A. RACI Matrix

R = Responsible A = Accountable C = Consulted I = Informed
Activity Board CAISO CISO DPO CTO/CIO Model Owner
AI security policy and standard A R C C C I
AI systems register I A C C C R
Approval of high-risk or sensitive AI solutions I A C C C R
Pre-deployment security gate I A R C C R
DPIA / privacy coordination I C C A I R
AI incident escalation I A R C C R
AI literacy and training programme I A C C C R
Management AI risk reporting I A C C I I

B. Relationship with Other Functions

RelationshipComment
CAISO and CISO The CISO manages general cybersecurity; the CAISO manages AI-specific risk criteria, the AI register, and AI deployment control gates.
CAISO and DPO The DPO is responsible for the data protection system; the CAISO ensures that AI architecture, data flows, and solutions are reviewed from the AI security perspective together with privacy considerations.
CAISO and CTO/CIO The CTO/CIO is responsible for technical implementation and infrastructure; the CAISO sets security requirements and acceptable-risk boundaries.
CAISO and model/product owner The product owner is responsible for business purpose and functionality; the CAISO is responsible for AI security acceptability, risk escalation, and sufficiency of controls.

C. KPI / KRI Indicators

IndicatorDescriptionTarget
Inventory coverage Share of AI systems included in the register ≥ 95%
Pre-deployment control Share of significant AI deployments passing security gates 100%
Assessments Share of AI solutions with risk assessment / DPIA / AI ISA where applicable 100%
Incidents Time from AI incident identification to escalation < 4 hours
Training Role coverage for AI literacy and AI security training ≥ 90%
Exceptions Share of expired exceptions 0%