This is a ready-to-use RACI matrix for AI and machine learning in a GxP quality function. It assigns who is Responsible, Accountable, Consulted, and Informed across the AI lifecycle, from defining intended use through decommissioning, and names the roles the general data-governance RACI does not: model owner, AI risk officer, AI steward, human reviewer, and monitoring owner. AI programs fail most often at the handoffs between these roles, where each side assumes the other has it covered. This matrix closes that ambiguity. Replace every <<FILL: ...>> placeholder, map the generic roles to your real job titles, and route it through document control. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | AI Lifecycle Roles RACI |
| Document number | <<FILL: MTX-ID, e.g. MTX-QA-014>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Document owner | <<FILL: role, e.g. AI Risk Officer / Head of Quality>> |
| Applies to | <<FILL: sites / functions / AI portfolio in scope>> |
| Parent policy | <<FILL: POL-ID for the AI Governance Policy>> |
How to read this matrix
RACI assigns exactly one type of involvement per role per activity:
- R, Responsible: does the work. There can be more than one R.
- A, Accountable: owns the outcome and signs off. There is exactly one A per activity. The A cannot be delegated away.
- C, Consulted: gives input before the work is done (two-way).
- I, Informed: told after the fact (one-way).
Rules this matrix enforces:
- Every activity has exactly one A.
- The AI risk officer is structurally independent of the individual model-build teams; the same segregation logic that keeps a data originator from reviewing their own audit trail keeps risk oversight independent of the people building the model.
- Human-in-the-loop review and human-on-the-loop supervision are listed as separate activities, because they are different controls with different staffing and different accountable owners, even when the same person performs both on different use cases.
Roles
Map each generic role to your real title or organizational placement. Add or remove roles to fit your organization; keep the AI risk officer and AI steward roles distinct even where one person holds both, so the accountability is named explicitly rather than assumed.
| Code | Generic role | Your title / placement |
|---|---|---|
| MO | Model owner (business / process owner accountable for the use case) | <<FILL>> |
| ARO | AI risk officer (portfolio-level risk and tiering oversight) | <<FILL>> |
| AIS | AI steward (per-model or per-family lifecycle governance) | <<FILL>> |
| HR | Human reviewer (operational reviewer or supervisor) | <<FILL>> |
| MOW | Monitoring owner (day-to-day monitoring execution) | <<FILL>> |
| DS | Data science / ML engineering | <<FILL>> |
| QA | Quality Assurance / Validation | <<FILL>> |
| IT | IT / infrastructure | <<FILL>> |
RACI matrix
Define and build
| Activity | MO | ARO | AIS | HR | MOW | DS | QA | IT |
|---|---|---|---|---|---|---|---|---|
| Define intended use and risk tier | A | C | R | I | I | C | C | I |
| Prepare and label training data | C | I | C | I | I | A | C | I |
| Build and train the model | I | I | C | I | I | A | C | I |
| Validate on the held-out test set | C | I | C | I | I | R | A | I |
| Design the human oversight control | A | C | R | C | I | C | C | I |
Release and operate
| Activity | MO | ARO | AIS | HR | MOW | DS | QA | IT |
|---|---|---|---|---|---|---|---|---|
| Approve release to production | R | C | C | I | I | I | A | I |
| Exercise human-in-the-loop review, per case | I | I | I | A | I | I | I | I |
| Exercise human-on-the-loop supervision, by sample | I | I | I | I | A | I | I | I |
| Run day-to-day production monitoring | I | I | A | I | R | C | I | C |
| Provide the validated environment, access control, and hosting | I | I | C | I | C | C | C | A |
Change, escalate, and retire
| Activity | MO | ARO | AIS | HR | MOW | DS | QA | IT |
|---|---|---|---|---|---|---|---|---|
| Feed overrides back into the next model iteration | I | I | R | R | I | A | I | I |
| Approve a retrain or model change | C | C | R | I | I | R | A | I |
| Escalate a cross-model or portfolio-level risk | I | A | R | I | R | I | C | I |
| Report AI portfolio risk into management review | C | A | R | I | I | I | C | I |
| Decommission the model | A | I | R | I | I | C | C | C |
| Defend the model and its records during a regulatory inspection | C | C | A | C | C | C | R | C |
Segregation of duty note
Keep two separations explicit, and document a compensating control if your org chart forces an overlap:
- The AI risk officer holds the portfolio-level risk view and is not the same person who builds or is accountable for an individual model’s outcome (the model owner), so risk tiering is not self-graded by the people with an interest in a lighter tier.
- The human reviewer or supervisor exercising the oversight control is not the person who built the model, so the control retains an independent check rather than becoming the builder confirming their own work.
Acceptance criteria
This matrix is being used correctly when:
- Every activity has exactly one Accountable role, and that person can name what they own without checking the chart.
- Every production model has a named individual, not just a job title, for model owner, AI steward, and monitoring owner.
- The AI risk officer can name every model in the portfolio and its current risk tier without preparing in advance.
- The matrix is current with the live org chart and AI register, and is reviewed when either changes.
References
21 CFR Part 11 and EU GMP Annex 11 (electronic records, signatures, and the roles that control them, extended by analogy to AI system governance). ICH Q9(R1), Quality Risk Management, on risk-proportionate governance and the independence of the risk function from the activity being assessed. ICH Q10, Pharmaceutical Quality System, on management responsibility and the escalation of risk into management review. GAMP 5 Second Edition (ISPE, 2022), on lifecycle roles for computerized systems, including its treatment of machine learning and novel technologies. FDA guidance, “Data Integrity and Compliance With Drug CGMP: Questions and Answers” (December 2018), and PIC/S PI 041, on segregation of duties as a data-governance control, extended here to AI oversight roles.
Confirm the current version and clause numbers of each reference before issue.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (AI Risk Officer / Quality Head) | <<FILL>> |
Filled specimen
The following shows the role mapping and a sample of completed activity rows for an illustrative mid-size biologics company running three production AI use cases in quality. Titles and notes are illustrative; replace them with your own.
Role mapping as adopted:
| Code | Generic role | Title at this company |
|---|---|---|
| MO | Model owner | QC Laboratory Systems Manager (for the QC data review use case) |
| ARO | AI risk officer | Associate Director, Digital Quality (chairs the AI Governance Board) |
| AIS | AI steward | Senior Quality Systems Specialist, assigned per model family |
| HR | Human reviewer | QC Analyst II (human-in-the-loop reviewer) |
| MOW | Monitoring owner | Senior Quality Systems Specialist (same person as AIS in this program’s current size) |
| DS | Data science | ML Engineer, Digital Quality Analytics |
Sample of completed activity rows:
| Activity | A (who) | R (who) | Evidence held |
|---|---|---|---|
| Define intended use and risk tier | QC Laboratory Systems Manager | Senior Quality Systems Specialist | Intended-use statement AI-REG-011, risk tier Advisory |
| Approve release to production | QA Validation Lead | QC Laboratory Systems Manager | Release record VAL-2026-0201, QA disposition signed |
| Run day-to-day production monitoring | Senior Quality Systems Specialist | Senior Quality Systems Specialist | Weekly override-rate report, drift dashboard review log |
| Escalate a cross-model or portfolio-level risk | Associate Director, Digital Quality | Senior Quality Systems Specialist | AI Governance Board minutes, Q3 2026, risk escalation item 3 |
In this example the AI risk officer (Associate Director, Digital Quality) never builds or owns an individual model’s day-to-day operation; that sits with the model owner and steward. When the QC data review model’s override rate trended low, the steward flagged it through the monitoring row, and the risk officer took the portfolio-level pattern (a similar trend on a second model) to the AI Governance Board rather than each steward handling it in isolation. That separation, one person governing the model, a different person holding the cross-portfolio view, is what let the pattern get caught at all.
Common inspection findings this matrix prevents
- No one can say who is accountable for monitoring a production model, so a drift signal sits unactioned.
- The same person who built the model is also the only person who decided its risk tier, with no independent check.
- Multiple models show a similar problem in isolation because no role held the cross-portfolio view to notice the pattern.
- A RACI exists on paper but the org chart and the AI register do not match it, so the documented owners are not the real ones.
- An inspector asks who owns a specific AI system and gets three different answers from three different people.
How to adapt this matrix
- Set your document number, owner, and effective date in the header, and link the parent AI governance policy.
- Map every generic role code to a real title or organizational placement; where AI risk officer and AI steward are held by the same person today, say so explicitly rather than leaving the row ambiguous.
- Confirm each activity still has exactly one A after you edit it; this is the most common error when adapting any RACI.
- Add activities specific to your operation (for example a vendor-supplied model’s shared-responsibility handoffs, covered separately in the AI supplier shared-responsibility matrix, or a generative-AI-specific guardrail review).
- Review the matrix whenever the org chart or AI register changes, and confirm every regulation in the references against the current published version before issue.