All RACI charts & matrices are free to use, no account, no sign-up. All RACI charts & matrices are free, no sign-up
Family 1: Task-centric

RACI-VS: Adding Control Gates for Regulated Work

RACI plus Verify and Sign-off. The variant for environments where a deliverable cannot pass without an explicit check against criteria and a named formal approver.

Jump aheadTemplate generatorCompareFind your matrix

Summary

RACI-VS extends RACI with two control roles: Verify, which checks the finished output against defined acceptance criteria, and Sign-off, which gives formal recorded acceptance before the deliverable can proceed. It exists for regulated and quality-gated work, where auditors expect a named person who checked and a named person who accepted, separate from the people who produced the work. Choose it for pharmaceutical, aerospace, financial-services, and safety-critical processes; avoid it for ordinary internal delivery, where two mandatory gates per task manufacture bureaucracy. Its core discipline is separation of duties: the doer, the verifier, and the signatory should not be the same person.

The letters

RACI-VS keeps the four base roles and adds two control roles at the end. Some sources render it RACI-VSL and name the roles Verifier and Signatory.

R

Responsible

Does the work.

A

Accountable

Owns the outcome and delegates the work. One per task.

C

Consulted

Advisors consulted before the work proceeds.

I

Informed

Kept up to date.

V

Verify

Checks the finished output against defined acceptance criteria.

S

Sign-off

Gives formal, recorded acceptance before the deliverable can proceed.

The distinction that matters is between the two new roles and the Accountable role. Accountable owns the work throughout. Verify is an output check against criteria performed after the work is done. Sign-off is a formal act of acceptance, often by a different named authority, that releases the deliverable to its next stage. In regulated settings, the Verifier and the Signatory are frequently not accountable for producing the work at all, which is precisely the point: control is separated from delivery.

Origin and history

RACI-VS is a compliance-driven extension of RACI, and like most of the family it has no single inventor. It emerged from the needs of regulated and quality-gated industries where the base matrix was inadequate for one specific reason: RACI has no explicit place for a mandatory control step. In a pharmaceutical batch release, an aerospace design gate, or a financial model validation, the deliverable legally or contractually cannot advance until it has been verified against criteria and formally signed. Folding that into “Accountable” would blur the very separation that auditors and regulators require.

The matrix is documented and supported in enterprise process tooling; Interfacing’s Enterprise Process Center, for example, treats RACI-VS as one of the two most widely used RACI extensions alongside RASCI, and generates control-aware process maps from it. Its persistence is a function of regulation rather than fashion: wherever an external body demands evidence that a named person checked the work and a named person accepted it, some form of RACI-VS tends to appear.

What problem it solves

RACI-VS solves the control-gate problem. It answers two questions that plain RACI leaves silent: has this output been checked against its acceptance criteria, and who formally accepted it? By making Verify and Sign-off first-class roles rather than assumptions buried inside Accountable, it produces an auditable trail. That trail is the deliverable’s passport: without the V and the S recorded, the work cannot move, and there is a named individual attached to each control act.

Crucially, the matrix enforces separation of duties. The person who did the work should not be the only person who verifies it, and ideally not the person who signs off on it. RACI-VS gives that separation a place to live on the chart, which is why it is the natural responsibility matrix for environments where segregation of duties is a formal requirement rather than good manners.

When to choose it, and when not

Choose RACI-VS in regulated or quality-gated work: pharmaceutical and medical-device processes, aerospace and defense, financial services model governance, safety-critical engineering, and any audited process where a deliverable needs both a verification against criteria and a formal acceptance. It is a strong fit anywhere a regulator, auditor, or contract demands evidence of who checked and who accepted.

Do not use it for ordinary internal delivery. In a fast-moving product team, adding two mandatory control roles to every task manufactures bureaucracy and slows work with no compliance benefit to show for it. If your gates are about quality assurance as a standing function rather than a per-deliverable control, RACIQ is a better fit. If reviewers need the power to reject work outright rather than simply verify and sign, PACSI with its Control role gives more teeth.

Common pitfalls

  • Verifier and Signatory collapsed into Accountable. If the same person owns, verifies, and signs, the separation-of-duties benefit is lost and an auditor will say so.
  • Confusing Verify with quality assurance. Verify is an acceptance check against defined criteria for a specific deliverable, not a standing QA function. If you need the latter, you want RACIQ.
  • Gate proliferation. Adding V and S to every row when only a few deliverables are genuinely controlled turns the matrix into a rubber-stamp exercise and devalues the real gates.
  • Unnamed signatories. “Sign-off: the compliance team” defeats the purpose. The value is a single named authority who can be held to the acceptance.

Worked example

Validating an actuarial pricing model in an insurance setting, where independent review and formal sign-off are expected controls.

TaskPricing ActuaryPeer ReviewerHead of PricingModel RiskChief Actuary
Build the model
R
C
A
I
I
Document assumptions
R
C
A
C
I
Independent review
I
V
A
V
I
Formal validation sign-off
I
I
C
R
S

Reading the “Independent review” row: the Peer Reviewer and Model Risk both Verify the output against criteria (V), the Head of Pricing remains Accountable (A), and the Pricing Actuary is Informed but does not verify their own work. The final row records the Chief Actuary as Signatory (S), the single named authority whose formal acceptance releases the model into use. This is the kind of control geometry that a financial-services regulator expects to see.

Where it sits in the family

RACI-VS is the compliance-oriented branch of the task family. It shares the “add a control role” instinct with PACSI (which reframes review as a veto-bearing Control) and RACIQ (which adds a standing Quality role), but it is the most explicitly gate-and-signature oriented of the three. Where RASCI enriches the doing side of RACI, RACI-VS enriches the accepting side. If your organization lives under external scrutiny, this is usually the first variant you will need.

Sources

Web sources

Academic sources

No peer-reviewed literature treats RACI-VS as its own subject; it is documented through practitioner and tooling references. The academic grounding sits one level up, in the control and governance ideas it applies.

  • Fama, E.F. and Jensen, M.C. (1983) ‘Separation of ownership and control’, Journal of Law and Economics, 26(2), pp. 301-325. The theoretical case for separating the ratifying role from the executing role.
  • Institute of Internal Auditors (2020) The IIA’s Three Lines Model. Lake Mary, FL: IIA. The governance model whose first-line/second-line separation RACI-VS expresses at task level.
  • Project Management Institute (2021) A Guide to the Project Management Body of Knowledge (PMBOK Guide). 7th edn. Newtown Square, PA: PMI. The formal codification of the responsibility assignment matrix that RACI-VS extends.

Do more with RACI-VS