9.2 RACI Charts and Key Roles

Key Takeaways

  • RACI means Responsible, Accountable, Consulted, Informed — it documents the organizational-structures component, not an eighth component.
  • Exactly one Accountable per activity or practice; Responsible does the work; Consulted is two-way; Informed is one-way.
  • The governing body is typically Accountable for EDM practices; management is typically Accountable for APO, BAI, DSS, and MEA practices.
  • A chart with three Accountables and no Responsible is invalid — shared A is not conservative ownership.
  • Do not memorize a 40-objective RACI; Foundation scores the letter rules and the governance-versus-management split.
Last updated: August 2026

Quick Answer: RACIResponsible, Accountable, Consulted, Informed — is how the organizational structures component shows who does what for practices. Exactly one Accountable per activity or practice. Responsible does the work. Consulted is two-way. Informed is one-way. EDM accountabilities sit with the governing body; APO / BAI / DSS / MEA accountabilities sit with management. Do not memorize a 40-objective RACI.

Chapter 7 taught organizational structures as the key decision-making entities. This section is the documentation those entities need: a RACI chart on practices, not an eighth component and not a substitute for the other six slots you just integrated.

A structure without a RACI is a committee that “owns security” in the minutes and owns nothing on Tuesday. A RACI without a structure is a spreadsheet of job titles that do not exist. COBIT 2019 publishes generic RACI charts in Governance and Management Objectives so each process’s practices have suggested assignments. Enterprises tailor those suggestions. They do not invent a second framework, and Foundation candidates do not need a 40-objective memory palace.

The four letters, with the rules the exam actually scores

Write the letters in this order and keep the rules tight.

LetterMeaningCommunicationHow many
R — ResponsibleDoes the work; performs the activityWorks the taskOne or more
A — AccountableUltimately answerable that the activity is correct and completeOwns the outcomeExactly one
C — ConsultedOpinion is sought before or during the workTwo-wayZero or more
I — InformedKept up to date after decisions or resultsOne-wayZero or more

Lock four rules:

  1. Exactly one A. Two Accountables is how a practice becomes ownerless. Three Accountables is the same failure with more titles on the slide.
  2. Someone must be R. An A with no R is a sponsor who will be blamed after nobody did the work.
  3. C is a conversation. I is a notice. Mixing them is how a board gets buried in working sessions or a CISO learns about a production exception from the newspaper.
  4. RACI assigns practices, not “the whole of COBIT.” Charts sit on activities and practices inside an objective. They do not collapse 40 objectives into one row.

Northline Transit’s “digital safety” program lists the CIO, the chief safety officer, and the vendor account director as Accountable for the same go-live gate, and lists nobody as Responsible for writing the residual-risk acceptance. Three A’s, zero R. When the gate is missed, each Accountable can point at the other two, and no named person was assigned to produce the artifact. That chart is not conservative. It is invalid.

Where RACI lives — organizational structures, not a new component

RACI is not an eighth building block. It is how organizational structures make decision rights visible. The generic charts in the Objectives publication name roles such as the board, CEO, CIO, CISO, business executives, business process owners, steering committees, architecture board, program and project roles, heads of development and operations, service manager, information security manager, privacy officer, compliance, audit, and risk. Those are example decision-making entities. They are not extra components, and they are not exam domains.

Do not answer a “what is a component?” item with “RACI.” Answer organizational structures, then, if the stem asks how structures are documented for practices, say RACI charts.

Because the charts are generic, design factors change the variant of the structure: a small enterprise may combine CISO and CIO; a regulated bank may split security, risk, and compliance more finely. The letter rules do not change. Combined roles still need one A per practice.

Typical key roles you should be able to place, without reciting a 40-row matrix:

  • Governing body / board — Accountable on EDM Evaluate-Direct-Monitor practices; Informed on residual-risk and value trends from management.
  • CEO and executive management — Accountable on many APO practices that set direction inside management; Responsible or Consulted where the board is Accountable.
  • CIO — Accountable on a large share of I&T management practices across APO, BAI, DSS, and MEA; not the board’s stand-in for EDM01.
  • CISO / information security manager — Accountable or Responsible on security-management practices such as those under APO13 and related DSS security services; Consulted on changes and incidents that carry security impact.
  • Business executives and process owners — Accountable or Responsible where the practice is a business decision that I&T supports; Consulted on technical execution they do not own.
  • Audit, risk, compliance, privacy — usually Consulted or Informed, sometimes Responsible for assurance or compliance activities; almost never a third Accountable piled onto a management practice “for independence.”

Those placements are patterns, not a statute. The exam scores whether you put the board on EDM, management on APO/BAI/DSS/MEA, and a single A on the practice.

Governing body versus management on the chart

Carry Chapter 5’s split onto the RACI. Governance is distinct from management.

  • For EDM practices — Evaluate, Direct, Monitor; the five Ensured objectives — the governing body / board is typically Accountable. Management is typically Responsible, Consulted, or Informed. The board does not become Responsible for resetting passwords or closing incident tickets.
  • For APO, BAI, DSS, and MEA practices — the 35 Managed objectives — management is typically Accountable. The CIO, CISO, CFO, business executive, or another management role owns the practice. The board is typically Informed or Consulted on the few practices that need governing-body visibility, not Accountable for running the work.

Exam trap: putting the board as Accountable for DSS02 ticket handling, or putting the CIO as Accountable for EDM01 Ensured Governance Framework Setting and Maintenance because the CIO “is an officer.” Officer title does not move EDM off the board. Ticket work does not climb into EDM.

A second trap: copying ISACA’s generic chart as if it were a statute. The published RACI is a starting suggestion. Tailoring can move an R or a C. Tailoring cannot create three A’s, delete the only R, or hand the board the Responsible row for a service-desk practice.

Scenario: three Accountables, no Responsible

Northline’s board wants a single page that “shows COBIT is implemented.” A consultant prints one row titled “Security and incidents” and places A under Board, CEO, and CIO, with C under everyone else and no R anywhere.

Read that page the way the exam will:

  • It is not a COBIT RACI. It violates exactly one Accountable.
  • It assigns no one to do the work.
  • It mixes a governance concern and a management concern into one row, so EDM and DSS collapse.
  • It cannot be repaired by adding more C’s.

The fix is not a 40-row recitation you memorize for Foundation. Split the work back into practices. Put one A on each practice — board on the EDM direction-and-monitoring practices, CISO or CIO on the APO13 and DSS-style management practices. Name the R who will produce the policy, run the incident bridge, or update the register. Use C for the roles whose expertise is needed (legal, privacy, operations). Use I for the roles that need the result (board on residual-risk trend; service manager on a closed Sev-1).

If you can repair Northline’s slide, you can answer every RACI item this exam writes.

What you do not need to memorize

Do not build a personal 40-objective RACI. The Objectives publication is the source if you later implement. Foundation scores the letter rules, the one-A constraint, the two-way versus one-way split, the home of RACI on organizational structures, and the EDM-versus-management accountability pattern.

Reject these distractors:

  • RACI as an eighth component or a replacement for culture and skills
  • Multiple Accountables “for shared ownership”
  • Consulted and Informed used interchangeably
  • The board Responsible for DSS activities
  • A worldwide mandatory matrix that every enterprise must copy unchanged
Loading diagram...
RACI lives on organizational structures; one A, and EDM stays with the board
Test Your Knowledge

Which RACI rule does COBIT 2019 require on a practice or activity?

A
B
C
D
Test Your Knowledge

Northline Transit’s go-live chart lists the CIO, the chief safety officer, and the vendor director as Accountable for the same gate, and lists no one as Responsible. What is wrong?

A
B
C
D
Test Your Knowledge

In a typical COBIT 2019 RACI, who is Accountable for EDM practices versus APO, BAI, DSS, and MEA practices?

A
B
C
D