RACI — IT change enablement, normal, emergency and failed changes
Responsibility assignment matrix for ITIL change enablement on a SOX-scoped production platform, covering RFC raising, risk classification, CAB and ECAB authorisation, implementation, back-out, post-implementation review and evidence retention for ITGC testing.
Make it your own.
title "RACI — change enablement, SOX-scoped production platform"
roles: Requester, Change Mgr, CAB / ECAB, Service Owner, Tech Approver, Release Eng, InfoSec, IT Audit
# One A per row. Where two roles both do the work they are both R,
# but only one role is ever answerable for the outcome.
Raise RFC with plan and back-out | A/R, C, -, I, C, I, -, -
Classify change model and risk | C, A/R, -, C, C, -, C, -
Peer technical review of the build | I, I, -, -, A/R, R, C, -
Security and data-protection assessment | I, C, -, C, C, -, A/R, -
CAB authorisation — normal change | I, R, A, C, C, I, C, I
ECAB authorisation — emergency change | R, R, A, C, R, I, C, I
Schedule into a release window | I, A, C, C, I, R, -, -
Implement and post-implementation test | I, I, -, I, C, A/R, -, -
Declare failure and invoke back-out | R, A, I, C, C, R, I, I
Post-implementation review of a failure | C, A, C, R, C, R, C, I
Retain evidence for ITGC sample testing | I, A, -, I, I, R, C, C
Close the change record | I, A/R, -, I, -, C, -, I