In large environments, there will be legitimate exceptions. Build a documented exception process with temporary access, compensating controls, and automatic expiry to avoid leaving high-risk exceptions open indefinitely. Automate exception reviews where possible and make exception data visible to compliance owners.