September 7, 2026 · 6 min read
TL;DR: The risk register shows up in 67 of the bank's answer options: 17 keyed, 50 wrong. Almost every keyed one has the project manager reading the register to find a response somebody already agreed, or correcting it after reality moved. Almost every wrong one uses the register as a place to put a problem instead of a place to look one up.
Nobody fails a PMP question by not knowing what a risk register is. They fail by treating it as an action. Writing a live problem into a document is the most comfortable-looking option on any list, and the exam knows it.
When the scenario tells you the risk was identified earlier. That phrase is doing real work, and it changes what you are being asked.
A key supplier's deliverables have a serious quality problem, and the stem says this supplier risk was identified earlier in the project. Four options: brainstorm with the team, commission a full audit of every supplier deliverable, refer to the risk register for the predetermined mitigation actions, or write to the supplier demanding a rectification plan. Keyed is the register. The response was analysed and approved back when the risk was identified, so brainstorming, auditing, and confronting all redo analysis the project already paid for.
Flip the same scenario. A vendor with a documented history of quality problems misses acceptance criteria twice, and when the project manager checks the register, the vendor's history was never logged. Now there is no response to execute, and the keyed answer is to add the risk and assess it before deciding what to do. Rejecting the deliverable, escalating to default proceedings, and absorbing the rework all pick a remedy before anyone has analysed the risk.
Same artefact, opposite instructions, and the stem tells you which one you are in.
It stops being a risk. A customs hold delays a supplier's shipment and the team improvises a substitute part to keep assembly moving. Once the workaround is in place, the keyed answer records the event in the issue log and updates the risk register to reflect what actually occurred. Not one or the other.
The distractors are instructive because each drops half of it. Updating only the register leaves no record of the issue itself or who handled it. Taking no further action lets the event disappear from the project's memory the moment the work resumes. Closing the register entry because a substitute part exists claims the exposure cannot recur, which the substitute part does not establish.
The register is also maintained downward. When a deliverable that threatened the critical path arrives early, the keyed answer reviews the register and lowers that risk's ranking. Not update the schedule baseline, which has not moved because something arrived on time. Not close an issue log entry, because nothing ever became an issue.
Common trap: treating "record it in the risk register and revisit it at the next review" as a safe, always-defensible answer. It is one of the most reliable wrong answers in the bank. In a scenario where a machine learning model has left clinicians unsure what they are accountable for, that exact option is offered and loses to rewriting the role's responsibilities with the line manager. Logging an accountability gap does not close it. The bank keys the record only when a record is what is missing.
Six situations, and the register wins three of them. In each case the stem tells you which mode you are in.
| Situation | Keyed | Why the register loses or wins |
|---|---|---|
| Risk identified earlier, now occurring | Read the register, execute the planned response | The analysis is done; improvising repeats it |
| Risk never identified, now occurring | Add it and assess before responding | No response exists to execute |
| Risk has occurred and been worked around | Issue log and register update | Two records, two jobs |
| Threat has receded | Lower the risk's ranking | Registers are maintained as things improve |
| Chartering, before planning exists | Enterprise environmental factors | The register does not exist yet |
| A live problem with a clear owner | Resolve it with the owner | Logging it defers the decision |
That last row is where most of the 50 distractors sit.
When is the risk register the keyed answer on the PMP exam? When the scenario names a risk that was identified earlier. The register already holds the agreed response, so the keyed move is to read it and carry that response out rather than improvise a new one.
Why is updating the risk register so often a distractor? Because it is offered as a substitute for acting. In the bank, an option that logs a live problem and revisits it later loses to the option that resolves the problem, unless the scenario genuinely calls for a record.
Does a risk go in the risk register or the issue log? A risk that has occurred is an issue, and the bank keys recording it in the issue log while also updating the risk register to reflect what actually happened. Updating only the register leaves no record of the event or its owner.
Can the risk register be the answer during chartering? No. One bank item asks what to investigate during chartering and keys enterprise environmental factors precisely because the register, the project management plan, and performance reports do not exist yet.
PMP Practice's 2,141 questions are certified against PMBOK 8 and the July 2026 ECO, with every wrong answer explained rather than just marked wrong. Start the free 20-question sample — no card, no signup required to try it.
Related reading: Risk Responses on the PMP Exam: Check Whether You Already Wrote the Plan and Impediments, Blockers and the Issue Log: When to Escalate and When Not To. Risk sits in Business Environment now, mapped on the Business Environment study page.
When is the risk register the keyed answer on the PMP exam?
When the scenario names a risk that was identified earlier. The register already holds the agreed response, so the keyed move is to read it and carry that response out rather than improvise a new one.
Why is updating the risk register so often a distractor?
Because it is offered as a substitute for acting. In the bank, an option that logs a live problem and revisits it later loses to the option that resolves the problem, unless the scenario genuinely calls for a record.
Does a risk go in the risk register or the issue log?
A risk that has occurred is an issue, and the bank keys recording it in the issue log while also updating the risk register to reflect what actually happened. Updating only the register leaves no record of the event or its owner.