Operational Governance

The EU AI Act RACI Matrix

Vague legal requirements must translate into strict corporate accountability. Use our interactive matrix to determine exactly who is Responsible, Accountable, Consulted, and Informed for compliance tasks.

R Responsible (Does the work)
A Accountable (Buck stops here)
C Consulted (Provides input)
I Informed (Needs updates)
Compliance Task Legal & Compliance Engineering / IT Data Privacy (DPO) Product Owner
Risk Tier Classification A
Legal is fully Accountable for officially classifying the system's risk tier under Annex III to prevent catastrophic liability.
C
Engineering must be Consulted to explain exactly how the model architecture works so Legal can classify it.
C
DPO is Consulted to determine if biometric or sensitive data classification triggers high-risk status.
R
Product Owners are Responsible for initiating the classification review before launching any new feature.
Article 11 Technical Documentation C
Legal is Consulted to ensure the documentation meets regulatory standards.
R
Engineering is Responsible for actually writing the architecture, training data, and metric documentation.
I
DPO is Informed of data governance architectures documented by Engineering.
A
Product Owner is Accountable for ensuring documentation is complete before market launch.
Article 26 Human Oversight (Deployers) A
Legal is Accountable for proving to regulators that human oversight is structurally possible and enforced.
R
Engineering is Responsible for building the UI/UX tools (kill switches, override buttons) that enable human oversight.
I
DPO is Informed to ensure human oversight aligns with automated decision-making rules in GDPR.
R
Product Owners are Responsible for defining the Standard Operating Procedures for humans interacting with the AI.
Article 50 Transparency (Deepfakes/Chatbots) A
Legal is Accountable for drafting the exact disclosure copy to avoid deceptive practices.
R
Engineering is Responsible for implementing machine-readable watermarks and rendering UI disclosures.
C
DPO is Consulted to ensure transparency notices do not conflict with existing privacy policies.
R
Product Owners are Responsible for ensuring transparency features are prioritized in the sprint backlog.

Includes 25+ tasks covering the entire AI lifecycle.