Skip to main content
Praxikon

Free template · Excel · English and Dutch

RACI matrix template for AI governance (Excel)

A RACI matrix for AI governance records, for each obligation under the AI Act and the GDPR, who carries out the work (R), who is accountable (A), who is consulted beforehand (C) and who is informed afterwards (I). The law places the obligations on the organisation as provider, deployer or controller; the matrix shows who performs them internally.

Last checked against the law
Editor
, jurist, privacy and AI
Version and template ID
2.0 · praxikon:template:raci-ai-governance
Legal basis
Art. 3, 4, 5, 6, 9 to 21, 25 to 27, 43, 47 to 50, 53, 72, 73, 86, 111 and 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744; Art. 5, 6, 12 to 22, 24, 25, 28, 30, 32 to 39 and 44 to 49 of Regulation (EU) 2016/679 (GDPR); Art. 27(1)(k) and (l) of the Dutch Works Councils Act (Wet op de ondernemingsraden)

Who is this template for?

  • Executive managementAdopts the matrix and is accountable for the AI literacy measures (Article 4 AI Act)
  • AI coordinator or owner of the AI registerMaintains the matrix and assesses new use cases for prohibited practices (Article 5) and for a shift into the provider role (Article 25(1))
  • Process ownerAs deployer of a high-risk system, organises human oversight, monitoring and suspension of use (Article 26(2) and (5), for Annex III from 2 December 2027)
  • Data protection officer (DPO)Advises and monitors, and is therefore on C or I; other tasks must not result in a conflict of interests (Articles 38(6) and 39 GDPR)
  • Quality and risk at a providerIncludes the allocation in the quality management system as the accountability framework for management and other staff (Article 17(1)(m))
  • HR and employee representativesPrior information to workers' representatives when a high-risk system is used at the workplace (Article 26(7)); national law may add rights, such as the consent right of a Dutch works council under Article 27(1)(k) and (l) of the Works Councils Act (WOR)

What is inside

  • Cover sheet: seven-step method, fields for owner and adoption, citation, and three signals for when you need legal advice
  • Roles sheet: ten roles, from management to procurement, with who this usually is, the typical task, a name and a deputy
  • Deployer sheet: 19 obligations (G-01 to G-19), from Articles 4 and 5 to Articles 26, 27, 50 and 86, each with the date from which it applies
  • Provider sheet: 25 obligations (P-01 to P-25), from risk management and technical documentation to conformity assessment, serious incident reporting and general-purpose AI models (Article 53)
  • GDPR and security sheet: 14 obligations (V-01 to V-14) as controller, including DPIA, data processing agreement, international transfers and personal data breaches
  • For every obligation the columns Applies to you?, an example of evidence and Where recorded, plus ten empty rows for your own obligations
  • Check sheet: counts rows per sheet with no A, more than one A, no R or a DPO in an executive role, and shows accountability per role

How to use the template

  1. On the Roles sheet, enter a name and a deputy for each role. If you do not have a role, designate who covers the task.
  2. Choose your sheets: Deployer for every organisation that uses AI, Provider only if you place an AI system on the market or put it into service under your own name, GDPR and security as soon as personal data is processed.
  3. Set Applies to you? to Yes, No or Not sure for each row and adjust the suggested letters to your organisation: exactly one A and at least one R per row.
  4. Record for each row where your evidence is kept and its date. The example column is not evidence.
  5. Clear the open items on the Check sheet, have management adopt the matrix and review it after every new AI use case and at least once a year.

Common mistakes

  • Two accountable roles for one obligation, for example IT and the process owner. Then nobody feels responsible; the check reports More than one A.
  • Letting the DPO carry out or decide, such as writing the DPIA or approving new use cases. The DPO advises and monitors (Article 39 GDPR).
  • Completing only the Deployer sheet while you have your own AI application built or offer a system under your own name. You may then be the provider (Article 25(1)).
  • Treating the example column as evidence. Only a reference to a real, dated document shows what you have done.
  • Adopting the matrix once and never again. After a reorganisation or a new use case, names and roles no longer match.

When do you need legal advice?

  • You are provider and deployer at the same time. You develop an AI system for your own use, or you put your name on a supplier's high-risk system, substantially modify it or change its intended purpose so that it becomes high-risk (Article 25(1)). Both sheets then apply, and the provider obligations of Article 16 call for owners other than those responsible for its use.
  • The DPO is given an executive role. Your organisation wants the DPO to carry out the DPIA or to decide on AI applications. As controller, you must ensure that other tasks of the DPO do not result in a conflict of interests (Article 38(6) GDPR).
  • You need to report or stop quickly. As a deployer of a high-risk system, you suspend use when there is a risk and, on a serious incident, inform the provider first (Article 26(5); Annex III from 2 December 2027, Annex I from 2 August 2028). As controller, you notify a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours, unless it is unlikely to result in a risk (Article 33 GDPR). Agree in advance who decides and who reports.

Frequently asked questions

Does the AI Act require a RACI matrix?

No. The AI Act places obligations on the organisation as provider or deployer, not on a particular function. A provider of a high-risk AI system must, however, include in its quality management system an accountability framework setting out the responsibilities of management and other staff (Article 17(1)(m)). A RACI matrix is a practical form for that.

Do we have to appoint an AI officer?

No. The AI Act does not require an AI officer or any other function. Who coordinates is your own choice. The obligations remain with the organisation as provider, deployer or controller.

Can the data protection officer be accountable for AI?

The DPO informs, advises and monitors (Article 39 GDPR). Other tasks must not result in a conflict of interests (Article 38(6) GDPR). According to the DPO guidelines endorsed by the EDPB, that rules out a role that decides on the purposes and means of processing. That is why the DPO is on C or I in this matrix.

Which obligations already apply?

As of 6 October 2026, the prohibited practices (Article 5) and the AI literacy measures (Article 4) have applied since 2 February 2025, and the transparency obligations of Article 50 since 2 August 2026. The new prohibitions on non-consensual intimate imagery and child sexual abuse material apply from 2 December 2026. The GDPR has applied since 25 May 2018.

When do the obligations for high-risk AI systems apply?

For Annex III systems from 2 December 2027, for Annex I systems from 2 August 2028 (Regulation (EU) 2026/1744). Systems already placed on the market or put into service before then are only covered after a significant change in their design; systems intended to be used by public authorities must comply by 2 August 2030 (Article 111(2)).

Which authority supervises the AI Act in my country?

Each Member State designates its own market surveillance authorities. As of 6 October 2026, the Netherlands, for example, has not yet designated one for the AI Act. Record in your incident and stop procedure who follows the designation in your Member State. For the GDPR, your national data protection authority remains the supervisory authority.

Use and credit

You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.

How to cite this template: Source: Praxikon, RACI matrix template for AI governance (Excel), version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/roles-matrix

This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.

Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597