Roles, responsibilities and RACI: who does it and who answers for it
A RACI chart maps activities to roles; done badly it hides who answers for what.

Every governance record has to answer two questions about an activity: who does it, and who answers for it. A RACI chart writes both down at once — activities as rows, roles as columns, four letters in the cells: responsible, accountable, consulted, informed. Its value is diagnostic: it exposes the row with nobody accountable, and the role accountable for everything and responsible for nothing.
The four letters come from one paragraph and a footnote
NISTIR 8286r1 is the only document in this sheet’s evidence that names the technique: “It may be helpful to document responsibilities in the form of a RACI chart that designates which roles are responsible, accountable, consulted, or informed about various activities” (line 966); footnote 18 defines the letters as “those who are responsible (R), accountable (A), consulted (C), and informed (I)” (line 979). The technique is offered as a possibility — “may be helpful” — not a requirement: no control in SP 800-53 Rev. 5 asks for a chart. And the definition stops at the letters: nothing about what the rows should be, or how to fill a cell.
The one distinction that carries the chart
R is the role that performs the work, A the role that answers for the outcome; NISTIR 8286r1 states the pair once, about risk ownership: “There may be a distinction between responsibility and accountability for risk ownership. For example, in a federal agency, responsibility for information system risks might be assigned to a System Owner, but accountability might be assigned to an Authorizing Official” (lines 1935–1946). The claim turns on might be, and no method is prescribed: strategy “should clearly describe the roles that will be responsible and accountable for risk decisions at each organizational level” (lines 1947–1948).
One letter per cell — notional, from no source:
activity service owner system owner security lead CIO
identify the risk C R C -
choose the response C C I A
implement the response R R I -
accept the residual risk C C C A
The rows come from a process, not an organisational chart
The rows are the difficult half, and NISTIR 8286r1 anchors them in work that already exists: “identifying the relevant work roles for each stage”, with “recording the names of personnel in those roles who are involved at each stage” supporting risk communication and timely decisions (lines 960–963). “Each stage” is the six-step process the same document sets out — identify the context, the risks, their analysis, prioritisation and response, then monitoring (lines 661–680) — so a row is a decision somebody has to make. Rows copied from an organisational chart give one per department and none for the cross-cutting decisions, which is where accountability is usually the open question. (Interpretation.)
What turns a letter into a role
A cell is a claim about a person, and the claim needs an appointment behind it. PM-2 requires the organisation
to “Appoint a senior agency information security officer with the mission and resources” to run an
organisation-wide programme (line 13697); PL-1(b) requires a designated official “to manage the development,
documentation, and dissemination of the planning policy and procedures” (line 13094); AT-2 trains all users,
“including managers, senior executives, and contractors” (line 4869), and AT-3 trains them by role (line 5015);
PS-7 puts the same duty on external providers (line 15117). A role with a name, training and no access has a
chart entry and no capability; the access decisions belong to the technical areas.
Where a chart fails
- A blank A. Several R’s and no A means performers with nobody answering for the outcome — the failure the chart exists to expose. (Interpretation.)
- An A that carries nothing. A role accountable for every row and responsible for none is a title; NISTIR 8286r1 puts the counterweight on leadership (lines 1934–1935).
- R and A on one person where the duty requires separation.
AC-5requires the organisation to “Identify and document [Assignment: organization-defined duties of individuals requiring separation]” and to shape access authorisations around them (lines 3360–3363); its discussion names the case — “security personnel who administer access control functions do not also administer audit functions” (line 3369). - Everyone consulted, nobody informed. C is cheap to hand out; without I, nobody else learns that a decision was taken. (Interpretation.)
What is required, and what RACI is not
Remove the chart and the obligation stays. CSF 2.0 has a category for it — Roles, Responsibilities, and
Authorities, stated as “Cybersecurity roles, responsibilities, and authorities to foster accountability,
performance assessment, and continuous improvement are established and communicated” (lines 788–790) — with
GV.RR-01 putting responsibility and accountability for cybersecurity risk on leadership (lines 792–793) and
GV.RR-02 requiring roles, responsibilities and authorities to be “established, communicated, understood, and
enforced” (lines 795–796). SP 800-53 Rev. 5 puts the same subject in policy content — PL-1(a)(1)(a) requires
planning policy that “Addresses purpose, scope, roles, responsibilities, management commitment, coordination
among organizational entities, and compliance” (lines 13085–13086) — and, for services delivered externally, in
SA-9(b) (lines 17876–17877). A chart is one way to make the “established, communicated, understood, and
enforced” part of GV.RR-02 inspectable — not the requirement itself, and not evidence that a role exists.
Level and prerequisites
L2 — operational: build an activity-to-role mapping, or read one and say where it fails. Prerequisites are the L1 vocabulary of accountability (accountable versus responsible, and the roles attached to an asset) and a process you can already write down. Owner identity and the register the mapping is filed in belong to their own sheets.
Where to go next
- Knowledge — the index.
- Cybersecurity Governance — the area this sheet belongs to.
- Security governance foundations — this sheet’s node.
References
- NIST — NISTIR 8286r1, Integrating Cybersecurity and Enterprise Risk Management (ERM) (December 2025) — https://doi.org/10.6028/NIST.IR.8286r1 — the RACI paragraph (line 966) and footnote 18 (line 979), the “work roles for each stage” sentence (lines 960–963), the six-step risk management life cycle (lines 661–680), the auditor role in the work-roles list (line 976), and the responsibility-versus-accountability passage for risk ownership (lines 1931–1948).
- NIST — SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations — https://doi.org/10.6028/NIST.SP.800-53r5 —
PL-1(a)(1)(a)policy content andPL-1(b)designated official,PM-2leadership role,AT-2/AT-3training,AC-5separation of duties,PS-7external personnel,SA-9(b)roles for external services. - NIST — The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (26 February 2024) — https://doi.org/10.6028/NIST.CSWP.29 — the GV.RR category statement and the subcategories GV.RR-01 to GV.RR-04.