A Practical Responsibility Assignment Matrix for Your ISMS
Implementing ISO 27001 requires coordination across management, IT, engineering, HR, procurement and other business functions.
But who is responsible for performing each activity? Who approves decisions? Who must be consulted? And who simply needs to be informed?
An ISO 27001 RACI Matrix helps answer these questions by defining roles and responsibilities for the activities required to establish, implement, maintain and continually improve an Information Security Management System (ISMS).
For startups, a RACI matrix helps avoid unnecessary complexity. You do not need a separate person for every role. One person can hold multiple responsibilities, provided accountability is clear and appropriate objectivity is maintained.
1. What Does RACI Mean?
RACI is a responsibility assignment model that identifies the involvement of different roles in a particular activity.
| Letter | Meaning | Explanation |
|---|---|---|
| R | Responsible | Performs the activity or completes the work. |
| A | Accountable | Owns the outcome and ensures the activity is completed. |
| C | Consulted | Provides input, expertise or advice. |
| I | Informed | Receives updates about decisions or outcomes. |
Example: AWS Access Management
Suppose a SaaS startup needs to review privileged access to its AWS production environment.
- Responsible: Cloud Administrator — performs the access review.
- Accountable: CTO — owns the outcome.
- Consulted: ISMS Manager — checks the review against security requirements.
- Informed: CEO — receives updates where appropriate.
The matrix makes ownership clear before an issue occurs.
2. Roles Used in This RACI Matrix
This example assumes a startup operating a SaaS application on AWS.
| Role | Description |
|---|---|
| TM | Top Management / CEO |
| ISMS | ISMS Manager / Security & Compliance Lead |
| CTO | CTO / IT Manager |
| ENG | Engineering Lead |
| HR | Human Resources |
| PROC | Procurement / Operations |
| IA | Internal Auditor |
| EMP | Employees and relevant contractors |
Important: These are functional roles, not mandatory job titles. In a small startup, the CEO might also be the risk owner for certain business risks, while the CTO may manage IT and cloud security.
3. ISO 27001 RACI Matrix — Clauses 4 to 10
The following matrix covers key activities across the ISO 27001 management system.
Legend: R = Responsible · A = Accountable · C = Consulted · I = Informed
| ISMS Activity | TM | ISMS | CTO | ENG | HR | PROC | IA | EMP |
|---|---|---|---|---|---|---|---|---|
| Understand organizational context | A | R | C | C | C | C | I | I |
| Identify interested parties | A | R | C | C | C | C | I | I |
| Determine relevant requirements | A | R | C | C | C | C | I | I |
| Define ISMS scope | A | R | C | C | C | C | I | I |
| Establish the ISMS | A | R | C | C | C | C | I | I |
| Approve Information Security Policy | A | R | C | C | C | I | I | I |
| Assign ISMS roles and responsibilities | A | R | C | C | C | C | I | I |
| Establish security objectives | A | R | C | C | C | C | I | I |
| Determine required resources | A | R | C | C | C | C | I | I |
| Establish risk assessment methodology | A | R | C | C | I | I | C | I |
| Conduct risk assessment | A | R | R | C | C | C | I | I |
| Maintain risk register | I | A/R | C | C | C | C | I | I |
| Determine risk treatment | A | R | R | R | C | C | I | I |
| Approve risk acceptance, where authorized | A | R | C | C | C | C | I | I |
| Develop and maintain the SoA | A | R | C | C | C | C | I | I |
| Implement technical controls | I | C | A | R | I | I | I | I |
| Implement secure development controls | I | C | C | A/R | I | I | I | I |
| Implement personnel security controls | I | C | C | I | A/R | I | I | R |
| Implement supplier security controls | I | C | C | C | I | A/R | I | I |
| Manage documented information | I | A/R | C | C | C | C | I | I |
| Conduct security awareness | I | A | C | C | R | I | I | R |
| Monitor ISMS performance | A | R | R | C | C | C | I | I |
| Conduct internal audit | I | C | C | C | C | C | A/R | I |
| Conduct management review | A/R | R | C | C | C | C | I | I |
| Manage corrective actions | A | R | R | R | R | R | C | I |
| Continually improve the ISMS | A | R | R | C | C | C | C | I |
How to use this matrix
- Assign one clear Accountable role for each activity wherever practical.
- Identify the person who will actually perform the work.
- Consult people whose expertise or responsibilities affect the activity.
- Inform relevant stakeholders about decisions and results.
- Customize the assignments to match your real organization.
The matrix is a management tool. It does not replace the organization’s documented responsibilities, approval authorities or applicable ISO 27001 requirements.
4. RACI Matrix — Annex A Control Activities
The following examples show how responsibilities can be assigned to selected security controls.
| Control Activity | TM | ISMS | CTO | ENG | HR | PROC | IA |
|---|---|---|---|---|---|---|---|
| Information security policies | A | R | C | C | C | I | I |
| Asset inventory | I | C | A/R | R | C | C | I |
| Information classification | I | A | R | R | C | C | I |
| Identity and access management | I | C | A/R | R | C | I | I |
| Privileged access reviews | I | C | A/R | C | I | I | I |
| Supplier security assessments | I | C | C | C | I | A/R | I |
| Incident management | A | R | R | R | C | C | I |
| Personnel screening and onboarding | I | C | C | I | A/R | I | I |
| Security awareness | I | A | C | C | R | I | I |
| Backup and recovery | I | C | A/R | C | I | I | I |
| Vulnerability management | I | C | A | R | I | I | I |
| Secure software development | I | C | C | A/R | I | I | I |
| Change management | I | C | A | R | I | I | I |
| Business continuity | A | R | R | C | C | C | I |
| Internal audit | I | C | C | C | C | C | A/R |
This is a sample assignment, not a mandatory mapping of ISO/IEC 27001 Annex A controls to job titles. The organization should assign ownership based on its selected controls, risks, structure and operating model.
5. Example: RACI for Employee Offboarding
Employee offboarding is a useful example because it involves multiple departments.
When an employee leaves, access must be removed, company assets recovered and relevant records retained.
| Activity | HR | IT/CTO | ISMS | Employee’s Manager |
|---|---|---|---|---|
| Confirm employee exit | A/R | I | I | C |
| Notify IT of termination | A/R | I | I | C |
| Identify access to remove | C | A/R | C | C |
| Disable accounts | I | A/R | I | I |
| Recover company devices | A | R | I | R |
| Confirm access removal | I | A/R | C | I |
| Retain required records | A/R | C | C | I |
| Escalate incomplete actions | C | R | A | C |
Evidence to retain
- HR exit record
- IT access-removal ticket
- Account deactivation evidence
- Company asset return record
- Completion confirmation
The RACI matrix defines who does what. The evidence demonstrates that the process was actually completed.
6. Example: RACI for AWS Privileged Access Review
Objective: Ensure that only authorized personnel retain privileged access to the AWS production environment.
| Activity | CEO | ISMS | CTO/Cloud | Engineering |
|---|---|---|---|---|
| Define review requirements | I | A/R | C | C |
| Export privileged user list | I | C | A/R | I |
| Validate business need | I | C | A | R |
| Identify excessive access | I | C | A/R | C |
| Approve access changes | I | C | A | C |
| Remove unnecessary access | I | I | A/R | C |
| Review evidence | I | A/R | C | I |
| Escalate unresolved risks | A | R | R | C |
Evidence
- AWS IAM user/role listing
- Privileged access review record
- Access approval
- Remediation tickets
- Updated IAM configuration
- Review completion date
7. RACI for Internal Audit and Corrective Action
Internal audit requires particular attention to objectivity.
| Activity | TM | ISMS | Control Owner | Internal Auditor |
|---|---|---|---|---|
| Establish audit programme | A | R | C | C |
| Define audit scope and criteria | I | C | C | A/R |
| Conduct audit testing | I | C | C | A/R |
| Report findings | I | C | I | A/R |
| Determine corrective action | I | C | A/R | C |
| Implement corrective action | I | C | A/R | I |
| Verify corrective action effectiveness | I | C | C | A/R |
| Review overall audit results | A | R | C | C |
Independence principle: Where practical, the auditor should not audit their own work. If a startup has limited personnel, it can consider an appropriately independent person from another function or an external auditor.
The organization remains responsible for ensuring its internal audit programme meets applicable requirements.
8. How Startups Should Customize the RACI Matrix
A 15-person startup does not need to create separate departments just to complete this matrix.
For example:
| Startup Role | Responsibilities It May Combine |
|---|---|
| CEO | Top management, executive oversight, selected risk acceptance |
| CTO | IT, cloud infrastructure, technical control ownership |
| Security/Compliance Lead | ISMS coordination, risk register, SoA, compliance tracking |
| Engineering Lead | Secure development, code review, change management |
| HR/Operations | Employee lifecycle, awareness coordination, supplier administration |
| External Internal Auditor | Independent internal audit support |
One person may appear in several columns or hold multiple roles. However, the organization should consider conflicts of interest and ensure that critical decisions and audits receive appropriate oversight.
9. Common RACI Mistakes
Mistake 1: Multiple Accountable Roles
If everyone is accountable, no one clearly owns the outcome.
Solution: Assign one accountable role per activity wherever practical.
Mistake 2: The ISMS Manager Owns Everything
The ISMS Manager should coordinate the system, but operational control owners must perform their activities.
Solution: Assign control ownership to the functions that operate the controls.
Mistake 3: The Consultant Is the Owner of the ISMS
A consultant may assist with implementation, documentation and readiness, but the organization retains responsibility for its ISMS and management decisions.
Mistake 4: No Employee Responsibilities
Employees are often left out of the matrix even though they must follow security requirements and report incidents.
Solution: Include employees where their participation is required.
Mistake 5: The RACI Exists Only for Certification
A matrix that nobody follows provides little operational value.
Solution: Use it during onboarding, process design, risk treatment, internal audits and management reviews.
10. Downloadable-Style RACI Template
Use the following fields to build your own RACI matrix in Excel or a spreadsheet.
| Field | Description |
|---|---|
| Activity ID | Unique reference |
| ISMS Activity | Activity or process |
| Requirement / Control | Relevant ISO clause, Annex A control or internal requirement |
| Responsible | Person or role performing the work |
| Accountable | Person or role owning the outcome |
| Consulted | People providing input |
| Informed | People receiving updates |
| Evidence / Record | Evidence that the activity occurred |
| Frequency | How often the activity is performed |
| Review Date | Date of the latest review |
| Remarks | Additional notes |
Final Takeaway
An effective ISO 27001 RACI matrix should make three things clear:
- Who performs the work?
- Who owns the outcome?
- What evidence demonstrates completion?
For startups, the goal is not to create a complicated organizational structure. It is to establish clear ownership, avoid responsibility gaps and ensure that information security becomes part of everyday business operations.
A simple RACI matrix that people actually use is more valuable than a detailed matrix that exists only in the ISMS documentation folder.
