2.2 Organizational Structures, Roles & RACI Matrix

Key Takeaways

  • The Board of Directors holds ultimate fiduciary accountability for establishing enterprise risk appetite, approving governance policies, and ensuring active oversight of organizational risk management.
  • Business Unit Leaders / Business Process Owners are the true 'Risk Owners'—they own the business assets and processes, bear the operational consequences of risk events, and have the sole authority to accept residual risk or fund risk treatment.
  • The Chief Risk Officer (CRO) and Chief Information Security Officer (CISO) act as strategic advisors, risk facilitators, and program coordinators; neither the CISO nor IT operational staff own business risk.
  • A RACI matrix establishes clear governance by defining who is Responsible (completes the work), Accountable (has final decision and ownership; exactly one 'A' per activity), Consulted (provides subject matter expertise), and Informed (receives status updates).
  • The Enterprise Risk Committee provides cross-functional executive coordination, ensuring IT and cyber risks are integrated into broader enterprise risk management (ERM) rather than managed in technical silos.
Last updated: August 2026

2.2 Organizational Structures, Roles & RACI Matrix

Effective IT risk governance depends entirely on well-defined organizational structures, unambiguous authority limits, and clear lines of accountability. When risk roles and responsibilities are ill-defined or blurred, organizations suffer from governance vacuums—where critical vulnerabilities are ignored because operational teams assume security is responsible, while security assumes business units own the remediation budget.

ISACA emphasizes that risk management is an enterprise-wide responsibility that spans from the boardroom to frontline systems administrators. Understanding the specific duties of each role and applying responsibility assignment models (such as the RACI matrix) is vital for passing the CRISC exam and establishing resilient enterprise governance.

+-----------------------------------------------------------------------------+
|                 ENTERPRISE RISK GOVERNANCE ORGANIZATIONAL HIERARCHY         |
|                                                                             |
|                     +---------------------------------+                     |
|                     |       BOARD OF DIRECTORS        | (Ultimate Oversight)|
|                     |   (Audit / Risk Committee)      |                     |
|                     +----------------+----------------+                     |
|                                      |                                      |
|                                      v                                      |
|                     +---------------------------------+                     |
|                     |     CHIEF EXECUTIVE OFFICER     | (Executive Direction|
|                     |        & EXECUTIVE SUITE        |                     |
|                     +----------------+----------------+                     |
|                                      |                                      |
|       +------------------------------+------------------------------+       |
|       |                              |                              |       |
|       v                              v                              v       |
| +-------------+              +---------------+              +-------------+ |
| | ENTERPRISE  | <----------> |  CHIEF RISK   | <----------> | CHIEF INFO  | |
| | RISK COMM.  |              | OFFICER (CRO) |              |  SEC. OFF.  | |
| |(Exec Leads) |              | (Independent) |              |   (CISO)    | |
| +------+------+              +---------------+              +------+------+ |
|        |                                                           |        |
|        v                                                           v        |
| +------------------------------------+     +------------------------------+ |
| |      BUSINESS UNIT LEADERS         |     |    IT OPERATIONS / ENG.      | |
| |        (THE RISK OWNERS)           |     |     (CONTROL CUSTODIANS)     | |
| | - Own business processes & assets  |     | - Configure, deploy, & run   | |
| | - Authorize risk acceptance/budget |     |   technical controls         | |
| +------------------------------------+     +------------------------------+ |
+-----------------------------------------------------------------------------+

1. Key Governance & Risk Roles Breakdown

To correctly answer CRISC scenario questions, candidates must recognize the exact legal, fiduciary, and operational boundaries of each organizational stakeholder:

A. The Board of Directors (Governing Body)

  • Fiduciary Obligation: Holds ultimate legal and fiduciary accountability to shareholders, regulators, and stakeholders for the enterprise's long-term viability and risk posture.
  • Key Responsibilities:
    • Defines and approves the enterprise Risk Appetite and risk governance philosophy.
    • Sets the Tone at the Top, establishing ethical expectations and compliance culture.
    • Ensures adequate capital, executive staffing, and resources are allocated to risk management.
    • Oversees risk exposure via quarterly briefings from the Chief Risk Officer, CISO, and Board Audit/Risk Committees.
  • What the Board Does NOT Do: The Board never manages operational incidents, reviews individual technical log files, or chooses specific firewall vendors.

B. Executive Management (CEO, CFO, COO, CIO)

  • Operationalizing Governance: Translates Board-approved risk appetite into operational policies, capital allocations, and organizational performance objectives.
  • Chief Executive Officer (CEO): Ultimately accountable for day-to-day organizational execution and operational risk management.
  • Chief Financial Officer (CFO): Ensures financial risk controls, capital allocation for risk mitigation, and compliance with statutory financial reporting (e.g., SOX).
  • Chief Information Officer (CIO): Accountable for IT strategy, enterprise systems availability, digital transformation, and ensuring IT operations meet agreed-upon service levels.

C. The Enterprise Risk Committee (ERC / Risk Steering Committee)

  • Composition: Cross-functional executive body comprising Business Unit Heads, CRO, CISO, CIO, CFO, Chief Legal Counsel, and Chief Compliance Officer (Internal Audit attends as an independent observer).
  • Key Functions:
    • Meets regularly (typically monthly or quarterly) to evaluate the aggregated enterprise risk register.
    • Prioritizes capital investment for risk mitigation across competing business unit demands.
    • Reviews systemic Key Risk Indicators (KRIs) and escalates risk appetite breaches to the Board.
    • Ensures IT and cybersecurity risks are evaluated alongside market, credit, and operational risks rather than treated as isolated IT problems.

D. Chief Risk Officer (CRO) vs. Chief Information Security Officer (CISO)

  • Chief Risk Officer (CRO): Leads the independent enterprise risk management (ERM) function. Establishes enterprise-wide risk assessment methodologies, aggregates risk across all domains (credit, market, operational, cyber), and reports directly to executive leadership and the Board.
  • Chief Information Security Officer (CISO): Establishes information security architecture, cybersecurity operations, incident response plans, and security policies. The CISO acts as a risk advisor and facilitator to business leaders regarding cyber threats.

[!IMPORTANT] CRISC Golden Rule — The CISO Never Owns Business Risk: One of the most frequently tested concepts on the CRISC exam is that the CISO and IT teams do not own business risk. The CISO discovers, measures, and reports risk, and recommends control strategies. However, the business leader who relies on the system to generate revenue is the Risk Owner and makes the final decision on whether to accept, mitigate, transfer, or avoid that risk.

E. Business Unit Leaders (The True "Risk Owners")

  • Definition: The business executive who possesses budgetary authority over a business process, operational system, or data asset.
  • Key Authority:
    • Accountable for business assets and the impact of potential risk events.
    • Sole authority to accept residual risk that falls within authorized organizational risk tolerance thresholds.
    • Approves and funds risk treatment plans (e.g., purchasing insurance, hiring staff, buying controls).

F. Control Custodians / IT Administrators

  • Definition: The technical custodians who deploy, configure, maintain, and operate controls on behalf of the Risk Owner.
  • Responsibilities: Implementing access controls, configuring firewalls, backing up data, executing patch cycles, and monitoring technical alerts in accordance with policy.

2. Accountability vs. Responsibility: The Non-Delegation Principle

A critical distinction tested on the CRISC exam is the difference between Accountability and Responsibility:

+-----------------------------------------------------------------------------+
|                     ACCOUNTABILITY vs. RESPONSIBILITY                       |
|                                                                             |
|   ACCOUNTABILITY (Non-Delegable)           RESPONSIBILITY (Delegable)       |
|   --------------------------               --------------------------       |
|   - Cannot be shared or delegated.         - Can be shared and delegated.   |
|   - Belongs to exactly ONE individual.     - Can involve multiple actors.   |
|   - Holds ultimate decision & veto power.  - Executes the operational work. |
|   - Answers to Board and Regulators.       - Answers to the Accountable Lead|
|   - Examples: Risk Owner, Board, CEO.      - Examples: Engineers, Vendors.  |
+-----------------------------------------------------------------------------+

The Outsourcing Paradox

When an enterprise contracts a third-party Cloud Service Provider (CSP) or Managed Security Service Provider (MSSP):

  • The enterprise can delegate responsibility for operating firewalls, patching hypervisors, and managing physical data centers to the vendor.
  • The enterprise can NEVER delegate accountability. If customer data is compromised or regulatory non-compliance occurs, the enterprise governing body and business risk owner remain 100% accountable to regulators, courts, and customers.

3. The RACI Assignment Matrix Mechanics

The RACI Matrix (Responsible, Accountable, Consulted, Informed) is the standard governance tool used to clarify roles and eliminate operational ambiguity across complex risk and security workflows.

+-----------------------------------------------------------------------------+
|                           THE RACI MATRIX MECHANICS                         |
|                                                                             |
|   [R] RESPONSIBLE     The "Doer" - The individual or team that performs     |
|                       the activity to achieve the deliverable.              |
|                                                                             |
|   [A] ACCOUNTABLE     The "Owner" - The single individual with final        |
|                       decision-making power, ownership, and veto authority. |
|                       *MANDATORY RULE: Exactly ONE 'A' per activity!*       |
|                                                                             |
|   [C] CONSULTED       The "Advisor" - Subject matter experts who provide    |
|                       two-way input, analysis, or guidance before actions.  |
|                                                                             |
|   [I] INFORMED        The "Stakeholder" - Individuals kept updated with     |
|                       one-way notifications regarding progress or results.  |
+-----------------------------------------------------------------------------+

Core Rules for Building an Effective RACI Matrix:

  1. Exactly One 'A' Per Activity: If zero individuals are Accountable, no one takes ownership and tasks fail. If multiple individuals are assigned 'A', decision gridlock occurs and accountability is diluted.
  2. Minimize Excessive 'C's (Consulted): Consulting too many stakeholders creates bureaucratic paralysis, slows incident response, and increases meeting overhead.
  3. Clarity in 'R' (Responsible): Ensure those assigned 'R' possess the necessary authority, tools, skills, and budget from the Accountable leader to execute the task.

Illustrative Enterprise Risk & Security RACI Matrix

Governance / Operational ActivityBoard of DirectorsExecutive Comm. (CEO/CFO)Business Risk OwnerCISO / CROIT Operations CustodianInternal Audit
Establish Enterprise Risk AppetiteARCCII
Approve Business System Residual RiskIIACII
Design Information Security PolicyIICA / RCC
Deploy Operating System Security PatchesIIICA / RI
Conduct Independent Risk & Control AuditIIIIIA / R
Perform Third-Party Vendor Risk AssessmentIICA / RCI

[!NOTE] Reading the Table: In row 2 (Approve Business System Residual Risk), the Business Risk Owner is Accountable (A). The CISO is Consulted (C) to provide threat analysis and control recommendations, while IT Operations and Executive Management are Informed (I).


4. Organizational Governance Anti-Patterns & Exam Traps

+-----------------------------------------------------------------------------+
|                   FOUR CLASSIC GOVERNANCE ANTI-PATTERNS                     |
|                                                                             |
|   1. THE "IT OWNS THE RISK" ANTI-PATTERN                                    |
|      Symptom:   Business executives disclaim responsibility for cyber risk, |
|                 claiming "IT is in charge of computers."                    |
|      Result:    Security controls lack business context; risk is ignored.   |
|                                                                             |
|   2. THE "MULTIPLE ACCOUNTABLES" ANTI-PATTERN                               |
|      Symptom:   Assigning both the CIO and CISO as 'A' in the RACI matrix.  |
|      Result:    Finger-pointing during major breaches; zero clear ownership.|
|                                                                             |
|   3. THE "SILOED RISK COMMITTEE" ANTI-PATTERN                               |
|      Symptom:   IT Risk meets separately from Enterprise Financial Risk.    |
|      Result:    Inability to evaluate aggregated operational risk exposure. |
|                                                                             |
|   4. THE "AUDITOR AS DECISION MAKER" ANTI-PATTERN                           |
|      Symptom:   Allowing Internal Audit to approve system architecture.     |
|      Result:    Destroys audit independence (Third Line assurance failure). |
+-----------------------------------------------------------------------------+

Real-World Vignette: The Orphaned Database

An online retail conglomerate suffered a breach compromising 2.4 million payment records from an unpatched legacy analytics database.

  • The Investigation: The database was created five years earlier for a marketing campaign. When the marketing vice president left the company, no successor was assigned as the Risk Owner.
  • The RACI Void: The IT infrastructure team kept the server running (operational responsibility) but refused to upgrade the underlying OS because they had no budget or business approval to test application compatibility. The CISO had flagged the vulnerability, but had no authority to decommission the revenue-generating database.
  • Lesson for CRISC: Without clear assignment of a single Accountable Business Risk Owner for every enterprise asset, technical controls will inevitably fail.
Test Your Knowledge

A critical vulnerability is identified in an enterprise customer relationship management (CRM) application that processes online sales. Remediating the vulnerability requires taking the application offline for 24 hours during peak sales week. Who holds the PRIMARY authority to decide whether to accept the temporary risk or mandate immediate patching?

A
B
C
D
Test Your Knowledge

When designing a RACI responsibility assignment matrix for an enterprise risk management process, which structural rule must be strictly enforced to ensure effective governance?

A
B
C
D
Test Your Knowledge

What is the PRIMARY responsibility of the Board of Directors regarding enterprise information risk governance?

A
B
C
D
Test Your Knowledge

An enterprise contracts a major public cloud service provider (CSP) to host its core customer billing platform under an Infrastructure as a Service (IaaS) model. Which statement accurately describes the transfer of accountability and responsibility?

A
B
C
D