Is this email from risk-management@shopify.com legitimate?

I agree. It is unprofessional of them and absurd. I spent a lot of my own time making sure it was legit before completing the form. As you said, it should be from within the Shopify admin where other important notices and action requests are posted.