PMBOK Project Compliance and Governance 5 — Questions and Answers
Question 1: A project manager notices that a team member is bypassing the change control process to avoid delays. What is the MOST appropriate response?
- Allow it since the team member has good intentions
- Coach the team member on governance requirements and reinforce the change control process (Correct answer)
- Report the team member to senior management immediately without discussion
- Retroactively approve all unauthorized changes to maintain project momentum
Correct answer: Coach the team member on governance requirements and reinforce the change control process
The project manager should educate the team member on why change control governance exists and ensure future compliance with the established process.
Question 2: Which PMBOK knowledge area MOST directly encompasses governance of project changes, baselines, and corrective actions?
- Project Risk Management
- Project Integration Management (Correct answer)
- Project Scope Management
- Project Stakeholder Management
Correct answer: Project Integration Management
Project Integration Management encompasses integrated change control, baseline management, and coordinating corrective actions across the entire project.
Question 3: A project governance review finds that lessons learned have not been documented. What is the RISK of this non-compliance?
- The project budget will be automatically reduced
- Future projects cannot benefit from this project's experience, reducing organizational learning (Correct answer)
- The project team will be disqualified from future projects
- The project's quality score will be retroactively lowered
Correct answer: Future projects cannot benefit from this project's experience, reducing organizational learning
Failing to document lessons learned means the organization loses valuable knowledge that could improve future project governance and performance.
Question 4: A project manager is asked to sign off on a deliverable that does not fully meet compliance standards in order to meet the deadline. What should the project manager do?
- Sign off to avoid delaying the project
- Refuse to sign off and document the non-compliance as an issue requiring resolution (Correct answer)
- Delegate the sign-off to a team member to avoid personal liability
- Ask the client to waive the compliance requirement informally
Correct answer: Refuse to sign off and document the non-compliance as an issue requiring resolution
The project manager must not approve a non-compliant deliverable; the issue should be formally documented and resolved through proper channels.
Question 5: Which metric is MOST useful for monitoring a project's ongoing compliance with scope governance?
- Cost performance index (CPI)
- Schedule variance (SV)
- Number of approved versus rejected change requests (Correct answer)
- Team velocity in story points
Correct answer: Number of approved versus rejected change requests
Tracking the ratio of approved versus rejected change requests shows how well the project is controlling scope and adhering to its governance process.
Question 6: In PMBOK, what distinguishes a governance risk from a project execution risk?
- Governance risks relate to the threat of natural disasters affecting the project
- Governance risks involve failures in oversight, decision-making authority, or compliance with policies (Correct answer)
- Governance risks are only relevant during project closure
- Governance risks are lower priority than technical risks
Correct answer: Governance risks involve failures in oversight, decision-making authority, or compliance with policies
Governance risks specifically relate to breakdowns in oversight structures, decision authority, accountability, or policy compliance, rather than technical execution failures.
Question 7: A project manager is implementing a new software system for a healthcare client. Which type of compliance is MOST critical to address in the project's governance plan?
- ISO 9001 quality management certification
- HIPAA regulations protecting patient health information (Correct answer)
- PMP certification requirements for team members
- Agile manifesto principles for software delivery
Correct answer: HIPAA regulations protecting patient health information
Healthcare software projects in the US must comply with HIPAA regulations governing the privacy and security of protected health information.
A project manager notices that a team member is bypassing the change control process to avoid delays.
What is the MOST appropriate response?