Roles, Responsibilities and Decision Rights (RACI)
In the Certified in the Governance of Enterprise IT (CGEIT) framework, defining roles, responsibilities and decision rights is a core part of establishing an effective governance framework, the first CGEIT domain. Governance of Enterprise IT (GEIT) depends on clarity about who directs, who manages,… In the Certified in the Governance of Enterprise IT (CGEIT) framework, defining roles, responsibilities and decision rights is a core part of establishing an effective governance framework, the first CGEIT domain. Governance of Enterprise IT (GEIT) depends on clarity about who directs, who manages, who executes and who must be kept aware, so that IT-related decisions are aligned with enterprise objectives, risks are managed and value is delivered. The RACI model is the most widely used tool for documenting this clarity. RACI stands for Responsible, Accountable, Consulted and Informed. Responsible refers to the person or group that performs the work or activity. Accountable refers to the single individual who owns the outcome, approves the work and answers for its success or failure. Best practice requires only one Accountable party per activity, to avoid diluted ownership. Consulted refers to subject matter experts or stakeholders whose input is sought through two-way communication before decisions or actions. Informed refers to those who are kept up to date on progress or results through one-way communication. In COBIT, which underpins much of CGEIT, RACI charts map governance and management practices to roles such as the board, executive committee, CEO, CIO, CFO, chief risk officer, business process owners, the IT steering committee and audit. Decision rights define who has the authority to make specific IT decisions, such as IT principles, architecture, infrastructure investment, business application needs and prioritization. This reflects the distinction between governance, which evaluates, directs and monitors and is typically the board's accountability, and management, which plans, builds, runs and monitors within that direction. Key principles include that accountability can be delegated in execution but ultimate governance accountability remains with the board, and that segregation of duties must be preserved. A well-defined RACI improves transparency, reduces conflict and duplication, supports decision-making speed, strengthens risk management and enables performance measurement, making it a foundational enabler of sound GEIT.
Roles, Responsibilities and Decision Rights (RACI) in Governance of Enterprise IT: A Complete CGEIT Guide
Introduction
Roles, Responsibilities and Decision Rights sit at the heart of the CGEIT domain Governance of Enterprise IT. Every governance framework, including COBIT, ISO/IEC 38500 and the ISACA governance model, assumes one thing: people know who decides, who does the work, who must be consulted and who must be kept informed. Without that clarity, even the best strategy, policies and controls fail. This guide explains why the topic matters, what it is, how it works in practice, and how to answer CGEIT exam questions on it.
1. Why Roles, Responsibilities and Decision Rights Are Important
Accountability is the foundation of governance. Governance is about making sure stakeholder needs are evaluated, direction is set through prioritization and decision-making, and performance and compliance are monitored. All three need named owners. If no one is accountable, no one can be held to account.
Key benefits of clear roles and decision rights:
- Faster, better decisions: Escalation paths are clear and decisions are not stalled or duplicated.
- Business and IT alignment: Business leaders own business outcomes and the value from IT-enabled investments. IT owns delivery and service.
- Value realization: Benefits have owners who are accountable for achieving them.
- Risk management: Risk owners are identified, risk appetite is set at the right level (the board), and risk responses are owned.
- Resource optimization: Investment and resource allocation decisions are made by the right forums, not by default within IT.
- Compliance and auditability: Auditors and regulators can trace who approved what.
- Fewer gaps and overlaps: Tasks are neither forgotten nor done twice, and conflict between departments goes down.
- Segregation of duties: Conflicting responsibilities are kept apart.
Common symptoms of poor role clarity: projects with no business sponsor, IT making business decisions by default, shadow IT, repeated audit findings with no remediation owner, benefits never measured, and committees that discuss but never decide.
2. What It Is
Roles are positions or functions in governance and management structures. Examples are the board of directors, executive committee, CIO, CFO, business process owner, IT steering committee, architecture board, risk committee, audit committee, project sponsor, data owner and data custodian.
Responsibilities are the activities or tasks a role must perform.
Decision rights define who has the authority to make which decisions, and with what input. Weill and Ross's IT governance research identifies five key IT decision domains:
- IT principles: high-level statements about how IT is used in the business.
- IT architecture: the logical organization of data, applications and infrastructure.
- IT infrastructure: shared IT services.
- Business application needs: requirements for purchased or internally built applications.
- IT investment and prioritization: how much to spend and on what.
The same research describes decision archetypes: Business Monarchy, IT Monarchy, Feudal, Federal, IT Duopoly and Anarchy. Each describes who holds decision or input rights.
RACI is the most widely used tool for documenting roles and decision rights. It stands for:
- R - Responsible: the person or group who does the work. There can be several.
- A - Accountable: the person who owns the outcome, approves the result and answers for it. Best practice is exactly one A per activity. Accountability cannot be delegated, though responsibility can.
- C - Consulted: people whose opinion or expertise is sought before or during the activity. This is two-way communication.
- I - Informed: people kept up to date on progress or results. This is one-way communication.
Variants you may meet:
- RASCI: adds S for Support.
- RACI-VS: adds Verify and Sign-off.
- DACI: Driver, Approver, Contributor, Informed.
- RAPID: Recommend, Agree, Perform, Input, Decide.
COBIT and RACI: COBIT 5 provided RACI charts for each process. COBIT 2019 provides organizational structures as a governance component, showing which roles are Accountable or Responsible for each management practice. Typical COBIT roles include the board, executive committee, CEO, CFO, CIO, CRO, CISO, business process owners, portfolio manager, program and project managers, the architecture board, the enterprise risk committee, the I&T governance board and audit.
3. How It Works
Step 1 - Separate governance from management. This is a core COBIT principle.
- Governance (board and executive level) carries out EDM: Evaluate, Direct and Monitor. It sets direction, approves strategy and risk appetite, and holds management accountable.
- Management carries out Plan, Build, Run and Monitor (APO, BAI, DSS, MEA). It executes within the direction set by governance.
The board is accountable for governance of enterprise IT. Management is responsible for execution.
Step 2 - Establish governance structures. Typical bodies and their roles:
- Board of Directors: ultimately accountable for governance, including IT. Approves strategy and risk appetite.
- IT Strategy Committee: a board-level body that advises the board on strategic IT direction and value.
- IT Steering Committee: an executive-level body that prioritizes investments, oversees programs and resolves resource conflicts.
- Architecture Review Board: sets architecture principles and standards.
- Audit Committee: oversees assurance, independent of management.
- Risk Committee: oversees enterprise risk, including IT risk.
Step 3 - Define decision rights. For each key decision, state who decides, who provides input, who executes and who is informed. Document this in a governance charter, terms of reference and policies.
Step 4 - Build the RACI matrix. Activities or decisions go on the rows and roles go on the columns. Then validate the matrix with these checks:
- Is there exactly one A per row?
- Is there at least one R per row?
- Are there too many Cs, which slow decisions?
- Are there too many Is, which cause information overload?
- Does any role have too many As, which creates a bottleneck?
- Does any role have no As or Rs? If so, why does it exist?
- Are segregation of duties conflicts avoided?
Step 5 - Communicate, embed and enforce. Put roles into job descriptions, performance objectives and incentives. Train people. Reward accountable behavior. This links to the COBIT components for culture, ethics and behavior, and for people, skills and competencies.
Step 6 - Monitor and review. Review the matrix periodically and after reorganizations, mergers, new regulations, outsourcing or cloud adoption. Use audit findings and performance metrics to refine it.
Key ownership principles to remember:
- Business owns the value. The business sponsor or business process owner is accountable for realizing benefits from IT-enabled investments, not the CIO.
- Data owners are business managers. They classify data and approve access. Data custodians (usually IT) implement and maintain the controls.
- Risk owners are the managers accountable for the business activity that creates the risk. The board sets risk appetite.
- System owners and application owners are typically business roles. IT operates the systems.
- Internal audit provides independent assurance. It should not own or implement controls, because that impairs independence.
- Outsourcing transfers responsibility but not accountability. The enterprise remains accountable for outsourced services.
- The CIO is accountable for IT delivery, IT operations and the IT function. The CIO is responsible for advising on and enabling strategy, but is usually not accountable for business benefits.
- The CISO manages the information security program. Executive management and the board are accountable for information security governance.
Example RACI excerpt (IT investment approval):
- Define the business case: Business Sponsor = A, Business Analyst = R, CIO = C, CFO = C, Steering Committee = I.
- Approve and prioritize the investment: IT Steering Committee or Executive Committee = A, Portfolio Manager = R, Business Sponsor = C, Board = I.
- Deliver the program: Business Sponsor = A, Program Manager = R, CIO = C.
- Realize and track benefits: Business Sponsor = A, Business Process Owner = R, Portfolio Manager = C, Steering Committee = I.
4. How to Answer CGEIT Exam Questions on This Topic
CGEIT questions are scenario-based and written from the viewpoint of a senior governance professional advising the board or executive management. You are usually asked for the BEST, MOST, FIRST or PRIMARY option. Use this approach:
1. Identify the decision level. Ask whether the scenario is strategic (board or executive), tactical (steering committee) or operational (IT management).
2. Ask who owns the outcome. Business value and business risk belong to the business. Technical execution belongs to IT.
3. Look for the root cause. If projects fail, benefits are not realized, or audit issues recur, the underlying problem is often unclear accountability or decision rights. In such scenarios, the best answer is usually to define or clarify them.
4. Prefer structural, sustainable fixes. Establishing a governance framework, charter or RACI usually beats a one-off technical fix.
5. Check the governance versus management distinction. The board evaluates, directs and monitors. It does not manage day-to-day IT.
6. Remember single-point accountability. If an option creates shared or committee accountability for a specific outcome where one owner is appropriate, be wary.
Exam Tips: Answering Questions on Roles, Responsibilities and Decision Rights (RACI)
Tip 1: Accountable means one person, and accountability cannot be delegated. Responsibility can be delegated. If two options differ only on this point, choose the one that preserves single accountability.
Tip 2: The board is ultimately accountable for the governance of enterprise IT. Executive management is accountable for implementing it. The CIO is not ultimately accountable for IT governance.
Tip 3: Business owns benefits. For questions about who is accountable for realizing value from an IT-enabled investment, pick the business sponsor or business executive, not the CIO or project manager.
Tip 4: Data owner versus custodian. The data owner (business) classifies data and approves access. The custodian (IT) implements controls. The user follows policy.
Tip 5: Outsourcing does not transfer accountability. Answers suggesting the vendor is accountable for compliance or risk are usually wrong.
Tip 6: Watch for independence. Internal audit should not be Responsible or Accountable for designing or operating controls. It provides assurance and can be Consulted or Informed.
Tip 7: Clarify roles first. When a scenario describes confusion, duplicated effort, conflicting priorities or stalled decisions, look for the option that establishes or clarifies decision rights, such as a RACI, a governance charter or steering committee terms of reference. Avoid options that immediately buy tools or replace staff.
Tip 8: Too many Cs and Is is a warning sign. It signals slow, bureaucratic decision-making. Too many As for one role signals a bottleneck. No A at all signals an accountability gap.
Tip 9: Match the body to the decision.
- Strategic IT direction goes to the IT strategy committee or the board.
- Investment prioritization goes to the IT steering committee or the executive committee.
- Standards go to the architecture board.
- Risk appetite goes to the board.
- Risk acceptance goes to the business risk owner.
Tip 10: The best way to embed accountability is to link roles to performance objectives, job descriptions and incentives, and to ensure top management sponsorship. Documentation alone is not enough.
Tip 11: Know the vocabulary. Recognize RACI variants (RASCI, DACI, RAPID) and the Weill and Ross archetypes (Business Monarchy, IT Monarchy, Federal, Duopoly, Feudal, Anarchy). Federal and IT Duopoly arrangements are often cited as effective for balancing business and IT input.
Tip 12: Think like a governance advisor, not a technician. The CGEIT perspective is to enable business value, optimize risk and resources, and ensure stakeholder transparency. Choose answers that strengthen accountability and alignment.
Tip 13: Words that hint at the right answer include ownership, accountability, sponsorship, alignment, charter, framework, decision rights, escalation. Words that often mark a distractor include IT decides alone, the vendor is accountable, audit implements, the committee is jointly accountable.
Sample Question
An enterprise has invested heavily in a new ERP system, but expected benefits have not materialized, and business and IT blame each other. What should the governance professional recommend FIRST?
A. Replace the ERP vendor
B. Have the CIO take accountability for benefits realization
C. Define clear accountability for benefits realization with the business sponsor, supported by a RACI
D. Commission an internal audit of the ERP configuration
Answer: C. The root cause is unclear accountability. Benefits belong to the business, and clarifying decision rights and ownership is the governance-level fix. Option B wrongly places business value accountability on IT. Option A is premature. Option D is useful but does not address the governance gap.
Summary
Roles, Responsibilities and Decision Rights turn governance from intent into action. Remember these points:
- Separate governance (EDM) from management.
- Assign exactly one Accountable party per activity.
- Keep business ownership of value and risk.
- Retain accountability when outsourcing.
- Preserve audit independence.
- Embed roles through charters, job descriptions and incentives.
In the exam, find the root cause, identify the right decision level and owner, and choose the answer that creates clear, sustainable accountability.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!