PMP Practice: Use Methods to Support Compliance
Question 3 of 6 in Plan and Manage Project Compliance
Pick an answer below — you'll get the explanation instantly, no signup.
Show answer & explanation
Correct answer: Reject the change until regulatory pre-approval is complete, then assess whether the new algorithm can be incorporated through formal change control
Explanation
In regulated environments, compliance requirements create non-negotiable constraints that override typical agile flexibility. Because the encryption method was part of the mandatory regulatory pre-approval submission currently under review, changing it unilaterally would invalidate the compliance documentation and potentially violate regulatory requirements across three jurisdictions. In a hybrid approach, the predictive compliance framework establishes boundaries within which agile delivery operates. The project manager must protect the compliance baseline until regulatory approval is secured, then evaluate the technical improvement through proper change control that includes resubmission to regulators if needed. The sprint-level team authority to pivot does not extend to components that are under active regulatory review. This demonstrates the core hybrid principle: agile delivery methods adapt within the governance structure established by predictive compliance planning.
**Why not A:** This misapplies agile responsiveness to change. While agile values encourage adaptation, compliance constraints in regulated industries create firm boundaries. Changing a component currently under regulatory review without approval could result in non-compliance, project shutdown, or legal liability. The hybrid approach means agile flexibility applies within the compliance framework, not instead of it. Responding to change still requires following mandatory regulatory processes.
**Why not B:** Deferring to a retrospective delays an urgent compliance decision and inappropriately democratizes a matter requiring regulatory expertise. Retrospectives are for process improvement, not regulatory compliance decisions. The issue is not whether the team agrees with the change but whether it violates the compliance framework. Additionally, waiting until after the sprint could mean work proceeds on an unapproved architectural change, creating rework and compliance risk.
**Why not D:** Sandbox testing might seem like a reasonable compromise, but it creates divergence between what regulators are reviewing and what the team is developing. This introduces governance risk and could be seen as circumventing the approval process. More importantly, it does not address the fundamental issue: the compliance documentation under review would become inaccurate, which itself may constitute a regulatory violation depending on jurisdiction requirements for disclosure accuracy during the review period.
Key Concept
This question covers Use Methods to Support Compliance under Plan and Manage Project Compliance (Business Environment).
This is 1 of 100 free PMP questions
Unlock 6,300+ PMP practice questions with detailed explanations, progress tracking, and exam readiness prediction.
Unlock All Questions