A RACI matrix clarifies roles and responsibilities across project activities. This example demonstrates how to create and use RACI matrices for NUP projects.
RACI Legend
Discovery Phase RACI
| Activity | Product Owner | Business Analyst | Architect | Lead Dev | QA Lead | Security |
|---|---|---|---|---|---|---|
| Define project vision | A | R | C | I | I | I |
| Identify stakeholders | A | R | C | I | I | I |
| Gather requirements | A | R | C | C | C | C |
| Prioritize requirements | R | C | C | C | C | I |
| Create user stories | A | R | C | C | C | I |
| Define acceptance criteria | A | R | C | C | R | I |
| Risk assessment | A | C | R | C | C | R |
| Feasibility analysis | A | C | R | R | C | C |
Design Phase RACI
| Activity | Architect | Lead Dev | Developer | Security | QA Lead | Product Owner |
|---|---|---|---|---|---|---|
| Define architecture | R/A | C | I | C | I | I |
| Create ADRs | R | C | C | C | I | I |
| Design APIs | R | R | C | C | I | I |
| Design database schema | R | R | C | I | I | I |
| Threat modeling | C | C | I | R/A | I | I |
| Review architecture | A | R | C | R | C | I |
| Design review approval | A | C | I | C | I | I |
Development Phase RACI
| Activity | Lead Dev | Developer | QA Lead | QA Engineer | Security | Architect |
|---|---|---|---|---|---|---|
| Sprint planning | A | R | R | C | I | C |
| Task breakdown | R | R | C | I | I | C |
| Code implementation | A | R | I | I | I | C |
| Unit testing | A | R | C | I | I | I |
| Code review | R | R | C | I | C | C |
| Integration testing | C | C | A | R | I | I |
| Bug fixing | A | R | C | C | I | I |
| Documentation | A | R | C | C | I | C |
Testing Phase RACI
| Activity | QA Lead | QA Engineer | Developer | Security | Lead Dev | Product Owner |
|---|---|---|---|---|---|---|
| Test planning | A | R | C | C | C | I |
| Test case design | A | R | C | C | I | C |
| Test execution | A | R | C | I | I | I |
| Defect reporting | A | R | C | I | C | I |
| Performance testing | A | R | C | I | C | I |
| Security testing | C | C | I | R/A | I | I |
| UAT coordination | C | R | I | I | I | A |
| Test sign-off | A | R | C | C | C | R |
Deployment Phase RACI
| Activity | DevOps Lead | Developer | QA Lead | Security | Lead Dev | Product Owner |
|---|---|---|---|---|---|---|
| Deployment planning | A | C | C | C | R | I |
| Environment setup | R | C | I | C | C | I |
| Deployment execution | R | C | C | C | C | I |
| Smoke testing | I | C | R | I | C | I |
| Release notes | C | R | C | I | A | I |
| Rollback planning | R | C | C | C | A | I |
| Go-live approval | C | I | C | C | C | A |
| Post-deployment review | R | R | R | R | A | I |
Security Activities RACI
| Activity | Security Lead | Developer | Architect | QA | DevOps | CISO |
|---|---|---|---|---|---|---|
| Security requirements | R | C | C | I | I | A |
| Threat modeling | R | C | R | I | I | A |
| Secure code review | R | R | C | I | I | I |
| SAST scanning | R | C | I | I | C | I |
| DAST scanning | R | I | I | C | C | I |
| Penetration testing | A | I | C | I | C | R |
| Vulnerability remediation | C | R | C | I | C | A |
| Security audit | R | C | C | C | C | A |
| Incident response | R | C | I | I | R | A |
Compliance Activities RACI
| Activity | Compliance Officer | Security Lead | Product Owner | QA Lead | Legal | CISO |
|---|---|---|---|---|---|---|
| Compliance assessment | R | C | C | I | C | A |
| Control implementation | C | R | I | C | I | A |
| Evidence collection | R | R | C | R | I | I |
| Audit preparation | R | C | C | C | C | A |
| Audit response | R | R | C | C | R | A |
| Remediation planning | R | R | C | C | C | A |
| Policy updates | R | C | I | I | R | A |
Creating Your RACI Matrix
Step 1: List Activities
1. Identify all activities/deliverables
2. Break down into discrete, actionable items
3. Group by phase or workstream
4. Ensure completeness
Step 2: Identify Roles
1. List all roles involved
2. Use role names, not person names
3. Include all relevant stakeholders
4. Consider external parties
Step 3: Assign Responsibilities
For each activity:
1. Assign exactly one A (Accountable)
2. Assign at least one R (Responsible)
3. Identify who needs to be Consulted
4. Determine who should be Informed
Step 4: Validate
Check for:
□ One A per activity
□ At least one R per activity
□ No role overload (too many Rs)
□ Appropriate C and I assignments
□ Coverage of all critical activities
Common RACI Patterns
Pattern 1: Standard Development Activity
Product Owner: A
Lead Developer: R
Developer: R
QA: C
Pattern 2: Security Review
Security Lead: R/A
Developer: C
Architect: C
QA: I
Pattern 3: Release Decision
Product Owner: A
QA Lead: R
Lead Developer: C
Security: C
Anti-Patterns to Avoid
| Anti-Pattern | Problem | Solution |
|---|---|---|
| Multiple A's | No clear accountability | Single A per activity |
| No A | No decision maker | Assign accountable role |
| No R | Work won't get done | Assign responsible parties |
| Everyone is C | Decision paralysis | Limit consulted parties |
| No one is I | Communication gaps | Identify stakeholders |
| R without A | Work without authority | Ensure A has authority |
Related Resources
- Project Management Templates - PM templates
- Roles - NUP role definitions
- Workflow Examples - Process workflows
Compliance
This section fulfills ISO 13485 requirements for responsibility and authority (5.5.1), design and development planning (7.3.2), and competence (6.2), and ISO 27001 requirements for roles and responsibilities (A.5.2), segregation of duties (A.5.3), and information security in project management (A.5.8).