Skip to content
PMPEasy

PMP Practice: Confirm project compliance requirements

Question 1 of 6 in Plan and Manage Project Compliance

Pick an answer below — you'll get the explanation instantly, no signup.

Tane Whenua-Clarke is managing a hybrid project for Parallax Engine Co to develop a new telemedicine platform. The platform must comply with healthcare data privacy regulations in three countries: the United States (HIPAA), Canada (PIPEDA), and the European Union (GDPR). The team is using two-week sprints for feature development, with regulatory reviews conducted at defined milestones. During sprint planning for the upcoming iteration, the development team proposes building a patient messaging feature. Tane realizes that this feature will involve storing and transmitting protected health information, which has specific compliance requirements that differ across the three jurisdictions. The team has not yet consulted with the compliance officer or reviewed the regulatory requirements for this particular functionality. Which approach would be MOST effective for managing compliance in this situation?
Show answer & explanation

Correct answer: Pause sprint planning and facilitate a working session with the compliance officer, legal advisor, and development team to identify specific requirements for the messaging feature before adding it to the sprint backlog

Explanation

In a hybrid project with regulatory compliance requirements, the project manager must integrate compliance checkpoints proactively into the workflow before work begins on features that carry compliance risk. Bringing the compliance officer and legal advisor together with the development team during sprint planning allows the team to understand the specific requirements across all three jurisdictions before committing to the work. This collaborative approach ensures the feature is designed correctly from the start, prevents costly rework, and maintains compliance throughout development. In hybrid projects, regulatory requirements act as constraints that must be addressed upfront, particularly when consequences of non-compliance include legal penalties or project failure. The team can then incorporate these requirements into their definition of done for this feature.

**Why not A:** Escalating to the project sponsor and waiting for executive approval before doing any work on the messaging feature introduces unnecessary delay in a sprint-based environment and bypasses the appropriate subject matter experts. The compliance officer and legal advisor—not the sponsor—hold the expertise needed to clarify jurisdiction-specific requirements. Executive escalation is warranted for strategic decisions, not for gathering technical compliance information that can be obtained directly.

**Why not C:** Directing the team to build using general security best practices and scheduling a compliance audit after the feature is built is the riskiest approach. HIPAA, PIPEDA, and GDPR each have distinct and specific requirements for storing and transmitting protected health information. General best practices are unlikely to satisfy all three simultaneously, and discovering gaps after the feature is built would require costly rework across multiple compliance frameworks.

**Why not D:** Adding the messaging feature to the sprint backlog with a note to review compliance during the retrospective after the feature is built ensures non-compliant work is committed to and then evaluated too late. The retrospective is a process improvement ceremony, not a compliance review mechanism. Building the feature first and reviewing for compliance afterward creates the exact costly rework scenario that proactive compliance management is designed to prevent.

Key Concept

This question covers Confirm project compliance requirements under Plan and Manage Project Compliance (Business Environment).

Share:

This is 1 of 100 free PMP questions

Unlock 6,300+ PMP practice questions with detailed explanations, progress tracking, and exam readiness prediction.

Unlock All Questions