Skip to content

Roles and RACI charts in COBIT 2019

By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · COBIT 2019

Governance fails on ambiguity about who owns what. COBIT's RACI charts make responsibility explicit — for every objective, who is Responsible, Accountable, Consulted, Informed.

Who does what

A practical part of COBIT 2019 is its specification of roles and responsibilities. For the activities within each objective, COBIT provides RACI charts that map roles (from the board and executives down to specific functions) to their involvement. It answers the governance question that ambiguity quietly kills: who is actually responsible.

What RACI means

  • Responsible — the role that does the work.
  • Accountable — the single role answerable for the outcome (there should be exactly one).
  • Consulted — roles whose input is sought before acting.
  • Informed — roles kept up to date on progress or decisions.

Why it is a control

Clear accountability is itself a governance control. When everyone assumes someone else owns a thing, it does not get done — the diffusion-of-responsibility failure. A RACI that names a single accountable role per activity removes that ambiguity, which is why COBIT bakes it into every objective.

Tailor it

COBIT's RACI charts are a starting point — you adapt the generic roles to your actual organisation, which in a small company may mean a few people holding many roles. The discipline that matters is naming a clear accountable owner for each thing, however small the team.

COBIT 2019 governance components ISO 27001 leadership and roles (Clause 5) COBIT 2019 governance and management objectives

Run your compliance program in one workspace.