Roles and Responsibilities (RACI)
RACI is a simple model used to map out who does what across the tasks, deliverables, or decisions within a project or business process. The acronym stands for four types of involvement, Responsible, Accountable, Consulted, and Informed, so that everyone understands their part and roles are agreed upon in advance. In security leadership engagements, it is often used to clarify which decisions the client organization owns versus where a virtual or fractional CISO advises or directs.
RACI is a responsibility assignment matrix that lays out relevant roles along one axis and tasks, deliverables, or decisions along the other, assigning each intersection one of four participation types: Responsible (performs the work), Accountable (owns the outcome and is answerable for it), Consulted (provides input before a decision or action), and Informed (kept aware of progress or results). Practitioners use it to discuss, communicate, and agree on role definitions, reducing ambiguity in project execution and governance workflows. A common expert-level caution is that Accountable typically maps to a single role rather than being shared; in the context of security leadership, mapping accountability accurately matters because legal and organizational accountability for security decisions usually remains with the client and its officers even when a virtual CISO is Responsible or Consulted for advisory tasks. Variants such as RASCI extend the model by adding a Support role, and the specific labeling of the vertical axis as tasks, deliverables, or decisions may vary by context.
Why it matters
In virtual and fractional CISO engagements, the single most common source of friction and risk is ambiguity about who owns what. Because a virtual CISO typically advises, directs, and develops strategy rather than performing hands-on operational work, and because legal and organizational accountability for security decisions usually remains with the client and its officers, a clear RACI matrix helps prevent the dangerous assumption that engaging a vCISO transfers accountability for security outcomes. Mapping roles in advance clarifies which decisions the client owns, where the vCISO is Responsible for advisory deliverables, and where they are only Consulted or Informed.
The RACI convention that Accountable typically maps to a single role, rather than being shared, is especially relevant here. When accountability is left implicit or is diffused across parties, gaps emerge in which everyone assumes someone else owns a decision or task. In security leadership, that gap can affect governance decisions, compliance readiness efforts, and program development. Explicitly assigning Accountable to a named client officer, while the vCISO carries Responsible or Consulted roles for the work that supports those decisions, keeps the accountability boundary honest and avoids implying the vCISO assumes liability that the contract does not grant.
RACI also supports the practical value of an engagement, which often depends on client cooperation, defined scope, and access to stakeholders. By discussing, communicating, and agreeing on roles before work begins, both the provider and the client set expectations that reduce downstream disputes about scope, ownership, and hand-offs. This is particularly important when distinguishing what a vCISO delivers from operational functions such as monitoring, tooling, or incident response execution that may be out of scope unless explicitly contracted.
Who it's relevant to
Inside RACI
Common questions
Answers to the questions practitioners most commonly ask about RACI.