RACI Matrix — AIMS Activities
ISO/IEC 42001:2023 | Clause 5.3 — Template
Document ID: AIMS-RACI-001
Version: 1.0
Owner: AI Governance Lead
Date: ___________________________
Review Cycle: Annual or upon role/structure change
Code
Meaning
R
Responsible — Does the work
A
Accountable — Ultimate owner; signs off
C
Consulted — Input required before action
I
Informed — Notified of outcome
AIMS Activity
CEO / Top Mgmt
AI Gov Lead / CAIO
AI System Owner
AI Developer / MLOps
DPO
Risk Manager
Internal Auditor
HR / People Lead
Legal
CLAUSE 4 — CONTEXT
Context analysis and PESTLE
I
A/R
C
I
C
C
I
I
C
AI Systems Inventory maintenance
I
A
R
R
I
C
I
I
I
Interested Parties Register
I
A/R
C
I
C
C
I
I
C
Scope Statement approval
A
R
C
I
C
C
I
I
C
CLAUSE 5 — LEADERSHIP
AI Policy approval
A
R
C
I
C
C
I
I
C
AI Policy communication
I
A/R
I
I
I
I
I
R
I
Role and responsibility assignment
A
R
C
I
C
C
I
C
I
Governance committee establishment
A
R
C
I
C
C
I
I
I
Budget approval for AIMS
A
R
C
I
I
C
I
I
I
CLAUSE 6 — PLANNING
AI risk assessment (per system)
I
A
R
C
C
R
I
I
C
Risk treatment planning
I
A
R
C
C
R
I
I
C
Statement of Applicability
I
A/R
C
C
C
C
I
I
I
AI objectives setting
A
R
C
I
C
C
I
I
I
Change management
I
A/R
C
C
I
C
I
I
I
CLAUSE 7 — SUPPORT
Resource planning
A
R
C
I
I
C
I
I
I
Competence gap analysis
I
A
R
R
I
I
I
R
I
Training programme delivery
I
A
I
I
I
I
I
R
I
Training records maintenance
I
A
I
I
I
I
I
R
I
Awareness communications
I
A/R
I
I
I
I
I
R
I
Document control
I
A/R
C
C
C
C
I
I
I
CLAUSE 8 — OPERATION
AI Impact Assessment
I
A
R
C
C
C
I
I
C
AI Lifecycle management
I
A
R
R
C
C
I
I
C
Pre-deployment gate review
I
A
R
C
C
C
I
I
I
Supplier risk assessment
I
A
R
C
C
R
I
I
C
AI change control
I
A
R
C
I
C
I
I
I
CLAUSE 9 — PERFORMANCE
Performance monitoring
I
A
R
R
I
R
I
I
I
Internal audit planning
I
A
I
I
I
I
R
I
I
Internal audit execution
I
I
C
C
C
C
A/R
I
I
Management review (chair)
A/R
R
C
I
C
C
C
C
C
Management review actions
A
R
C
I
I
C
I
I
I
CLAUSE 10 — IMPROVEMENT
Nonconformity recording
I
A/R
R
R
C
C
I
I
I
Root cause analysis
I
A
R
R
C
C
C
I
I
Corrective action implementation
I
A
R
R
C
C
I
I
C
Continual improvement log
I
A/R
C
C
I
C
I
I
I
AI incident management
I
A
R
R
C
C
I
I
C
Role Descriptions Summary
Role
Description
CEO / Top Management
Ultimate accountability for AIMS; approves policy and resources
AI Governance Lead / CAIO
Day-to-day AIMS management; owns most AIMS processes
AI System Owner
Accountable for specific AI systems in scope
AI Developer / MLOps
Technical implementation; model documentation; bias testing
DPO
Data Privacy Officer; AI + personal data compliance interface
Risk Manager
AI risk register; treatment plans; monitoring oversight
Internal Auditor
AIMS internal audits; independent of areas audited
HR / People Lead
Competence, training, awareness programmes
Legal
Regulatory compliance; contractual controls; AI disclosures
See AI-SYSTEM-OWNERSHIP-REGISTER.md for per-system accountability assignments.
Version
Date
Changes
Approved By
1.0
Initial issue
ISO/IEC 42001:2023 AI Governance Toolkit | Clause 5.3 | See root README.md for full index