Skip to content
PMPHard

PMP Practice: Classify compliance categories

Question 2 of 6 in Plan and Manage Project Compliance

Pick an answer below — you'll get the explanation instantly, no signup.

Sora Kobayashi is developing a new clinical trial management system. During user acceptance testing, the compliance officer, Dr. Matteo Bernardini-Conti, halts the project immediately after discovering that patient consent data is being stored on servers located in a country that does not meet the data sovereignty requirements mandated by the European Medicines Agency (EMA). The project is now three weeks behind schedule, and the remediation will require migrating all test data to compliant infrastructure at significant cost. The infrastructure vendor was selected eight months ago based primarily on cost savings and technical capabilities. The project manager, Sienna Volkov, realizes that regulatory data residency requirements were documented in the initial compliance assessment but were not explicitly included in the vendor evaluation criteria. What should Sienna have done earlier to prevent this compliance failure?
Show answer & explanation

Correct answer: Established a compliance gate review process with the compliance officer before finalizing vendor selection and infrastructure decisions

Explanation

The root cause of this compliance failure was that critical regulatory requirements identified in the compliance assessment were not actively incorporated into decision-making processes at key milestones. Establishing compliance gate reviews before major procurement and architectural decisions would have caught the data sovereignty issue before vendor selection, when alternatives could have been evaluated without costly rework. This prevention measure ensures compliance considerations are not just documented but actively integrated into decision points. The scenario specifically states that requirements 'were documented' but 'were not explicitly included in the vendor evaluation criteria'—a compliance gate review would have bridged this gap by requiring the compliance officer to verify that all documented requirements were properly addressed before the decision was locked in. Advanced project managers recognize that compliance management requires structured verification points, not just documentation and periodic audits.

**Why not A:** Scheduling regular compliance audits throughout the project lifecycle is a monitoring measure, not a preventive control at key decision points. Audits catch issues after decisions are already made and implemented, as evidenced by this scenario where the compliance failure was discovered during a routine audit eight months after the vendor was selected. Prevention requires structured verification before commitments are locked in.

**Why not B:** A lessons learned session with the infrastructure vendor would occur after the fact and would not have prevented the compliance failure. Understanding a vendor's compliance capabilities after they are already selected and deployed does not undo the data residency violation; it only informs future projects. The root cause was a failure to integrate compliance requirements into the selection criteria, not a lack of vendor dialogue.

**Why not D:** Escalating vendor selection to the project sponsor for final approval changes who makes the decision but not the quality of information informing that decision. If compliance requirements were still excluded from the evaluation criteria, sponsor approval would still result in a non-compliant vendor selection. The problem was structural—compliance criteria were absent from the decision framework—and escalation alone does not fix that.

Key Concept

This question covers Classify compliance categories under Plan and Manage Project Compliance (Business Environment).

Share:

This is 1 of 100 free PMP questions

Unlock 6,300+ PMP practice questions with detailed explanations, progress tracking, and exam readiness prediction.

Unlock All Questions