Traceability Matrix
A traceability matrix is a document or tool that maps requirements to related items such as test cases, deliverables, and issues, so teams can see how each requirement is addressed. It helps confirm that nothing has been overlooked as a project or system evolves. It is commonly used in project management and software development.
A requirements traceability matrix (RTM) is a structured artifact that establishes and maintains bidirectional relationships between requirements and other project artifacts—typically test cases, final deliverables, issues, and source items—to support coverage analysis and change control. As described in the evidence, it is used to map user or functional requirements to test cases and deliverables, enabling practitioners to control the evolution of functionality and verify that each requirement is traced to corresponding validation activities. Note: the evidence describes the RTM in general project management and software development contexts; it does not establish any specific application, mandate, or definition within AI governance or model risk management frameworks, which are out of scope for this entry.
Why it matters
A traceability matrix matters because it provides a structured way to demonstrate that every requirement in a project or system has been accounted for—typically by linking each requirement to the test cases, deliverables, and other artifacts that address it. Without such a mapping, teams can lose track of whether functionality has been implemented, tested, or validated, particularly as requirements change over time. The evidence describes the RTM as a tool for controlling the evolution of functionality, which speaks to its value in managing change: when a requirement shifts, the matrix helps identify which downstream items are affected.
In coverage terms, the traceability matrix supports the practical question of "have we missed anything?" By making the relationships between requirements and validation activities visible, it enables gap analysis and helps teams confirm that each requirement traces to corresponding work. This is a discipline of documentation and control rather than a guarantee of correctness; the matrix records that a link exists, not that the underlying implementation or test is itself adequate.
It is worth noting the scope of this entry. The evidence describes the traceability matrix within general project management and software development. It does not establish any specific role, mandate, or defined meaning for the RTM within AI governance or model risk management frameworks. Readers in those domains should treat any application to AI-specific requirements as a matter of local practice rather than something supported by the sources here.
Who it's relevant to
Inside RTM
Common questions
Answers to the questions practitioners most commonly ask about RTM.