6.6 Documenting and Communicating the Compliance Decision

Key Takeaways

  • The authorization decision document records the decision, its terms and conditions, the authorization duration or ongoing-authorization basis, and an explicit residual risk statement.
  • A decision that is made but not communicated has no operational effect, because the parties who must act on it do not know it exists.
  • Notification must reach every system that inherits controls from the authorized system and every interconnection partner whose risk posture depends on it.
  • A denial of authorization requires the same formal documentation and communication rigor as an approval, including explicit direction on the system's disposition.
  • The decision triggers concrete downstream actions — inventory updates, activation of continuous monitoring, and the start of the authorization clock.
Last updated: August 2026

Documenting and Communicating the Compliance Decision

Task 6.3 closes Domain 6 with two deceptively simple bullets: "formal notification of compliance decision" and "formal notification shared with stakeholders." The exam's angle is that a decision which exists only in the Authorizing Official's inbox has no operational effect — the parties who must act on it cannot act on what they have not received.


1. The Authorization Decision Document

The AO's determination is captured in a formal artifact, commonly the Authorization Decision Document or ATO letter. Four elements are mandatory:

ElementContent
The decisionATO, ATO with conditions, IATT, ATU, or DATO — stated unambiguously
Terms and conditionsBinding constraints: POA&M items with deadlines, restrictions on data types or user populations, required monitoring, prohibited configurations
Authorization durationA termination date, or the basis and conditions for ongoing authorization where the organization operates a continuous authorization model
Residual risk statementAn explicit statement of the risk being accepted, so the acceptance is visible rather than implied

The residual risk statement is what makes the decision meaningful. An ATO letter that simply grants authorization without naming what risk is being accepted does not evidence that the AO understood the decision — which is the entire purpose of the package.

Supporting content typically includes the identity and signature of the AO, the system name and unique identifier, the authorization boundary reference, the package version relied upon, the date, and the conditions under which the authorization may be suspended or revoked.

[!IMPORTANT] Terms and conditions are binding, not advisory. If the decision states that all Moderate POA&M items must close within 90 days, missing that deadline without an approved extension gives the AO grounds to suspend or revoke the authorization. Candidates who treat conditions as aspirational misread the instrument: it is the mechanism by which an AO authorizes a system that is not yet fully compliant while retaining leverage.


2. Who Must Be Notified

Distribution is not a courtesy list. Each recipient has an action to take.

RecipientWhy They Need It
System OwnerMust operate within the terms and satisfy the conditions
ISSO / ISSMExecutes continuous monitoring and tracks conditions
Common Control ProvidersLearn that another system now depends on their controls
Systems inheriting from this systemTheir own risk posture depends on this authorization remaining valid
Interconnection partnersTheir agreements are predicated on this system's authorization status
CIO / CISOEnterprise portfolio and FISMA reporting
Risk Executive (Function)Aggregate enterprise risk view
SAOPWhere privacy risk was accepted
Security Control AssessorCloses the assessment cycle
Inventory / GRC repository ownersMust record the status change

The two rows candidates overlook are inheriting systems and interconnection partners. Both have made risk decisions premised on this system's status. A partner operating an interconnection with a system whose authorization has lapsed is carrying risk they do not know about, which is why interconnection agreements customarily require notification of authorization changes.


3. What the Decision Triggers

Authorization is a state change with concrete consequences that must actually be executed:

  1. Inventory update. The system's status, authorization date, expiration, and impact level are recorded in the enterprise repository — eMASS, CSAM, or equivalent. This is what feeds FISMA reporting.
  2. Continuous monitoring activation. The approved ISCM strategy moves from planned to operational. Monitoring does not begin at the first scheduled scan; it begins when authorization takes effect.
  3. POA&M tracking begins against the dates in the terms and conditions.
  4. The authorization clock starts — either toward a termination date or against ongoing-authorization conditions.
  5. Inheritance relationships become live, so consuming systems may cite this authorization.
  6. Operational permission is granted. The system may process the data types and support the user populations described in the package — and no others.

That final constraint is examinable. Authorization is bounded by the package it was granted against. Adding a new data type or user population that the package did not describe is a change requiring security impact analysis, not an operational adjustment.


4. Communicating Conditional Decisions and Denials

ATO With Conditions

The most common real-world outcome. Communication must be unambiguous about what the conditions are, when they are due, who owns each one, and what happens if they are missed. A conditional ATO communicated as though it were unconditional produces a system operating past deadlines nobody was tracking — and an authorization that is technically voidable.

Denial of Authorization to Operate

A DATO requires the same rigor as an approval, plus explicit direction on disposition. The communication states the decision, the specific deficiencies that drove it, what would be required to obtain authorization, and — critically — what happens to the system now: whether it must be disconnected immediately, may continue in a restricted mode, or must be decommissioned. A denial that omits disposition guidance leaves operational staff without direction on a system they have been told not to authorize.

For an operating system, a DATO or revocation is disruptive by design, and the communication should reach the mission owner directly rather than through the security chain alone, since mission continuity decisions follow immediately.

Suspension and Revocation

Where an authorization is withdrawn mid-cycle — conditions missed, a significant unassessed change, a serious incident — the notification states the reason, the effective date and time, the required actions, and the path to restoration. These are urgent communications, and the distribution list is the same one that received the original decision, which is a practical reason to maintain that list accurately from the outset.

[!NOTE] Records retention. Authorization decision documents are part of the system's permanent record and are retained per the organization's records schedule — commonly for the life of the system plus a defined period. They are primary evidence in audits, oversight reviews, and incident investigations, and are among the first artifacts an Inspector General requests. The record should also show when notification was sent and to whom, since the ability to demonstrate that stakeholders were informed is exactly what is questioned after something goes wrong.

Loading diagram...
The Compliance Decision: Documentation, Distribution and Downstream Effects
Test Your Knowledge

An Authorizing Official issues an ATO with conditions requiring three Moderate POA&M items to close within 90 days. The system owner treats these as target dates and misses them without requesting an extension. What is the consequence?

A
B
C
D
Test Your Knowledge

Which stakeholders are most commonly omitted from authorization decision distribution, despite having made risk decisions that depend on the system's authorization status?

A
B
C
D
Test Your Knowledge

An Authorizing Official denies authorization for a system already operating in production. Beyond stating the decision and the deficiencies that drove it, what must the communication include?

A
B
C
D