Policy Development & Approval Responsibility Matrix
Clarifies who drafts, who is consulted, who approves and who communicates each document type.
Available soon
- Format
- Excel
- Size
- 68 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Responsibility Matrix
- By Document Type
- Role Holders
- Role Combinations
- Combined Roles Check
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Read the Responsibility Matrix. Each row is one activity in a document's life, with the rule of the Policy Framework Standard it comes from. R = does the work; A = accountable, signs it off, exactly one per activity; C = consulted before it is done; I = informed after. A/R means the accountable role also does the work. |
| 2 | Adjust the letters to how your organisation works, using the drop-down in each yellow cell. Keep exactly one A (or A/R) and at least one R per row: the Check column says OK only when both hold. |
| 3 | Keep the four approval rows (PD-06 to PD-09) as they are unless your approved Policy Framework Standard changes who approves each tier. By Document Type reads the approving role from those rows and flags any that no longer matches. |
| 4 | On Role Holders, name the post that holds each role and its deputy. A deputy may act for a role only at the same or a higher level of authority; approval authority is never delegated downwards. |
| 5 | If one person holds several roles, list them on Combined Roles Check and mark each role they hold. The Result column shows whether any combination is never acceptable, or needs the safeguard on Role Combinations. |
| 6 | Resolve every Never acceptable combination before approving this matrix, by moving a role to someone else or to an external reviewer. Record the safeguard you use for each Acceptable with safeguard combination. |
| 7 | Review the matrix with the Policy Framework Standard, at least every 12 months, and whenever a role holder changes. |
| 8 | The EXAMPLE rows on Combined Roles Check are the example organisation used across the pack (a software services company with 240 staff in two offices, an NIS2 important entity); each person's documents come from its example register. Delete them before approval. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Tailoring — small organisation: one person may hold several roles. Typically the managing director is executive management, and the IT manager is document owner, author, information security and publisher. That works with the safeguards on Role Combinations; the rule that never bends is that nobody approves a document they own or wrote (PF-03). The one thing to buy in is an independent reviewer: an external adviser or your auditor, once a year.
Tailoring — regulated entity (NIS2, DORA): the management body approves the cybersecurity risk-management measures (NIS2 Article 20(1)), so the Policy approval row (PD-06) is the management body itself, with a minute, not a delegate. DORA financial entities must set out the roles for developing, implementing and maintaining ICT security policies (RTS 2024/1774 Article 2(2)(i)): this matrix, approved, is that record. Keep the independent reviewer separate from information security and executive management.
Tailoring — IT run by a service provider: a provider may draft standards and procedures for the services it runs (Author) and be consulted on policies. Ownership and every A stay with people in your organisation; the provider never approves a document that governs its own work. Put its drafting and review duties in the service agreement.
Delegation: a deputy may act for a role while its holder is absent, at the same or a higher level of authority, and is bound by the same combination rules as the person they stand in for.
Responsibility Matrix
R = responsible (does it) · A = accountable (exactly one per activity) · C = consulted · I = informed · A/R = accountable and does it. Yellow cells are yours to adjust.
| Ref | Stage | Activity | Rule | Document owner | Author | Information security | Executive management | Consulted functions | Publisher | Independent reviewer | Output, evidence or note | A count | R count | Check |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PD-01 | Plan | Identify the need for a new document, or for a change to one, from the coverage gap assessment or a review trigger | PF-06 | R | A | C | C | Entry in the Policy Register & Review Schedule with status Draft; for gaps, the Policy Coverage Gap Assessment | 1 | 1 | OK | |||
| PD-02 | Plan | Set the document's tier and name its one owner | PF-01, PF-02 | C | A/R | C | Tier and owner recorded in the register; the hierarchy in the Security Policy Hierarchy & Document Map | 1 | 1 | OK | ||||
| PD-03 | Draft | Draft the document: for a policy, the sections in order, testable "must" statements, within the page limit | PF-04, PF-05 | A | R | C | Draft on the Security Policy Document Template (policies) or the house format for its tier | 1 | 1 | OK | ||||
| PD-04 | Draft | Consult the people who must follow the document | PF-07 | A | R | C | C | I | Status In consultation; comments and responses recorded | 1 | 1 | OK | ||
| PD-05 | Draft | Legal, HR and data protection review, where the document affects them | PF-07 | A | R | I | R | Each function's comments resolved, or its objection recorded for the approver | 1 | 2 | OK | |||
| PD-06 | Approve | Approve a Policy: executive management (the management body, or its delegate for the top policy) | PF-03 | R | I | C | A | The owner presents the final text; executive management decides and the decision is minuted. If the approver owns or wrote it: the rest of executive management, without the member who owns or wrote it | 1 | 1 | OK | |||
| PD-07 | Approve | Approve a Standard: Head of Information Security (the document owner is consulted) | PF-03 | C | I | A/R | I | The Head of Information Security approves; the document owner is consulted. If the approver owns or wrote it: executive management | 1 | 1 | OK | |||
| PD-08 | Approve | Approve a Procedure: Head of Information Security (the process owner is consulted) | PF-03 | R | I | A | Information security approves procedures, with the process owner consulted (TIERS). Where information security owns or wrote the procedure, executive management approves instead (CONFLICT_APPROVER, PF-03). If the approver owns or wrote it: executive management | 1 | 1 | OK | ||||
| PD-09 | Approve | Approve a Guideline: information security | PF-03 | C | I | A/R | Information security approves. If the approver owns or wrote it: executive management | 1 | 1 | OK | ||||
| PD-10 | Publish | Publish the approved version in the one place everyone can reach, and update the register | PF-03, PF-08, PF-11 | A | R | R | Status Approved; approval date and next review date in the register. Not in force until published | 1 | 2 | OK | ||||
| PD-11 | Publish | Withdraw and archive the superseded version | PF-08 | I | A | R | Only the current version reachable; the old one archived with its approval record | 1 | 1 | OK | ||||
| PD-12 | Acknowledge | Run the acknowledgement campaign: new starters within 10 working days of starting, everyone within 30 calendar days of the publication of a material change, and once a year, for every policy that applies to the person | PF-09 | C | A | I | R | Acknowledgements recorded in the Policy Attestation & Acknowledgement Tracker. Only Policy-tier documents are acknowledged individually; a new major version is acknowledged again, a minor one is not | 1 | 1 | OK | |||
| PD-13 | Acknowledge | Chase overdue acknowledgements through each person's line manager | PF-09 | A | I | R | Overdue list by manager (PM-04) | 1 | 1 | OK | ||||
| PD-14 | Review | Review each document by its tier's maximum interval (Policy 12 months, Standard 12 months, Procedure 24 months, Guideline 24 months) | PF-06 | A/R | R | C | C | Review recorded even when nothing changes; a changed document is approved again at its tier (PD-06 to PD-09) | 1 | 2 | OK | |||
| PD-15 | Review | Review a document early when a trigger occurs | PF-06 | A/R | R | I | Triggers: a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses | 1 | 2 | OK | ||||
| PD-16 | Retire | Retire a document that is no longer needed, and remove it from use | PF-08, PF-11 | R | A | I | R | Status Retired in the register; archived with its approval history. Anything that still depends on it is pointed elsewhere first | 1 | 2 | OK | |||
| PD-17 | Govern | Maintain the register: every document with owner, tier, status, version, approval date and next review date | PF-11 | C | A/R | I | The Policy Register & Review Schedule: the only authoritative list | 1 | 1 | OK | ||||
| PD-18 | Govern | Report document currency and acknowledgement coverage to executive management every quarter | PF-12 | I | A/R | I | PM-01 documents past review date; PM-02 documents in force without approval; PM-03 acknowledgement coverage; PM-04 overdue acknowledgements, from the Policy Health & Attestation Reporting Workbook | 1 | 1 | OK | ||||
| PD-19 | Govern | Check independently that documents are approved, published, reviewed and acknowledged as the Standard requires | PF-03, PF-06, PF-09, PF-11 | I | C | I | A/R | Independent review findings, at least once a year [[or as your audit plan sets]] | 1 | 1 | OK |
By Document Type
For each tier of the Policy Framework Standard: who drafts, who is consulted, who approves and who communicates. The approving role is read from the matrix.
| Tier | What it is for | Who drafts | Who is consulted (PF-07) | Who approves (PF-03) | Role holding the A | Approving role in the matrix | Matches | If the approver owns or wrote it (PF-03) | Who communicates | Acknowledged by (PF-09) | Review at least every (months) |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Policy | What the organisation commits to and why. Short, stable, written for everyone. | Author for the document owner, with information security | Everyone it applies to (through representatives); [[e.g. Legal, HR, Data Protection Officer]]; information security | Executive management (the management body, or its delegate for the top policy) | Executive management | Executive management | OK | The rest of executive management, without the member who owns or wrote it | Publisher [[e.g. Internal Communications, or HR for acknowledgements]], to everyone in scope | Everyone in scope: new starters within 10 working days, after a material change within 30 calendar days of its publication, and once a year | 12 |
| Standard | The specific, measurable requirements that make a policy real: settings, deadlines, minimums. | Author, usually information security or the function that runs the service | The teams who must meet it; [[e.g. Legal, HR, Data Protection Officer]] where affected | Head of Information Security (the document owner is consulted) | Information security | Information security | OK | Executive management | Publisher, to the teams who must meet it | Not acknowledged; communicated to the people who use it | 12 |
| Procedure | How a task is done, step by step, by named roles. | The process owner's team | The people who carry it out; information security | Head of Information Security (the process owner is consulted) | Information security | Information security | OK | Executive management | The process owner, to the people who carry it out | Not acknowledged; communicated to the people who use it | 24 |
| Guideline | Recommended practice. Helpful, not mandatory; nobody is non-compliant for not following it. | Information security, or any subject expert | The people it is written for | Information security | Information security | Information security | OK | Executive management | Information security, to the people it is written for | Not acknowledged; communicated to the people who use it | 24 |
Role Holders
Name who holds each role and who deputises. The counts show how much of the matrix each role carries.
| Role | What the role does here | Held by (post) | Deputy (post) | What the deputy may do | Accountable for (A) | Responsible for (R) |
|---|---|---|---|---|---|---|
| Document owner | Accountable for a document's content and its review (PF-02); presents it for approval, but never approves a document they own. | [[e.g. Head of IT for the access control policy]] | [[Deputy post]] | Another manager of the same or higher level in the same area. | 6 | 6 |
| Author | Drafts the document for its owner, runs the consultation and makes the changes a review calls for. | [[whoever the owner asks to draft]] | [[Deputy post]] | Any competent person the owner names. | 0 | 4 |
| Information security | Keeps the framework, the register and the reporting; approves standards, guidelines and procedures their owners cannot approve; checks tier, format and consultation before approval. | [[e.g. Head of Information Security]] | [[Deputy post]] | A named deputy may keep the register and run the reporting. Approvals need someone of equal authority. | 11 | 7 |
| Executive management | Approves policies, and standards the Head of Information Security owns or wrote; receives the quarterly report, and decides on documents far past review. | [[e.g. Executive Committee, or the management body]] | [[Deputy post]] | Acts as a body; a quorum under its terms of reference, excluding the author of the document being decided. | 1 | 0 |
| Consulted functions | Legal, HR and data protection review drafts that affect them (PF-07). | [[e.g. Legal, HR, Data Protection Officer]] | [[Deputy post]] | Another member of the same function. | 0 | 1 |
| Publisher | Publishes approved versions, withdraws old ones and runs the acknowledgement campaigns. | [[e.g. Internal Communications, or HR for acknowledgements]] | [[Deputy post]] | Any member of the publishing team. | 0 | 5 |
| Independent reviewer | Checks independently that documents are approved, published, reviewed and acknowledged as the Standard requires. | [[e.g. internal audit]] | [[Deputy post]] | Another reviewer independent of the process, internal or external. | 1 | 1 |
Role Combinations
The small-organisation variant: one person may hold several roles, but nobody approves a document they own or wrote (PF-03). The first rows apply in every organisation.
| Combination | Verdict | Why | Safeguard, or what to do instead |
|---|---|---|---|
| Approving a document you own or wrote | Never acceptable | The approval is the only independent look at the document (PF-03). | The conflict approver for the tier, on By Document Type, decides instead. |
| Approving the review outcome of a document you own or wrote | Never acceptable | A review that changes a document is a new approval (PF-06). | As above: the conflict approver for the tier. |
| Independently checking documents you own or wrote, or a process you run | Never acceptable | The check (PD-19) exists because nobody else looks. | Another reviewer, internal or external. |
| Recording your own acknowledgement or marking your own team's overdue ones complete | Never acceptable | Acknowledgement records are evidence (PF-09); they must come from the person. | The person acknowledges in the system of record; the publisher reconciles. |
| Document owner + Author | Acceptable with safeguard | Common: owners often draft their own documents. | They never approve a document they own or wrote; for a procedure: executive management. |
| Document owner + Information security | Acceptable with safeguard | The Head of Information Security often owns standards, which that role approves. | A standard or guideline the Head of Information Security owns is approved by the conflict approver: for a standard, executive management; for a guideline, executive management. |
| Document owner + Executive management | Acceptable with safeguard | Executives own policies that executive management approves. | The owner presents the policy and takes no part in the decision. |
| Document owner + Consulted functions | Acceptable | The HR or legal lead may own a document and be consulted on others. | — |
| Document owner + Publisher | Acceptable | No duty conflicts. | — |
| Document owner + Independent reviewer | Never acceptable | The reviewer would check documents they own. | Use another reviewer, or an external one. |
| Author + Information security | Acceptable with safeguard | Information security drafts many standards and guidelines that it would approve. | The conflict approver decides: for a standard, executive management; for a guideline, executive management. |
| Author + Executive management | Acceptable with safeguard | An executive may draft a policy themselves. | The rest of executive management, without the member who owns or wrote it. |
| Author + Consulted functions | Acceptable | Legal or HR may draft the parts that concern them. | Another member of the function reviews those parts (PD-05). |
| Author + Publisher | Acceptable | No duty conflicts. | — |
| Author + Independent reviewer | Never acceptable | The reviewer would check documents they wrote. | Use another reviewer, or an external one. |
| Information security + Executive management | Acceptable | A head of information security may sit on the executive committee. | Where they own or wrote a policy, they take no part in approving it. |
| Information security + Consulted functions | Acceptable | No duty conflicts. | — |
| Information security + Publisher | Acceptable | In small organisations the IT or security lead publishes documents and runs acknowledgements. | — |
| Information security + Independent reviewer | Never acceptable | The reviewer would check the register and reports they keep. | Use internal audit, or an external reviewer once a year. |
| Executive management + Consulted functions | Acceptable | No duty conflicts. | — |
| Executive management + Publisher | Acceptable | Possible in very small organisations. | — |
| Executive management + Independent reviewer | Never acceptable | The reviewer would check approvals they gave. | Use internal audit reporting to the board, or an external reviewer. |
| Consulted functions + Publisher | Acceptable | HR is often consulted and also runs acknowledgements. | — |
| Consulted functions + Independent reviewer | Acceptable | Internal audit is often consulted on drafts; being consulted does not stop an independent check. | — |
| Publisher + Independent reviewer | Never acceptable | The reviewer would check acknowledgement records they keep. | Use another reviewer, or an external one. |
Combined Roles Check
One row per person who holds more than one role. Mark each role they hold; the Result shows whether the combination is allowed.
| Example | Person or post | Document owner | Author | Information security | Executive management | Consulted functions | Publisher | Independent reviewer | Roles held | Never-acceptable pairs | Pairs needing a safeguard | Result | First pair to resolve |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | Chief Operating Officer (owns ISP-001); on the Executive Committee | Yes | Yes | 2 | 0 | 1 | Allowed with safeguard | Document owner + Executive management (safeguard) | |||||
| EXAMPLE | Head of IT (owns AUP-001, ACP-001, RMT-GDL); drafts them | Yes | Yes | 2 | 0 | 1 | Allowed with safeguard | Document owner + Author (safeguard) | |||||
| EXAMPLE | Head of Information Security (owns INC-001, VMS-001, EXC-STD); drafts them | Yes | Yes | Yes | 3 | 0 | 3 | Allowed with safeguard | Document owner + Author (safeguard) | ||||
| EXAMPLE | HR Director (owns JML-PRC); consulted; runs acknowledgements | Yes | Yes | Yes | 3 | 0 | 0 | OK | |||||
| EXAMPLE | IT Operations Manager (owns BKP-001); proposed as independent reviewer | Yes | Yes | 2 | 1 | 0 | Conflict — move a role | Document owner + Independent reviewer (never) |
Lists
| RACI | YesNo | Verdict |
|---|---|---|
| R | Yes | Never acceptable |
| A | No | Acceptable with safeguard |
| A/R | Acceptable |
C
I
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| R — Responsible | Does the work. There may be more than one. |
| A — Accountable | Owns the outcome and signs it off. Exactly one per activity, so there is never doubt about who decides. |
| C — Consulted | Asked for input before the activity is done. |
| I — Informed | Told of the outcome after the activity is done. |
| A/R | Accountable and also does the work. Counts as both an A and an R in the Check column. |
| Document owner | Accountable for a document's content and its review (PF-02); presents it for approval, but never approves a document they own. [[e.g. Head of IT for the access control policy]] |
| Author | Drafts the document for its owner, runs the consultation and makes the changes a review calls for. [[whoever the owner asks to draft]] |
| Information security | Keeps the framework, the register and the reporting; approves standards, guidelines and procedures their owners cannot approve; checks tier, format and consultation before approval. [[e.g. Head of Information Security]] |
| Executive management | Approves policies, and standards the Head of Information Security owns or wrote; receives the quarterly report, and decides on documents far past review. [[e.g. Executive Committee, or the management body]] |
| Consulted functions | Legal, HR and data protection review drafts that affect them (PF-07). [[e.g. Legal, HR, Data Protection Officer]] |
| Publisher | Publishes approved versions, withdraws old ones and runs the acknowledgement campaigns. [[e.g. Internal Communications, or HR for acknowledgements]] |
| Independent reviewer | Checks independently that documents are approved, published, reviewed and acknowledged as the Standard requires. [[e.g. internal audit]] |
| Approver | Not a separate column: the approver is set per tier — Policy: executive management (the management body, or its delegate for the top policy); Standard: Head of Information Security (the document owner is consulted); Procedure: Head of Information Security (the process owner is consulted); Guideline: information security — and the approval rows put the A on the role that holds it. |
| Tier | One of the four levels of security document: Policy, Standard, Procedure, Guideline (PF-01). |
| Conflict approver | Who approves a document when the tier's approver owns or wrote it (PF-03). Shown on By Document Type. |
| Trigger | An event that forces a review before the scheduled date (PF-06). |
| Deputy | The person who acts for a role holder while they are absent, with no more authority than the role holds. |
| Never acceptable | A combination that defeats the purpose of a control. Move one of the roles to someone else. |
| Acceptable with safeguard | A combination that is workable if the safeguard shown is applied and recorded. |
| EXAMPLE row | A worked example on Combined Roles Check, from the example organisation's register. Delete before approval. |
| PF-01 … PF-12 | Rule numbers in the Policy Framework Standard. PM-01 … PM-04 are its headline measures. |
| Exception | A deviation from any document, handled under the Security Exception & Waiver Standard (PF-10), never by informal agreement. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 5.3 — Organizational roles, responsibilities and authorities | Responsibility Matrix and Role Holders |
| ISO/IEC 27001:2022 | Annex A 5.2 — Information security roles and responsibilities | Responsibility Matrix: one accountable role per activity |
| ISO/IEC 27001:2022 | Annex A 5.4 — Management responsibilities | Approval rows PD-06 to PD-09; quarterly report PD-18 |
| NIST CSF 2.0 | GV.RR-02 — “Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced” | Responsibility Matrix, By Document Type and Role Holders |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(i) — roles and responsibilities for developing, implementing and maintaining the policies | Whole workbook: roles for developing, implementing and maintaining policies |
| NIS2 — Directive (EU) 2022/2555 | Article 20(1) — management bodies approve the cybersecurity risk-management measures and oversee their implementation | Policy approval row PD-06: executive management or the management body |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774