RACI Example

Examples & Case Studies

Example RACI matrix for NUP projects

A RACI matrix clarifies roles and responsibilities across project activities. This example demonstrates how to create and use RACI matrices for NUP projects.

RACI Legend

RACI Definitions
RACI Definitions

Discovery Phase RACI

ActivityProduct OwnerBusiness AnalystArchitectLead DevQA LeadSecurity
Define project visionARCIII
Identify stakeholdersARCIII
Gather requirementsARCCCC
Prioritize requirementsRCCCCI
Create user storiesARCCCI
Define acceptance criteriaARCCRI
Risk assessmentACRCCR
Feasibility analysisACRRCC

Design Phase RACI

ActivityArchitectLead DevDeveloperSecurityQA LeadProduct Owner
Define architectureR/ACICII
Create ADRsRCCCII
Design APIsRRCCII
Design database schemaRRCIII
Threat modelingCCIR/AII
Review architectureARCRCI
Design review approvalACICII

Development Phase RACI

ActivityLead DevDeveloperQA LeadQA EngineerSecurityArchitect
Sprint planningARRCIC
Task breakdownRRCIIC
Code implementationARIIIC
Unit testingARCIII
Code reviewRRCICC
Integration testingCCARII
Bug fixingARCCII
DocumentationARCCIC

Testing Phase RACI

ActivityQA LeadQA EngineerDeveloperSecurityLead DevProduct Owner
Test planningARCCCI
Test case designARCCIC
Test executionARCIII
Defect reportingARCICI
Performance testingARCICI
Security testingCCIR/AII
UAT coordinationCRIIIA
Test sign-offARCCCR

Deployment Phase RACI

ActivityDevOps LeadDeveloperQA LeadSecurityLead DevProduct Owner
Deployment planningACCCRI
Environment setupRCICCI
Deployment executionRCCCCI
Smoke testingICRICI
Release notesCRCIAI
Rollback planningRCCCAI
Go-live approvalCICCCA
Post-deployment reviewRRRRAI

Security Activities RACI

ActivitySecurity LeadDeveloperArchitectQADevOpsCISO
Security requirementsRCCIIA
Threat modelingRCRIIA
Secure code reviewRRCIII
SAST scanningRCIICI
DAST scanningRIICCI
Penetration testingAICICR
Vulnerability remediationCRCICA
Security auditRCCCCA
Incident responseRCIIRA

Compliance Activities RACI

ActivityCompliance OfficerSecurity LeadProduct OwnerQA LeadLegalCISO
Compliance assessmentRCCICA
Control implementationCRICIA
Evidence collectionRRCRII
Audit preparationRCCCCA
Audit responseRRCCRA
Remediation planningRRCCCA
Policy updatesRCIIRA

Creating Your RACI Matrix

Step 1: List Activities

1. Identify all activities/deliverables
2. Break down into discrete, actionable items
3. Group by phase or workstream
4. Ensure completeness

Step 2: Identify Roles

1. List all roles involved
2. Use role names, not person names
3. Include all relevant stakeholders
4. Consider external parties

Step 3: Assign Responsibilities

For each activity:
1. Assign exactly one A (Accountable)
2. Assign at least one R (Responsible)
3. Identify who needs to be Consulted
4. Determine who should be Informed

Step 4: Validate

Check for:
□ One A per activity
□ At least one R per activity
□ No role overload (too many Rs)
□ Appropriate C and I assignments
□ Coverage of all critical activities

Common RACI Patterns

Pattern 1: Standard Development Activity

Product Owner: A
Lead Developer: R
Developer: R
QA: C

Pattern 2: Security Review

Security Lead: R/A
Developer: C
Architect: C
QA: I

Pattern 3: Release Decision

Product Owner: A
QA Lead: R
Lead Developer: C
Security: C

Anti-Patterns to Avoid

Anti-PatternProblemSolution
Multiple A'sNo clear accountabilitySingle A per activity
No ANo decision makerAssign accountable role
No RWork won't get doneAssign responsible parties
Everyone is CDecision paralysisLimit consulted parties
No one is ICommunication gapsIdentify stakeholders
R without AWork without authorityEnsure A has authority

Compliance

This section fulfills ISO 13485 requirements for responsibility and authority (5.5.1), design and development planning (7.3.2), and competence (6.2), and ISO 27001 requirements for roles and responsibilities (A.5.2), segregation of duties (A.5.3), and information security in project management (A.5.8).

View full compliance matrix

Sign in or sign up

Enter your work email to receive a temporary sign-in link.

By continuing, you agree to our Terms of Service and Privacy Policy.