2016 — Quality management system requirements for automotive production
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.