Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Matrix Plug-and-play starting point AI & Automation

Matrix: AI Lifecycle Roles RACI

A plug-and-play RACI matrix assigning responsibility, accountability, consultation, and information across every stage of the AI lifecycle in a GxP quality function: model owner, AI risk officer, AI steward, human reviewer, monitoring owner, data science, QA, and IT, with a filled specimen and the regulations it satisfies.

Document type: Matrix

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use RACI matrix for AI and machine learning in a GxP quality function. It assigns who is Responsible, Accountable, Consulted, and Informed across the AI lifecycle, from defining intended use through decommissioning, and names the roles the general data-governance RACI does not: model owner, AI risk officer, AI steward, human reviewer, and monitoring owner. AI programs fail most often at the handoffs between these roles, where each side assumes the other has it covered. This matrix closes that ambiguity. Replace every <<FILL: ...>> placeholder, map the generic roles to your real job titles, and route it through document control. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titleAI Lifecycle Roles RACI
Document number<<FILL: MTX-ID, e.g. MTX-QA-014>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Document owner<<FILL: role, e.g. AI Risk Officer / Head of Quality>>
Applies to<<FILL: sites / functions / AI portfolio in scope>>
Parent policy<<FILL: POL-ID for the AI Governance Policy>>

How to read this matrix

RACI assigns exactly one type of involvement per role per activity:

  • R, Responsible: does the work. There can be more than one R.
  • A, Accountable: owns the outcome and signs off. There is exactly one A per activity. The A cannot be delegated away.
  • C, Consulted: gives input before the work is done (two-way).
  • I, Informed: told after the fact (one-way).

Rules this matrix enforces:

  1. Every activity has exactly one A.
  2. The AI risk officer is structurally independent of the individual model-build teams; the same segregation logic that keeps a data originator from reviewing their own audit trail keeps risk oversight independent of the people building the model.
  3. Human-in-the-loop review and human-on-the-loop supervision are listed as separate activities, because they are different controls with different staffing and different accountable owners, even when the same person performs both on different use cases.

Roles

Map each generic role to your real title or organizational placement. Add or remove roles to fit your organization; keep the AI risk officer and AI steward roles distinct even where one person holds both, so the accountability is named explicitly rather than assumed.

CodeGeneric roleYour title / placement
MOModel owner (business / process owner accountable for the use case)<<FILL>>
AROAI risk officer (portfolio-level risk and tiering oversight)<<FILL>>
AISAI steward (per-model or per-family lifecycle governance)<<FILL>>
HRHuman reviewer (operational reviewer or supervisor)<<FILL>>
MOWMonitoring owner (day-to-day monitoring execution)<<FILL>>
DSData science / ML engineering<<FILL>>
QAQuality Assurance / Validation<<FILL>>
ITIT / infrastructure<<FILL>>

RACI matrix

Define and build

ActivityMOAROAISHRMOWDSQAIT
Define intended use and risk tierACRIICCI
Prepare and label training dataCICIIACI
Build and train the modelIICIIACI
Validate on the held-out test setCICIIRAI
Design the human oversight controlACRCICCI

Release and operate

ActivityMOAROAISHRMOWDSQAIT
Approve release to productionRCCIIIAI
Exercise human-in-the-loop review, per caseIIIAIIII
Exercise human-on-the-loop supervision, by sampleIIIIAIII
Run day-to-day production monitoringIIAIRCIC
Provide the validated environment, access control, and hostingIICICCCA

Change, escalate, and retire

ActivityMOAROAISHRMOWDSQAIT
Feed overrides back into the next model iterationIIRRIAII
Approve a retrain or model changeCCRIIRAI
Escalate a cross-model or portfolio-level riskIARIRICI
Report AI portfolio risk into management reviewCARIIICI
Decommission the modelAIRIICCC
Defend the model and its records during a regulatory inspectionCCACCCRC

Segregation of duty note

Keep two separations explicit, and document a compensating control if your org chart forces an overlap:

  • The AI risk officer holds the portfolio-level risk view and is not the same person who builds or is accountable for an individual model’s outcome (the model owner), so risk tiering is not self-graded by the people with an interest in a lighter tier.
  • The human reviewer or supervisor exercising the oversight control is not the person who built the model, so the control retains an independent check rather than becoming the builder confirming their own work.

Acceptance criteria

This matrix is being used correctly when:

  • Every activity has exactly one Accountable role, and that person can name what they own without checking the chart.
  • Every production model has a named individual, not just a job title, for model owner, AI steward, and monitoring owner.
  • The AI risk officer can name every model in the portfolio and its current risk tier without preparing in advance.
  • The matrix is current with the live org chart and AI register, and is reviewed when either changes.

References

21 CFR Part 11 and EU GMP Annex 11 (electronic records, signatures, and the roles that control them, extended by analogy to AI system governance). ICH Q9(R1), Quality Risk Management, on risk-proportionate governance and the independence of the risk function from the activity being assessed. ICH Q10, Pharmaceutical Quality System, on management responsibility and the escalation of risk into management review. GAMP 5 Second Edition (ISPE, 2022), on lifecycle roles for computerized systems, including its treatment of machine learning and novel technologies. FDA guidance, “Data Integrity and Compliance With Drug CGMP: Questions and Answers” (December 2018), and PIC/S PI 041, on segregation of duties as a data-governance control, extended here to AI oversight roles.

Confirm the current version and clause numbers of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (AI Risk Officer / Quality Head)<<FILL>>

Filled specimen

The following shows the role mapping and a sample of completed activity rows for an illustrative mid-size biologics company running three production AI use cases in quality. Titles and notes are illustrative; replace them with your own.

Role mapping as adopted:

CodeGeneric roleTitle at this company
MOModel ownerQC Laboratory Systems Manager (for the QC data review use case)
AROAI risk officerAssociate Director, Digital Quality (chairs the AI Governance Board)
AISAI stewardSenior Quality Systems Specialist, assigned per model family
HRHuman reviewerQC Analyst II (human-in-the-loop reviewer)
MOWMonitoring ownerSenior Quality Systems Specialist (same person as AIS in this program’s current size)
DSData scienceML Engineer, Digital Quality Analytics

Sample of completed activity rows:

ActivityA (who)R (who)Evidence held
Define intended use and risk tierQC Laboratory Systems ManagerSenior Quality Systems SpecialistIntended-use statement AI-REG-011, risk tier Advisory
Approve release to productionQA Validation LeadQC Laboratory Systems ManagerRelease record VAL-2026-0201, QA disposition signed
Run day-to-day production monitoringSenior Quality Systems SpecialistSenior Quality Systems SpecialistWeekly override-rate report, drift dashboard review log
Escalate a cross-model or portfolio-level riskAssociate Director, Digital QualitySenior Quality Systems SpecialistAI Governance Board minutes, Q3 2026, risk escalation item 3

In this example the AI risk officer (Associate Director, Digital Quality) never builds or owns an individual model’s day-to-day operation; that sits with the model owner and steward. When the QC data review model’s override rate trended low, the steward flagged it through the monitoring row, and the risk officer took the portfolio-level pattern (a similar trend on a second model) to the AI Governance Board rather than each steward handling it in isolation. That separation, one person governing the model, a different person holding the cross-portfolio view, is what let the pattern get caught at all.

Common inspection findings this matrix prevents

  • No one can say who is accountable for monitoring a production model, so a drift signal sits unactioned.
  • The same person who built the model is also the only person who decided its risk tier, with no independent check.
  • Multiple models show a similar problem in isolation because no role held the cross-portfolio view to notice the pattern.
  • A RACI exists on paper but the org chart and the AI register do not match it, so the documented owners are not the real ones.
  • An inspector asks who owns a specific AI system and gets three different answers from three different people.

How to adapt this matrix

  1. Set your document number, owner, and effective date in the header, and link the parent AI governance policy.
  2. Map every generic role code to a real title or organizational placement; where AI risk officer and AI steward are held by the same person today, say so explicitly rather than leaving the row ambiguous.
  3. Confirm each activity still has exactly one A after you edit it; this is the most common error when adapting any RACI.
  4. Add activities specific to your operation (for example a vendor-supplied model’s shared-responsibility handoffs, covered separately in the AI supplier shared-responsibility matrix, or a generative-AI-specific guardrail review).
  5. Review the matrix whenever the org chart or AI register changes, and confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.