Courseiva
Business Environment: strategy and project benefitsmediumMultiple ChoiceObjective-mapped

First Step When a New Regulatory Requirement Is Discovered During Project Execution

During a project to implement a new CRM system, the team discovers a new regulatory requirement that affects data privacy. The requirement was not identified during planning. What should the project manager do first?

Quick Answer

The correct first step when a new regulatory requirement is discovered during project execution is to document it as a risk in the risk register and plan a response. This is because the PMBOK Guide treats newly identified, unplanned constraints as potential threats that must be captured through iterative risk management before any scope or schedule changes are made. On the PMP exam, this scenario tests your understanding that risk identification and analysis precede change control; a common trap is jumping to a change request or immediately updating the project management plan. The key distinction is that a new regulation is first a risk to compliance, not yet a change to scope. Remember the mnemonic: "Risk first, change later" — always log the threat in the risk register before escalating to a formal change request.

⚠ Common exam trap

A common mix-up: candidates confuse a new regulatory requirement with a scope change, leading them to choose immediate action like stopping the project (A) or ignoring it (D), instead of recognizing that the PMBOK process requires risk documentation as the first step before any change control or escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the new requirement as a risk in the risk register and plan a response

The project manager's first action upon discovering an unidentified regulatory requirement is to document it as a risk in the risk register and plan a response. This aligns with the PMBOK Guide's iterative risk management process, where new threats are captured and analyzed before any project changes are made. The requirement is a potential threat to data privacy compliance, and documenting it as a risk allows the team to assess its impact and determine the appropriate response, such as a change request to the scope or a mitigation plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Immediately stop the project until the requirement is fully understood

    Why it's wrong here

    Stopping the project may be too drastic without first analyzing the impact.

  • Ask the legal department to handle the requirement separately

    Why it's wrong here

    The PM should integrate the response within the project, not delegate entirely.

  • Document the new requirement as a risk in the risk register and plan a response

    Why this is correct

    The risk register is used to capture and manage emerging risks. The PM should assess impact and plan response.

  • Continue with the project as planned because the requirement was not in the initial scope

    Why it's wrong here

    Ignoring regulatory requirements can lead to non-compliance and legal issues.

About these practice questions

One of 800 original PMP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on PMP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are the project manager for a government IT project. Midway through, a new regulation is enacted that requires additional data privacy controls. The team estimates this will add 4 weeks to the schedule and increase costs by 10%. What should you do FIRST?

hard
  • A.Instruct the team to start implementing the new controls immediately
  • B.Ignore the regulation until the project is complete to avoid delays
  • C.Recommend stopping the project until the regulation is clarified
  • D.Submit a change request to the change control board to incorporate the required changes

Why D: When a new regulation impacts a project, the project manager should follow the formal change control process. The first step is to assess the impact and submit a change request to the change control board (CCB) for review and approval. This ensures compliance while maintaining proper governance. Option A is wrong because implementing changes without approval bypasses change control. Option B is wrong because ignoring regulations exposes the organization to legal risk. Option C is wrong because stopping the project is an extreme measure that should only be considered after evaluating alternatives.

Variation 2. A project manager is implementing a project in a highly regulated industry. A new regulatory requirement is discovered that will affect the project's deliverables. The project is already in execution. What should the project manager do first?

medium
  • A.Stop the project until legal clarifies the requirement.
  • B.Immediately update the project plan to incorporate the new requirement.
  • C.Continue the project as planned and address the requirement in a follow-up project.
  • D.Assess the impact of the requirement on the project and submit a change request if needed.

Why D: The correct first step is to assess the impact of the new regulatory requirement on the project's scope, schedule, cost, and quality. This aligns with the PMBOK® Guide's process of performing integrated change control. After assessing the impact, the project manager should submit a change request if a change is needed. Option A is reactive and may not be necessary without understanding the impact. Option B bypasses the formal change control process. Option C avoids addressing the requirement in the current project, which could lead to non-compliance. Therefore, D is the appropriate initial action.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.