Skip to main content
Category: Internal Audit and Assurance

Audit Sampling

Simply put

Audit sampling is a technique in which an auditor examines less than 100 percent of the items in a group of transactions or an account balance, rather than testing every single item. The auditor uses the results from the selected sample to draw conclusions about the larger population. This approach is generally used when testing every item would be impractical.

Formal definition

Audit sampling is the application of an audit procedure to less than 100 percent of the items within an account balance or class of transactions (or, more broadly, a population of audit relevance) for the purpose of forming a conclusion about the population as a whole. It is used both in tests of controls and in substantive testing, and sampling methods are typically aligned with applicable auditing standards and frameworks (for example, PCAOB standards or AICPA guidance). Because a sample provides only a partial basis for conclusions, sampling introduces sampling risk that the auditor must consider; the appropriate method and sample size depend on the audit objective, the population, and the auditor's professional judgment.

Why it matters

Testing every transaction in a large population is often impractical or uneconomical, so audit sampling allows auditors to form conclusions about an account balance or class of transactions by examining only a portion of the items. When applied appropriately, sampling lets auditors gather sufficient evidence to support their conclusions while managing the time and cost of an engagement. This makes it a foundational technique across both tests of controls and substantive testing.

Because a sample provides only a partial basis for conclusions, it introduces sampling risk, the possibility that the auditor's conclusion drawn from a sample differs from the conclusion that would be reached if the entire population were tested. Poorly designed samples, inadequate sample sizes, or samples that are not representative of the population can lead an auditor to miss material misstatements or to misjudge whether a control is operating effectively. Managing this risk through appropriate method selection and sample sizing is central to the reliability of the audit.

The stakes are heightened by the fact that sampling decisions rest heavily on the auditor's professional judgment and must generally align with applicable auditing standards, such as PCAOB standards or AICPA guidance, depending on the engagement. The suitability of any sampling approach depends on the specific audit objective, the nature of the population, and the facts of the engagement, so the technique supports, but does not replace, careful judgment about how much evidence is enough.

Who it's relevant to

Internal Auditors
Internal auditors regularly use sampling to test controls and transactions across large populations where examining every item would be impractical. Method selection and sample sizing rest on their professional judgment and, where applicable, on relevant auditing standards and frameworks.
External and Financial Statement Auditors
External auditors apply sampling in both tests of controls and substantive testing to form conclusions about account balances and classes of transactions. Their approaches are typically aligned with applicable standards such as PCAOB standards or AICPA guidance, depending on the engagement.
Chief Audit Executives and Assurance Leaders
Those responsible for audit methodology and quality need to understand how sampling risk is managed within their functions, since the reliability of audit conclusions depends on sound sample design, appropriate sample sizes, and consistency with applicable standards.
Audit Committee Members
Audit committee members overseeing internal and external assurance benefit from understanding that conclusions are often based on samples rather than complete populations, and that sampling introduces a risk the committee should be aware of when weighing the assurance provided. This entry is educational and not a substitute for professional audit advice.

Inside Audit Sampling

Sampling Population
The complete set of items or transactions from which a sample is drawn. Defining the population precisely, including its completeness and the period covered, is a prerequisite for conclusions about the whole set to be valid.
Sampling Unit
The individual element selected for testing, such as a transaction, account balance, journal entry, or control instance. The choice of sampling unit should align with the audit objective.
Statistical Sampling
An approach that uses probability-based selection and quantitative evaluation, allowing the auditor to measure sampling risk and express results with a defined level of confidence. Methods generally include random and systematic selection.
Non-Statistical (Judgmental) Sampling
An approach where selection and evaluation rely on the auditor's professional judgment rather than probability theory. It does not permit a quantified measure of sampling risk, though it may still produce a reasonable basis for a conclusion.
Sampling Risk
The risk that the auditor's conclusion based on a sample differs from the conclusion that would result from testing the entire population. It is distinct from non-sampling risk, which arises from factors such as human error or applying inappropriate procedures.
Tolerable Error / Deviation Rate
The maximum error or rate of control deviation the auditor is willing to accept while still concluding the tested objective is met. This threshold typically influences the required sample size.
Attribute Sampling
A technique generally used in tests of controls to estimate the rate of occurrence of a particular condition or deviation within a population.
Variables Sampling
A technique generally used in substantive tests to estimate a monetary amount, such as the total misstatement in an account balance.
Sample Evaluation and Projection
The step in which results from the tested items are analyzed and, where appropriate, projected to the population, with consideration of both identified errors and the residual sampling risk.

Common questions

Answers to the questions practitioners most commonly ask about Audit Sampling.

Does audit sampling let the auditor examine only a few items and still guarantee that the entire population is free from error?
No. Sampling involves applying an audit procedure to less than 100% of the items in a population so that the auditor can draw a conclusion about the whole population, but it does not provide a guarantee. By definition, testing less than the full population introduces sampling risk, the risk that the auditor's conclusion based on the sample differs from the conclusion that would be reached if the entire population were tested. Sampling supports reasonable, not absolute, assurance, and any conclusion is subject to the limitations of the method, the sample size, and the auditor's judgment. This entry is educational and not audit advice.
Is statistical sampling always superior to non-statistical (judgmental) sampling?
Not necessarily. Statistical sampling uses random selection and probability theory to measure sampling risk and project results quantitatively, while non-statistical sampling relies on the auditor's judgment to select items and evaluate results. Neither is inherently better; each can be appropriate depending on the objective, the population, and cost-benefit considerations. Statistical methods allow sampling risk to be quantified, but a well-designed non-statistical approach can also provide sufficient appropriate evidence. The choice generally depends on the engagement's facts and the auditor's professional judgment, and applicable standards may frame the options differently by jurisdiction and context.
How does an auditor decide on an appropriate sample size?
Sample size is generally influenced by factors such as the desired level of assurance (and the acceptable sampling risk), the tolerable rate of deviation or tolerable misstatement, the expected level of deviation or misstatement in the population, and, for certain approaches, population characteristics like variability. As the auditor accepts less sampling risk or tolerates less error, sample size typically increases. Determining sample size is a matter of professional judgment applied within the framework the auditor is following; this description is conceptual and not a formula or a substitute for the applicable standards.
What is the difference between using sampling in tests of controls versus tests of details?
In tests of controls, sampling is typically used to evaluate whether a control operated effectively over a period, here the auditor is often concerned with a rate of deviation from the expected control performance. In tests of details (substantive testing), sampling is typically used to evaluate whether a class of transactions or account balance is materially misstated, here the auditor is often concerned with the amount of misstatement. The objective differs, so the way error is defined, projected, and evaluated differs accordingly. The specific approach depends on the engagement and the auditor's judgment.
How should an auditor handle a deviation or misstatement identified within a sample?
When an auditor identifies a deviation or misstatement in a sampled item, it is generally investigated to understand its nature and cause and to consider its effect on the audit objective and on other areas. Depending on the approach, results are typically projected from the sample to the population, and the auditor evaluates whether the projected error, together with sampling risk, exceeds the tolerable threshold. An anomaly that is demonstrably not representative of the population may be treated differently, but that determination requires care and judgment. How results are evaluated depends on the sampling method and the applicable standards.
How does audit sampling relate to the assurance and oversight structure within an organization?
Sampling is a technique used by assurance functions, such as internal audit, and by external auditors when gathering evidence; it is one method among several for obtaining evidence rather than an oversight responsibility in itself. Management retains ownership of the controls and processes being tested, assurance functions design and perform the testing (which may include sampling), and the board or its audit committee generally oversees the adequacy of the overall assurance activity rather than performing the sampling. This separation of roles should be preserved when interpreting sampling results, and the appropriate application depends on the entity and the professional's judgment.

Common misconceptions

Audit sampling provides certainty about the entire population.
Sampling inherently involves sampling risk; testing less than 100% of items means the auditor's conclusion may differ from what full examination would show. Sampling supports a reasonable basis for a conclusion rather than absolute assurance.
A larger sample is always better and statistical sampling is always superior to judgmental sampling.
Sample size should be driven by the audit objective, tolerable error, expected error, and desired assurance rather than size for its own sake. Both statistical and non-statistical approaches can be appropriate; statistical methods allow sampling risk to be quantified, while judgmental methods rely on professional judgment, and the suitable choice depends on the engagement circumstances.
Finding no errors in a sample means the population is free of errors.
The absence of exceptions in a sample does not prove the population is error-free; it supports a conclusion only within the limits of sampling risk and the defined tolerable error. Errors may still exist in untested items.

Best practices

Define the population and sampling unit precisely before selection, confirming completeness and alignment with the specific audit objective being tested.
Select the sampling approach (statistical or non-statistical) based on the objective, the need to quantify sampling risk, and available data, and document the rationale for the choice.
Establish tolerable error or deviation rate and expected error in advance, and use these to inform sample size rather than selecting a size arbitrarily.
Distinguish between tests of controls and substantive tests when choosing between attribute and variables techniques, matching the method to what is being measured.
Investigate the nature and cause of any exceptions identified, and consider whether they are isolated or indicative of a broader pattern before projecting results.
Document the population, methodology, sample selection, evaluation, and conclusions clearly, and remember that sampling supports a reasonable basis for a conclusion, not a guarantee, given both sampling and non-sampling risk.