In both Adaptive (Agile) and Predictive (Waterfall) environments, a new external factor—such as a government or industry regulation—represents an uncertainty that could impact the project ' s objectives, timeline, or cost.
Why Choice A is correct:
Enterprise Environmental Factors (EEF): New regulations are classic examples of EEFs. Because the regulation is " upcoming " and its full impact may not be immediately known, it is initially treated as a Risk.
Risk Register Function: The Risk Register is the primary document for recording all identified risks. Even in Agile, the project manager (or the team) must document the threat, assess its probability and impact on the deliverables, and plan a response (e.g., updating the definition of done or adding specific compliance tasks to the backlog).
Visibility: Recording it here ensures it is monitored during daily stand-ups or risk-adjusted backlog refinement sessions, rather than being forgotten in a specific sprint.
Analysis of other options:
B (Sprint board): The sprint board (or Task board) is used to track the status of work items already committed to the current sprint. A new regulation is a high-level concern that needs analysis before specific tasks can be placed on a board.
C (Sprint planning): This is an event, not a documentation location. While the regulation would certainly be discussed during the next sprint planning session to determine how it affects the upcoming work, the regulation itself must be officially recorded in a tracking document like the risk register first.
D (User story): A user story describes a specific piece of functionality from an end-user perspective. While the regulation might eventually result in new user stories (e.g., " As a user, I want my data handled according to Regulation X " ), the regulation itself is a constraint or a risk, not a user story.
Key Concept: The Project Management Institute (PMI) emphasizes that while Agile teams focus on the Product Backlog, the Risk Register (Choice A) remains a vital tool for transparently managing threats. By identifying the regulation as a risk, the team can proactively decide whether to " Mitigate " it by changing the design or " Avoid " it by adjusting the project scope, ensuring the deliverable remains compliant.