Semitora.

Open template · version 1.0 · 23 July 2026

AI Governance RACI and decision rights

Define who does the work, who owns the outcome and who may approve, conditionally release or stop an AI system. This is a workshop starting point — not a ready-made organisation chart.

How to use this template

  1. Start with one system or use case from the portfolio register.
  2. Adapt the R/A/C/I codes and enter named people or role titles.
  3. Keep exactly one A in every row. Multiple As dilute accountability.
  4. The DPO remains an independent consulted input — do not merge the DPO with the Data owner or the decider.
  5. Complete the decision rights, evidence, escalation path and expected response time.
  6. Have the affected people approve the matrix before the first dispute or incident.

RACI in four sentences

RR — Responsible: does the work.
AA — Accountable: owns the outcome and remains answerable for it.
CC — Consulted: provides input before the decision.
II — Informed: receives an update after the decision.

7-stage × 7-role matrix

The codes are a starter baseline. Adapt them in a workshop, but keep exactly one A per stage. Use the second field in each cell for a person or role title.

Stage / activitySponsor / committeeBusiness ownerTechnical ownerData ownerSecurityCompliance / riskLegal
1. Intake and inventoryARRCCCI
2. Triage and scopeIARCCCI
3. Data use, privacy and role reviewIRCARCC
4. Design and procurementIARCCCC
5. Build, evaluation and acceptanceIARCCCI
6. Go-liveARRCCCC
7. Operate, change and retireIARCCCI

Decision rights — who may say GO, GO WITH CONDITIONS or STOP

RACI allocates responsibility for work. This table clarifies the mandate for a specific decision, the required input and evidence, and the escalation path.

DecisionDeciderInput requiredEvidence requiredEscalationDecision time
1. Admit a use case to discoverySponsor / committeeBusiness and technical ownersProblem statement and register entryExecutive sponsor / committeeBefore work starts
2. Approve scope, roles and review planBusiness ownerTechnology, data owner, security, compliance and legalScope brief and draft RACISponsor / committeeBefore solution selection
3. Approve data use and accessData ownerDPO, security, compliance / risk, legal and technical ownerSources, lawful basis, access, retention and data flowCompliance / sponsorBefore data is used
4. Select supplier, model and architectureBusiness ownerTechnology, procurement, security, compliance and legalOptions, TCO, contracts and security requirementsSponsor / committeeBefore purchase commitment
5. Accept PoC criteria and evaluation resultsBusiness ownerTechnical owner, domain users, compliance and securityGolden set, thresholds, results, limitations and remediation planSponsor / committeeBefore production decision
6. Make the production decisionSponsor / committeeOwners, security, compliance and legalEvidence Pack, open risks, rollback plan and monitoringHigher decision authorityBefore production release
7. Approve a material change, stop or retirementBusiness ownerTechnology, data owner, security, compliance and legalChange impact, incidents, evaluations and migration planSponsor / committeeAt change threshold or incident

Allowed decision outcomes: GO · GO WITH CONDITIONS · STOP. Record conditions, remediation owner and due date in the Evidence Pack.

Four artefacts, four questions