RACI Roles & Responsibilities Matrix

Matrix GOVERN

Purpose

Defines roles and responsibilities across all AI governance activities using RACI assignments.

Related Controls

ISO A.3 NIST GV-2

1. Purpose

Explain why clear role definition is critical for AI governance.

This matrix defines who is Responsible, Accountable, Consulted, and Informed for each AI governance activity at [ORGANIZATION NAME]. Clear role assignment prevents gaps in oversight, eliminates duplicated effort, and ensures every AI governance task has a single accountable owner.

R = Responsible (does the work) | A = Accountable (owns the outcome) | C = Consulted (provides input) | I = Informed (kept updated)

Document Owner: [ROLE TITLE]

Last Updated: [DATE]

2. Governance Roles

Define each role referenced in the RACI matrix with responsibilities and required skills.

RoleDescriptionTypical Title
AI Governance CommitteeCross-functional body that sets AI strategy, approves policies, and oversees riskCommittee (CTO, CISO, Legal, Business)
AI Program LeadDay-to-day coordination of AI governance activitiesDirector of AI / AI Program Manager
AI System OwnerBusiness owner of a specific AI system; accountable for its outcomesProduct Manager / Business Unit Lead
ML EngineerDevelops, trains, and maintains AI modelsML Engineer / Data Scientist
Security TeamAssesses and mitigates AI-specific security risksAppSec Engineer / Security Analyst
Legal/PrivacyEnsures regulatory compliance and data protectionPrivacy Officer / Legal Counsel
OperationsDeploys, monitors, and maintains AI systems in productionDevOps / MLOps Engineer

3. RACI Matrix

Map each governance activity to role assignments. Every row must have exactly one A.

ActivityAI Gov CommitteeAI Program LeadSystem OwnerML EngineerSecurityLegal/PrivacyOperations
AI Policy DevelopmentARCICCI
Risk Appetite SettingARCICCI
New AI System ApprovalARRCCCI
Vendor EvaluationIARCRCI
Risk AssessmentIARCRCI
Model DevelopmentIIARCII
Security TestingIIICA/RII
Deployment ApprovalIARCRIC
Production MonitoringIIACCIR
Incident ResponseIACCRCR
Compliance ReportingARCICRI
Annual ReviewARCCCCC

4. Escalation Paths

Define how disagreements and gaps in the RACI are resolved.

Escalation Rules

  1. Missing Accountable: If no individual is accountable for an AI governance task, the AI Program Lead assumes interim accountability and escalates to the AI Governance Committee within 5 business days
  2. Conflicting Responsibilities: When two roles disagree on approach, the Accountable party makes the final decision. If the Accountable party is conflicted, escalate to the AI Governance Committee
  3. Resource Gaps: If the Responsible party lacks capacity, the Accountable party must either reallocate resources or escalate to the AI Governance Committee for prioritization

Review Schedule

This RACI matrix is reviewed semi-annually and updated whenever organizational structure changes, new AI systems are deployed, or new roles are created.

← Back to all templates