What makes a project's end result worth paying for? In PRINCE2, the Quality Theme gives you the tools to ensure that the final product – whether a website, a bridge, or a new insurance policy – actually works as intended and meets the needs of the people who will use it. For the PRINCE2 Foundation exam, the Quality Theme is not just about 'testing' at the end; it is a complete approach that ensures quality is built in from the very start, across four key concepts: quality planning, quality control, quality assurance, and the management products that document it all.
Jump to a section
A simple way to picture Quality Theme
Why does anyone care about quality when renovating a house? Because a beautiful new kitchen is worthless if the wiring is faulty, and a fresh coat of paint hides nothing from a leaky roof. In a home renovation, quality planning is like drawing up the architect's blueprints and the detailed schedule of inspections. You decide upfront: 'The plaster must be smooth to the touch,' and 'All electrical work must pass a certified electrician's check before the walls are sealed.' Quality control is what the site foreman does every day. He walks the site with a spirit level and a tape measure. Is the tiling straight? Is the window frame square? If a wall is out of plumb, he flags it, marks it for rework, and does not let the plasterer move on until it is fixed. Quality assurance is the independent building inspector who visits monthly. That inspector does not work for the renovation company. She is an external expert who checks that the foreman's checks are working properly, that the electrician is actually certified, and that the project meets the national building regulations. The inspector gives the homeowner confidence that the house is safe and built to last. If the inspector finds that the foreman has been skipping checks, she issues a non-compliance report, and the work must stop until the problem is resolved. This whole system – planning, checking daily, and verifying independently – ensures the finished house is exactly what the owner paid for: a safe, beautiful home with no nasty surprises. Without it, you risk a house that looks good in the photos but falls apart in the first rainstorm.
The Quality Theme in PRINCE2 is the set of practices that ensures the project's final products (like a software application, a training course, or a new office layout) are fit for purpose. 'Fit for purpose' is a simple but important phrase. It does not mean 'perfect' in every possible way. It means the product does what the users and the business need it to do, without defects that would stop it working. For example, a cheap, functional plastic chair is 'fit for purpose' for a picnic, whereas an expensive, hand-carved wooden chair might be over-engineered and unnecessary for that same picnic. The goal is to meet agreed requirements, not to over-deliver in ways that waste time and money.
PRINCE2 breaks quality management into three interconnected concepts: Quality Planning, Quality Control, and Quality Assurance. Think of them as the plan, the check, and the independent verification.
Quality Planning is the upfront work of deciding what 'good' looks like. In this step, the project manager works with the customer (the person paying for the project) and the users (the people who will use the finished product) to write down specific, measurable criteria for each product. These criteria are called 'quality criteria'. For example, if the project is to build a simple shopping website, quality criteria might include: 'The checkout page must load in under two seconds,' and 'The customer must be able to see their order total before entering payment details.' PRINCE2 captures these criteria in a document called the Product Description, which describes every product the project will create. Quality planning also defines which methods will be used to check that the product meets those criteria – methods like testing, inspection, or a peer review. All of this is brought together in the Quality Management Strategy, which is the high-level plan for how the whole project will manage quality.
Quality Control is the hands-on, day-to-day checking that happens during the project. It is the work of the project team – the testers, developers, writers, or builders – who inspect the products as they are being created. If the product does not meet the criteria defined in the Quality Plan, the team logs a Quality Register entry, which is a formal record of a quality issue. That issue then triggers 'rework' – fixing the problem before the product is accepted. For example, if the team builds a checkout page that takes five seconds to load, they must go back and optimise the code until it meets the two-second target. Only when the team is satisfied that the product passes its quality checks is it passed to the project board for approval.
Quality Assurance is the independent, external check that the project's approach to quality is itself working correctly. It is not done by the project team or the project manager. Instead, it is carried out by someone outside the project, often a quality assurance department or an external auditor. Their job is to review the processes: Are we doing quality planning well? Are quality control checks being carried out consistently? Are we following the Quality Management Strategy? For example, a quality assurance auditor might find that a team is running only manual tests when the strategy required automated tests. They would report this finding to the project board, who must then fix the process. The purpose of quality assurance is to ensure that the project is not just checking products, but is also using the right ways to check them.
The Quality Theme also introduces several key management products (documents). These are:
Quality Management Strategy: The project-level document that describes how quality will be planned, controlled, and assured. It includes the approach to standards (which industry standards, like ISO 9001, will be followed), the tools and techniques for testing, and the roles responsible for quality.
Product Description: A document for each product that defines its purpose, composition, derivation (where it comes from), format, and the quality criteria that will be used to accept it.
Quality Register: A log of all quality management activities, including planned checks, their results, and any follow-up actions. It is a controlling document that shows the status of quality across the project.
Quality Record: A formal record that a product has passed a quality check. It is the evidence that a quality control activity was completed successfully.
PRINCE2F emphasises that quality is not an afterthought or a final test. Instead, it is integrated into every stage of the project. The project manager creates the Quality Management Strategy during the Initiating a Project process. Every time a product is created or updated, its Quality Criteria are checked. This approach replaces the old model where teams would build a complete product, then spend weeks testing and fixing bugs. In PRINCE2, quality is built in from the start, reducing rework and making projects more predictable.
Define Quality Criteria
During project initiation, the project manager, customer, and users meet to define specific, measurable criteria for each major product. For example, a product like a 'User Login Page' might have criteria: 'Password must be at least eight characters,' and 'Page must load in under one second.' This step ensures everyone has a shared understanding of what counts as 'good' before any work begins.
Write the Quality Management Strategy
The project manager documents the overall approach to quality in the Quality Management Strategy. This includes which standards to follow (e.g., industry standards), which quality methods will be used (testing, peer review, inspection), and who is responsible for each quality activity. This step sets the rules for how quality will be managed across the whole project.
Create the Quality Register
The project manager creates a log called the Quality Register. It initially lists all planned quality checks, when they will happen, and who will perform them. This step establishes a central record that will be updated throughout the project as each check is completed.
Execute Quality Control Checks
During product creation, the project team performs quality control checks according to the plan. They test, inspect, or review each product against the quality criteria defined in the Product Description. If a product fails, the issue is logged in the Quality Register, and the team reworks the product until it passes. This step ensures defects are caught early.
Carry Out Quality Assurance Reviews
An independent person or team outside the project (e.g., a QA department) periodically reviews the quality control activities and the Quality Management Strategy. They check that the project is following the agreed process and that the quality system is effective. If they find a gap, they issue a non-compliance report. This step provides external confidence that quality is being managed properly.
Update and Close Quality Records
At the end of the project, the project manager ensures that every planned quality check has a corresponding Quality Record (evidence the check was done). The Quality Register is closed, and all records are handed to the customer as proof of quality. This step provides traceability and closes the loop on quality activities.
A real IT professional working on a project to build a new online booking system for a chain of dental clinics would use the Quality Theme in every single step of their work.
First, during the project initiation, the project manager would invite the practice managers (the users) and the clinic chain's operations director (the customer) to a Quality Planning workshop. Together, they would define the key quality criteria for the booking system. For example, they might agree that:
The system must allow a patient to book, reschedule, or cancel an appointment in under ten clicks.
The system must show available appointment times within one second of the patient typing their date.
The system must automatically send an email confirmation to the patient within 30 seconds of a booking.
These criteria go into a Product Description for the 'Booking Module' product. The project manager then writes the Quality Management Strategy, specifying that each criterion will be tested using automated scripts (quality control) and that an independent tester from a separate company will perform a security audit (quality assurance) before launch.
Next, during the execution of the project, the development team uses automated testing scripts to check the first milestone – the 'Available Appointments' feature. The test shows that the system takes 1.5 seconds to load appointments. The team logs a Quality Register entry stating the test passed (since 1.5 seconds is below the 2-second limit). They then move on to building the booking flow. When the developer finishes a prototype, the quality control analyst manually goes through the process: clicking through all steps to see if any click is wasted. They find a bug where the patient is asked to enter their contact details twice. This is logged as a quality issue, and the developer reworks the code to combine the two screens into one. The Quality Register is updated with the status 'Fixed and re-tested'.
Meanwhile, the quality assurance auditor – a person from the chain's central IT security team – reviews the quality control logs. They notice that the security tests (checking that patient data is encrypted) were skipped in the last sprint because the team was short on time. The auditor raises a formal non-compliance report. The project manager must then stop all new feature work until the security tests are run. The team runs the tests, they pass, and the auditor closes the report. This independent QA step prevents a potential patient data leak.
Finally, at the end of the project, every product has a Quality Record showing it passed its checks. The customer reviews these records and signs off the project. The result is a booking system that works exactly as agreed, from first click to final confirmation, without any devastating bugs or security holes. The project team can confidently hand over the system, knowing it is fit for purpose.
The PRINCE2 Foundation exam tests the Quality Theme in several predictable ways. First, you must know the definitions of the three core concepts: Quality Planning, Quality Control, and Quality Assurance. The exam loves to ask you to match a description to one of these three terms. For example, a question might describe an external auditor reviewing how testing is done and then ask: 'Which concept does this represent?' The correct answer is always Quality Assurance, not Quality Control, because Quality Assurance focuses on the process, while Quality Control focuses on the product itself.
Second, the exam tests the management products specific to Quality. You must memorise what the Quality Management Strategy contains (the overall plan for quality in the project), what a Product Description contains (quality criteria for a single product), and what the Quality Register is (a log of quality activities). A common trick is to ask: 'Which document describes how quality will be managed across the entire project?' The answer is the Quality Management Strategy, not the Project Plan.
Third, the exam tests the difference between 'quality' and 'grade'. Quality means the degree to which a product meets its specified requirements. Grade means a category of the product that has different technical or functional characteristics. For example, a luxury car (high grade) might still have a faulty engine (low quality). A budget car (low grade) might have a perfectly working engine (high quality). The exam will present scenarios where a product is described as 'high grade but poor quality' or 'low grade but good quality', and you must identify which is which.
Here is a list of the most frequent exam traps and the correct patterns: - Trap: Confusing Quality Control with Quality Assurance. The exam often presents a scenario where a team member does a test. Some candidates think this is Quality Assurance because it is a check, but the correct answer is Quality Control, because the team member is checking the product itself, not the process. - Trap: Mistaking the Quality Register for a Product Description. The Quality Register is a log of all quality activities. The Product Description defines the criteria for one product. If the question mentions 'a list of all planned inspections and their results,' it is the Quality Register. - Trap: Believing Quality Assurance is the same as a final audit. Quality Assurance is an ongoing, independent review throughout the project, not just at the end. - Trap: Forgetting that the project manager owns the Quality Management Strategy. The project board approves it, but the project manager creates and maintains it. - Key definitions to memorise: - Acceptance criteria: The measurable conditions that must be met for a product to be accepted by the customer (defined in the Project Product Description). - Quality criteria: Specific, measurable statements that define what a product must achieve (defined in a Product Description). - Quality methods: The specific techniques used for checking quality (e.g., testing, inspection, peer review). - Quality roles: Defined in the Quality Management Strategy, including who is responsible for planning, controlling, and assuring quality.
Finally, the exam will test your understanding that Quality Planning happens early in the project, specifically during the Initiating a Project process. It is not left until later stages. A question might ask: 'At which point is the Quality Management Strategy created?' The answer is 'During the Initiating a Project process'.
Quality in PRINCE2 is defined as 'fit for purpose', not 'perfect', meaning the product must meet its agreed requirements.
Quality Planning decides upfront what 'good' looks like by defining measurable quality criteria for each product.
Quality Control is the hands-on checking of the product itself, performed by the project team during creation.
Quality Assurance is the independent review of the quality management process, performed by an external person or department.
The Quality Management Strategy is the project-level plan for how quality will be managed, created during project initiation.
The Product Description specifies the quality criteria for a single product, while the Quality Register logs all quality activities and their results.
Grade and Quality are not the same: a product can be high grade but poor quality, or low grade but excellent quality.
Acceptance criteria define what the customer needs for final approval, while quality criteria define interim product checks.
These come up on the exam all the time. Here's how to tell them apart.
Quality Control
Focuses on checking the product itself (e.g., testing software for bugs).
Performed by the project team (developers, testers).
Happens during product creation and is documented in the Quality Register.
Quality Assurance
Focuses on checking the process used to manage quality (e.g., auditing whether testing procedures are followed).
Performed by someone independent of the project (e.g., an external QA department).
Happens periodically throughout the project and results in non-compliance reports.
Quality Management Strategy
Describes the overall approach to quality for the entire project.
Created once during project initiation and applies to all products.
Includes standards, methods, and roles for quality.
Product Description
Describes the quality criteria and acceptance method for a single product.
Created for each product, often multiple times in a project.
Includes the product's composition, format, and derivation.
Quality Criteria
Defined in the Product Description for individual products.
Used by the project team to check if a product is correct during development.
Measurable statements specific to a single product (e.g., 'The button must be blue').
Acceptance Criteria
Defined in the Project Product Description for the entire project output.
Used by the customer to decide whether to accept the final project deliverable.
Measurable statements for the whole product set (e.g., 'The system must handle 500 simultaneous users').
Grade
A category assigned to a product based on its technical or functional characteristics (e.g., economy, business, first class).
A product can be high or low grade.
Grade changes the features or performance level of the product.
Quality
The degree to which a product meets its specified requirements.
A product can be high quality (meets requirements well) or low quality (fails to meet them).
Quality is about conformance to requirements, not about feature richness.
Quality Register
A log of all planned and completed quality activities for the project.
Used as a controlling document to track the status of quality checks.
Includes entries for each check, whether planned, in progress, or completed.
Quality Record
A formal document providing evidence that a specific product passed a quality check.
Created as an output of a quality control activity.
Acts as proof that the check was performed and the product met the criteria.
Mistake
Quality means the product must be perfect, with zero defects, no matter the cost.
Correct
Quality in PRINCE2 means 'fit for purpose' – the product meets its agreed requirements and acceptance criteria. A low-cost, functional product is high quality if it does what it is meant to do, even if it is not luxurious.
People in everyday life often equate quality with luxury or perfection. PRINCE2 redefines quality relative to requirements, so beginners mistakenly think they need to eliminate all possible errors, which is unrealistic and not the exam's definition.
Mistake
Quality Control and Quality Assurance are the same thing, just with different names.
Correct
Quality Control is checking the product itself (does it meet its criteria?), while Quality Assurance is checking the process (are we doing the checking correctly?). They are separate functions with different goals and often different people responsible for them.
Both terms contain the word 'quality' and both involve checking. Beginners often blur them because they sound similar in everyday conversation. The exam specifically tests the distinction.
Mistake
The project manager is responsible for doing all the quality checking themselves.
Correct
The project manager is responsible for planning and managing quality, but the actual quality control checks are done by the project team (developers, testers), and quality assurance is done by an independent external person or department.
Beginners often think the project manager is the only person responsible for everything. In reality, PRINCE2 distributes responsibility to the right people to ensure independent verification.
Mistake
The Quality Register is only created at the very end of the project, when the final product is tested.
Correct
The Quality Register is created at the start of the project, during initiation, and is updated continuously throughout the project as each quality check is planned, executed, and logged.
People think of testing as a final activity, so they assume the log of testing is also a final document. PRINCE2 emphasises continuous quality control, so the register evolves from project start to end.
Mistake
You only need a Quality Management Strategy if your project has a large budget or many people.
Correct
Every PRINCE2 project must have a Quality Management Strategy, regardless of size. The amount of detail may vary, but the document is mandatory because quality cannot be left to chance.
Beginners often think formal quality management is only for big, expensive projects. PRINCE2 makes it mandatory for all projects to ensure consistency and reduce risk, even in small teams.
Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.
Quality Control is checking the product itself (e.g., testing that a search function returns correct results). Quality Assurance is checking the process used to create and check products (e.g., reviewing whether the testing procedure is being followed correctly). Quality Control is done by the project team; Quality Assurance is done by an independent person or department.
Yes, PRINCE2 requires a Quality Management Strategy for every project, regardless of size. For a small project, the strategy can be a short document or even a few paragraphs, but it must exist to ensure quality is planned and managed, not left to chance.
Quality criteria are defined in the Product Description for each individual product and are used to check the product during development (e.g., a report must be in PDF format). Acceptance criteria are defined in the Project Product Description for the whole project and are used by the customer to decide whether to accept the final deliverable (e.g., the entire reporting system must handle 10,000 users per hour).
The project manager is responsible for planning and coordinating quality activities. The project team (developers, testers) performs quality control. An independent person or department performs quality assurance. The project board approves the Quality Management Strategy and is ultimately accountable for the project's quality.
The Quality Register is a log that records all planned and completed quality checks. It shows the status of each check (e.g., planned, in progress, passed, failed) and includes notes on any rework needed. It helps the project manager track quality activities and provides an audit trail.
'Fit for purpose' means the product meets the agreed requirements and acceptance criteria. It does not mean the product is perfect or the most luxurious version possible. For example, a simple, low-cost chair that holds a person safely is fit for purpose, even if it is not a designer item.
You've finished Quality Theme. Continue through the PRINCE2F study guide to build a complete picture of the exam.
Done with this chapter?