nerdexam
PMI

PMP · Question #28

A project manager for a software development company faces a number of financial risks in their project. The project manager needs to frequently check the strength and efficiency of the risk managemen

The correct answer is D. Audit meeting. To frequently check the strength and efficiency of the risk management process, the project manager should utilize audit meetings. These meetings allow for a systematic review and evaluation of the risk processes and their effectiveness.

Submitted by tarun92· Apr 18, 2026Process

Question

A project manager for a software development company faces a number of financial risks in their project. The project manager needs to frequently check the strength and efficiency of the risk management process. What should the project manager use to accomplish this?

Options

  • ABrainstorming session
  • BStakeholder register
  • CAssumption log
  • DAudit meeting

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    8% (2)
  • C
    4% (1)
  • D
    71% (17)

Why each option

To frequently check the strength and efficiency of the risk management process, the project manager should utilize audit meetings. These meetings allow for a systematic review and evaluation of the risk processes and their effectiveness.

ABrainstorming session

A brainstorming session is used for generating ideas (e.g., identifying risks or solutions), not for *checking the efficiency* of an existing process.

BStakeholder register

A stakeholder register lists project stakeholders and their attributes; it is not a tool for evaluating the risk management process itself.

CAssumption log

An assumption log documents assumptions and constraints; it is not used to audit the efficiency of the risk management process.

DAudit meetingCorrect

An audit meeting is a formal, systematic process to examine and evaluate the effectiveness of project management processes, including risk management. Regularly conducting audit meetings allows the project manager to assess if the risk management plan is being followed, if risks are being identified and responded to effectively, and if the overall process is strong and efficient.

Concept tested: Risk management process audit

Source: https://www.pmi.org/learning/library/project-risk-management-process-audit-1011

Topics

#Risk Management#Risk Audits#Monitoring and Controlling Risks#Process Evaluation

Community Discussion

10
Carlos M.Carlos M.Jul 5, 2026

D is correct. When the question says "check the strength and efficiency of the risk management process," that is straight out of the PMBOK definition of risk audits. You audit a process to see if it is working, simple as that. A, B, and C are inputs or tools you use during risk work, not how you evaluate if the process itself is effective. I got this exact framing on my exam last month and D was the right call.

25
Yusuf A.Yusuf A.Jul 7, 2026

That "evaluate the process itself" framing is exactly how my senior described it when he walked me through risk audits, said the trick is noticing the question is asking about the process, not individual risks.

0
Yusuf A.Yusuf A.Jul 5, 2026

D is right here. One of the senior PMs at my company told me to think of audits as the "health check" for your risk process, not the risks themselves. Quick question though, does anyone know if audit findings typically feed back into the risk register or do they go straight into lessons learned?

3
Grace U.Grace U.Jul 6, 2026

Your PMs framing is spot on, and yes, audit findings absolutely feed back into the risk register if they uncover new risks or expose gaps in existing risk responses, with lessons learned capturing the broader process takeaways afterward.

0
Grace U.Grace U.Jul 5, 2026

D is correct here. The key phrase in the stem is "check the strength and efficiency of the risk management process," which is the exact purpose of a risk audit. Brainstorming is for generating ideas and the assumption log tracks assumptions and constraints, so neither fits the need to evaluate how well your process is working. One thing that helped me lock this in was connecting it to the broader Monitor and Close process group. Does anyone know if risk audits are typically conducted by the project team itself or by an external party like PMO, and does that distinction matter on the exam?

2
Yusuf A.Yusuf A.Jul 8, 2026

One of the senior PMs at my company showed me that the exam leans toward risk audits being conducted by the project team or PMO, not necessarily external, so Grace's instinct to check that distinction is worth confirming with a practice question or two.

0
Olusegun A.Olusegun A.Jul 5, 2026

Leaned toward A first, but frequent checking of process efficiency = audit meeting.

1
Grace U.Grace U.Jul 6, 2026

Agreed on A, and the word efficiency is the real clue here rather than just checking, since an audit meeting evaluates how well things are running, not just whether they are running.

0
Hiroshi T.Hiroshi T.Jul 5, 2026

D is correct per PMBOK 6th Edition, section 11.7, which defines Control Risks as including risk audits to evaluate the effectiveness of the risk management process. One thing I want to confirm, does anyone know if the PMP exam still treats risk audits as a distinct tool from the broader Control Risks process, or has the 2021 content outline folded this entirely into Monitor and Close Project Phase?

1
Carlos M.Carlos M.Jul 8, 2026

D is right but the current exam uses the PMBOK 7th edition terminology where risk audits live under Monitor Risks, and the 2021 content outline groups it into the Monitor and Control Project Performance domain, so just match the wording to whichever edition your prep materials reference.

0
Full PMP Practice