This document proposes a two-step responsibility-based approach for aligning business-level requirements from the COBIT framework with technical RBAC policies. It emphasizes the importance of defining employee responsibilities, obligations, and rights to ensure an adequate mapping between business roles and application roles. The approach aims to enhance traceability in access rights management within organizations, particularly in sectors with stringent governance requirements.