ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. ISO 27001 RACI Matrix

ISO 27001 RACI Matrix

A Practical Responsibility Assignment Matrix for Your ISMS

Implementing ISO 27001 requires coordination across management, IT, engineering, HR, procurement and other business functions.

But who is responsible for performing each activity? Who approves decisions? Who must be consulted? And who simply needs to be informed?

An ISO 27001 RACI Matrix helps answer these questions by defining roles and responsibilities for the activities required to establish, implement, maintain and continually improve an Information Security Management System (ISMS).

For startups, a RACI matrix helps avoid unnecessary complexity. You do not need a separate person for every role. One person can hold multiple responsibilities, provided accountability is clear and appropriate objectivity is maintained.


1. What Does RACI Mean?

RACI is a responsibility assignment model that identifies the involvement of different roles in a particular activity.

LetterMeaningExplanation
RResponsiblePerforms the activity or completes the work.
AAccountableOwns the outcome and ensures the activity is completed.
CConsultedProvides input, expertise or advice.
IInformedReceives updates about decisions or outcomes.

Example: AWS Access Management

Suppose a SaaS startup needs to review privileged access to its AWS production environment.

  • Responsible: Cloud Administrator — performs the access review.
  • Accountable: CTO — owns the outcome.
  • Consulted: ISMS Manager — checks the review against security requirements.
  • Informed: CEO — receives updates where appropriate.

The matrix makes ownership clear before an issue occurs.


2. Roles Used in This RACI Matrix

This example assumes a startup operating a SaaS application on AWS.

RoleDescription
TMTop Management / CEO
ISMSISMS Manager / Security & Compliance Lead
CTOCTO / IT Manager
ENGEngineering Lead
HRHuman Resources
PROCProcurement / Operations
IAInternal Auditor
EMPEmployees and relevant contractors

Important: These are functional roles, not mandatory job titles. In a small startup, the CEO might also be the risk owner for certain business risks, while the CTO may manage IT and cloud security.


3. ISO 27001 RACI Matrix — Clauses 4 to 10

The following matrix covers key activities across the ISO 27001 management system.

Legend: R = Responsible · A = Accountable · C = Consulted · I = Informed

ISMS ActivityTMISMSCTOENGHRPROCIAEMP
Understand organizational contextARCCCCII
Identify interested partiesARCCCCII
Determine relevant requirementsARCCCCII
Define ISMS scopeARCCCCII
Establish the ISMSARCCCCII
Approve Information Security PolicyARCCCIII
Assign ISMS roles and responsibilitiesARCCCCII
Establish security objectivesARCCCCII
Determine required resourcesARCCCCII
Establish risk assessment methodologyARCCIICI
Conduct risk assessmentARRCCCII
Maintain risk registerIA/RCCCCII
Determine risk treatmentARRRCCII
Approve risk acceptance, where authorizedARCCCCII
Develop and maintain the SoAARCCCCII
Implement technical controlsICARIIII
Implement secure development controlsICCA/RIIII
Implement personnel security controlsICCIA/RIIR
Implement supplier security controlsICCCIA/RII
Manage documented informationIA/RCCCCII
Conduct security awarenessIACCRIIR
Monitor ISMS performanceARRCCCII
Conduct internal auditICCCCCA/RI
Conduct management reviewA/RRCCCCII
Manage corrective actionsARRRRRCI
Continually improve the ISMSARRCCCCI

How to use this matrix

  • Assign one clear Accountable role for each activity wherever practical.
  • Identify the person who will actually perform the work.
  • Consult people whose expertise or responsibilities affect the activity.
  • Inform relevant stakeholders about decisions and results.
  • Customize the assignments to match your real organization.

The matrix is a management tool. It does not replace the organization’s documented responsibilities, approval authorities or applicable ISO 27001 requirements.


4. RACI Matrix — Annex A Control Activities

The following examples show how responsibilities can be assigned to selected security controls.

Control ActivityTMISMSCTOENGHRPROCIA
Information security policiesARCCCII
Asset inventoryICA/RRCCI
Information classificationIARRCCI
Identity and access managementICA/RRCII
Privileged access reviewsICA/RCIII
Supplier security assessmentsICCCIA/RI
Incident managementARRRCCI
Personnel screening and onboardingICCIA/RII
Security awarenessIACCRII
Backup and recoveryICA/RCIII
Vulnerability managementICARIII
Secure software developmentICCA/RIII
Change managementICARIII
Business continuityARRCCCI
Internal auditICCCCCA/R

This is a sample assignment, not a mandatory mapping of ISO/IEC 27001 Annex A controls to job titles. The organization should assign ownership based on its selected controls, risks, structure and operating model.


5. Example: RACI for Employee Offboarding

Employee offboarding is a useful example because it involves multiple departments.

When an employee leaves, access must be removed, company assets recovered and relevant records retained.

ActivityHRIT/CTOISMSEmployee’s Manager
Confirm employee exitA/RIIC
Notify IT of terminationA/RIIC
Identify access to removeCA/RCC
Disable accountsIA/RII
Recover company devicesARIR
Confirm access removalIA/RCI
Retain required recordsA/RCCI
Escalate incomplete actionsCRAC

Evidence to retain

  • HR exit record
  • IT access-removal ticket
  • Account deactivation evidence
  • Company asset return record
  • Completion confirmation

The RACI matrix defines who does what. The evidence demonstrates that the process was actually completed.


6. Example: RACI for AWS Privileged Access Review

Objective: Ensure that only authorized personnel retain privileged access to the AWS production environment.

ActivityCEOISMSCTO/CloudEngineering
Define review requirementsIA/RCC
Export privileged user listICA/RI
Validate business needICAR
Identify excessive accessICA/RC
Approve access changesICAC
Remove unnecessary accessIIA/RC
Review evidenceIA/RCI
Escalate unresolved risksARRC

Evidence

  • AWS IAM user/role listing
  • Privileged access review record
  • Access approval
  • Remediation tickets
  • Updated IAM configuration
  • Review completion date

7. RACI for Internal Audit and Corrective Action

Internal audit requires particular attention to objectivity.

ActivityTMISMSControl OwnerInternal Auditor
Establish audit programmeARCC
Define audit scope and criteriaICCA/R
Conduct audit testingICCA/R
Report findingsICIA/R
Determine corrective actionICA/RC
Implement corrective actionICA/RI
Verify corrective action effectivenessICCA/R
Review overall audit resultsARCC

Independence principle: Where practical, the auditor should not audit their own work. If a startup has limited personnel, it can consider an appropriately independent person from another function or an external auditor.

The organization remains responsible for ensuring its internal audit programme meets applicable requirements.


8. How Startups Should Customize the RACI Matrix

A 15-person startup does not need to create separate departments just to complete this matrix.

For example:

Startup RoleResponsibilities It May Combine
CEOTop management, executive oversight, selected risk acceptance
CTOIT, cloud infrastructure, technical control ownership
Security/Compliance LeadISMS coordination, risk register, SoA, compliance tracking
Engineering LeadSecure development, code review, change management
HR/OperationsEmployee lifecycle, awareness coordination, supplier administration
External Internal AuditorIndependent internal audit support

One person may appear in several columns or hold multiple roles. However, the organization should consider conflicts of interest and ensure that critical decisions and audits receive appropriate oversight.


9. Common RACI Mistakes

Mistake 1: Multiple Accountable Roles

If everyone is accountable, no one clearly owns the outcome.

Solution: Assign one accountable role per activity wherever practical.

Mistake 2: The ISMS Manager Owns Everything

The ISMS Manager should coordinate the system, but operational control owners must perform their activities.

Solution: Assign control ownership to the functions that operate the controls.

Mistake 3: The Consultant Is the Owner of the ISMS

A consultant may assist with implementation, documentation and readiness, but the organization retains responsibility for its ISMS and management decisions.

Mistake 4: No Employee Responsibilities

Employees are often left out of the matrix even though they must follow security requirements and report incidents.

Solution: Include employees where their participation is required.

Mistake 5: The RACI Exists Only for Certification

A matrix that nobody follows provides little operational value.

Solution: Use it during onboarding, process design, risk treatment, internal audits and management reviews.


10. Downloadable-Style RACI Template

Use the following fields to build your own RACI matrix in Excel or a spreadsheet.

FieldDescription
Activity IDUnique reference
ISMS ActivityActivity or process
Requirement / ControlRelevant ISO clause, Annex A control or internal requirement
ResponsiblePerson or role performing the work
AccountablePerson or role owning the outcome
ConsultedPeople providing input
InformedPeople receiving updates
Evidence / RecordEvidence that the activity occurred
FrequencyHow often the activity is performed
Review DateDate of the latest review
RemarksAdditional notes

Final Takeaway

An effective ISO 27001 RACI matrix should make three things clear:

  1. Who performs the work?
  2. Who owns the outcome?
  3. What evidence demonstrates completion?

For startups, the goal is not to create a complicated organizational structure. It is to establish clear ownership, avoid responsibility gaps and ensure that information security becomes part of everyday business operations.

A simple RACI matrix that people actually use is more valuable than a detailed matrix that exists only in the ISMS documentation folder.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *