Audit Sampling: Methods, Techniques, Sample Size, Risk & Examples

In Simple Terms:

Audit sampling means testing a carefully selected portion of a larger population to obtain audit evidence about the population as a whole.

What Is Audit Sampling?

Audit sampling is an audit procedure in which the auditor applies testing procedures to fewer than 100% of the items in a relevant population and uses the results to draw conclusions about that population.

The objective is not simply to test fewer items. The sample should be designed and selected to provide an appropriate basis for the auditor’s conclusion. This requires a clearly defined audit objective, an appropriate population, a defensible selection method, an adequate sample size, appropriate testing procedures, and documented evaluation of the results.

In practice, audit sampling allows auditors to obtain audit evidence from a representative or appropriately selected portion of a population without examining every item. The results are then evaluated to determine whether they support the audit objective and whether exceptions or deviations require further investigation.

Why Is Audit Sampling Used in Auditing?

1. Makes Testing Practical

A large population may make 100% testing impractical. Sampling allows auditors to focus testing on a manageable number of items.

2. Obtains Audit Evidence

A properly designed sample can provide evidence that supports conclusions about a population.

3. Improves Efficiency

Reduces unnecessary testing while allowing auditors to focus resources on areas that matter most.

4. Supports Risk-Based Auditing

Sampling decisions should be connected to the audit objective, risk assessment, and overall audit plan.

5. Tests Recurring Controls

Determine whether controls operated consistently during a defined period.

Key Terms Used in Audit Sampling

Term Meaning
Population The complete set of items from which the sample is selected
Sampling Unit An individual item capable of being selected from the population
Sample The items selected for audit testing
Sampling Risk The possibility that a conclusion based on the sample differs from testing the entire population
Tolerable Deviation Rate Maximum rate of deviation the auditor is willing to accept
Tolerable Misstatement Amount of misstatement the auditor is willing to accept
Expected Deviation Rate Rate of control deviations the auditor expects to find
Stratification Dividing a population into sub-populations with similar characteristics
Sampling Interval Interval used to select items in systematic or value-based sampling

Types of Audit Sampling

Statistical Audit Sampling

Uses probability theory to select samples and evaluate results. Characteristics include random selection, defined sampling parameters, quantifiable sampling risk, structured sample-size determination, and statistical evaluation of results.

Non-Statistical Audit Sampling

Relies more heavily on professional judgment. The auditor determines the sample based on factors such as audit objective, risk, materiality, population characteristics, expected exceptions, and previous audit results.

Note:

SA 530 recognizes both statistical and non-statistical approaches to audit sampling. Non-statistical sampling is not automatically inferior to statistical sampling.

Audit Sampling Methods

Random Sampling

Items selected using a random mechanism. Best suited for large transaction populations and general control testing.

Systematic Sampling

Selects items using a defined interval after establishing an appropriate starting point.

Monetary Unit Sampling

Gives greater selection weight to monetary values. Useful when the audit objective is focused on potential overstatement.

Haphazard Sampling

Selecting items without formal randomization while attempting to avoid conscious bias.

Block Sampling

Selecting a contiguous group of items. Use with caution as a single block may not represent the entire population.

Judgmental/Targeted Selection

Deliberately selecting items with particular risk characteristics: high-value, unusual, previous exceptions, privileged users.

Audit Sampling Techniques

  • Random selection: Each sampling unit has a defined chance of selection
  • Stratification: Dividing population into groups (high/medium/low value, business unit, geography)
  • High-value item testing: Large or individually significant items tested separately
  • Risk-based selection: Items with higher risk receive greater attention
  • Exception-focused testing: Investigating unusual items or previous exceptions
  • Combined approaches: High-value items tested separately, remaining population subjected to systematic sampling

How to Determine Audit Sample Size

One of the most common mistakes in audit sampling is treating sample size as a fixed percentage of the population. There is no universal rule that makes 10% an appropriate sample for every audit. Sample size should be determined based on the audit objective, assessed risk, tolerable deviation or misstatement, expected deviation or misstatement, and the level of assurance required—not simply as a fixed percentage of the population.

Factors That Influence Sample Size

  • Population size: Number of items in the population
  • Risk: Higher assessed risk may require more extensive testing
  • Tolerable deviation or misstatement: The amount of error the auditor is willing to accept
  • Expected deviation or misstatement: The rate of deviations the auditor expects
  • Desired assurance: Level of assurance from the sampling procedure
  • Population characteristics: Whether stratification or other approaches are needed

Example

Suppose an internal auditor needs to test 15,000 purchase transactions. Instead of choosing 1,500 because it represents 10%, the auditor should consider:

  • What exactly is the population?
  • What is the sampling unit?
  • What control is being tested?
  • What is the assessed risk?
  • What deviation rate is acceptable?
  • What deviation rate is expected?
  • What level of assurance is required?
  • Which sampling approach is appropriate?
  • Are high-value or high-risk transactions being tested separately?

Audit Sampling Risk

Sampling risk is the possibility that the conclusion reached from testing a sample differs from the conclusion that would have been reached if the entire population had been tested.

Risk of Incorrect Acceptance

Concluding that a population is acceptable when it is not. Can result in insufficient audit response to a problem.

Risk of Incorrect Rejection

Concluding that a population is not acceptable when the true population condition would support an acceptable conclusion.

Audit Sampling for Tests of Controls

Sampling is commonly used to test whether a control operated consistently over a period.

Example

An organization requires all purchase orders above ₹1 lakh to receive approval from an authorized manager. The auditor may:

  • Define the population of relevant purchase orders
  • Establish the audit objective
  • Determine the sampling approach
  • Select the sample
  • Verify the required approval for each selected transaction
  • Record deviations
  • Evaluate the results
  • Document the conclusion

What is a Control Deviation?

A deviation occurs when the prescribed control was not performed as required. For example, a purchase order exists but the required approval is missing. That item represents a control deviation that should be evaluated.

Audit Sampling for Tests of Details

Tests of details examine individual transactions, balances, or supporting information. Examples include testing invoice amounts, account balances, purchase transactions, sales transactions, supporting documents, vendor balances, expense claims, and journal entries.

Important:

Audit sampling is not itself a test of details. Sampling is a method for selecting items for testing. The selected items may then be subjected to tests of details, tests of controls, or other appropriate audit procedures depending on the audit objective.

Audit Sampling vs 100% Testing

Factor Audit Sampling 100% Testing
Population coverage Less than 100% Entire population
Testing effort Generally lower Generally higher
Sampling risk Exists Eliminated
Suitable for Large populations and recurring items Small or highly significant populations

Audit Sampling Examples

Example 1: Purchase Transactions

An organization has 20,000 purchase transactions. The auditor defines the population, identifies the sampling unit, determines the sampling approach, selects the sample, checks purchase orders and invoices, verifies approval, records exceptions, evaluates results, and documents the conclusion.

Example 2: User Access Review

An organization has 3,500 active user accounts. The auditor tests selected users for access request, manager approval, role assignment, privileged access, employment status, termination status, and periodic access review. High-risk privileged accounts may be subject to separate targeted testing.

Example 3: Vendor Compliance

An organization has 1,000 vendors. The auditor examines vendor onboarding records, contracts, risk assessments, security assessments, compliance certificates, approvals, and periodic reviews.

How to Do Audit Sampling in Excel

Step 1: Prepare the Population

Create a complete list of items available for selection.

Step 2: Assign a Unique Identifier

Every sampling unit should have a unique identifier (e.g., TX001, TX002).

Step 3: Add a Random Number

Use Excel’s =RAND() function to generate random values for sorting or selection.

Step 4: Record the Selected Sample

Maintain a separate record of population, sample size, selection methodology, selected items, testing status, exceptions, reviewer comments, and final conclusion.

Step 5: Preserve the Sampling Evidence

Do not rely only on a temporary Excel filter. The audit file should retain enough information to explain how and why the sample was selected.

Audit Sampling Documentation

An audit workpaper should generally make it possible for another reviewer to understand:

  • Audit objective
  • Population
  • Sampling unit
  • Sampling method
  • Sample size and rationale
  • Risk considerations
  • Testing procedure
  • Exceptions
  • Evaluation
  • Conclusion

Audit Sampling vs Audit Evidence

Sampling determines which items are tested. Audit evidence is the information obtained and evaluated during the audit. A sampling approach should be designed around the evidence required to address the audit objective.

Audit Sampling vs Data Analytics

Data analytics can sometimes support population-level testing or identify unusual transactions that warrant targeted audit procedures.

Aspect Audit Sampling Data Analytics
Examines Selected items Can analyze complete population
Sampling risk Exists Population-level analysis reduces limitations
Useful for Detailed testing Pattern and anomaly identification
Requires Sampling design Data quality and analytical logic

Audit Sampling Best Practices

1. Define the audit objective first
2. Define the population carefully
3. Don’t use arbitrary percentages
4. Consider risk and materiality
5. Use an appropriate selection method
6. Separate targeted testing from representative sampling
7. Record every exception
8. Preserve the sampling rationale
9. Evaluate results, not just individual items
10. Maintain an audit trail

Common Audit Sampling Mistakes

Using a fixed percentage for every audit
Selecting convenient items
Defining the population incorrectly
Selecting the sample after reviewing the results
Ignoring exceptions
Failing to document the rationale
Treating sample size as the entire methodology

Audit Sampling Software and Tools

Audit sampling software can help auditors define audit populations, select samples, apply sampling methodologies, record selected items, document testing, record exceptions, maintain review history, link evidence to testing, and track audit conclusions.

Audit Sampling Workflow

Define Audit Objective
Define Population
Identify Sampling Unit
Assess Risk & Materiality
Determine Sampling Approach
Determine Sample Size
Select Sample
Perform Audit Procedures
Record Exceptions
Evaluate Results
Document Conclusion

Audit Sampling Checklist

☐ Audit objective is clearly defined
☐ Population is identified
☐ Population is complete and relevant
☐ Sampling unit is defined
☐ Risk has been considered
☐ Expected deviations have been considered
☐ Sampling methodology is documented
☐ Sample size has a clear rationale
☐ Sample selection is documented
☐ Testing procedures are defined
☐ Exceptions are recorded
☐ Results are appropriately documented
☐ Final conclusion is supported
☐ Sampling records are retained

Frequently Asked Questions

What is audit sampling?

Audit sampling is the application of audit procedures to less than 100% of a population to provide a reasonable basis for drawing conclusions about that population.

Which SA deals with audit sampling?

SA 530, Audit Sampling, deals with audit sampling in the ICAI Standards on Auditing.

What are the main types of audit sampling?

The two broad approaches are: statistical sampling and non-statistical sampling.

What is sampling risk in audit?

Sampling risk is the possibility that the conclusion reached from the sample differs from the conclusion that would have been reached by testing the entire population.

Is audit sampling a test of details?

No. Audit sampling is a method of selecting items for testing. It can be used when performing both tests of controls and tests of details.

Final Takeaway

Audit sampling is not simply about deciding how many transactions to test. A defensible sampling process starts with the audit objective and moves through the population, risk, materiality, sampling approach, sample selection, testing, evaluation, and documentation.

The strongest sampling methodology answers five questions:

  1. What are we trying to determine?
  2. What population are we testing?
  3. Why did we select this sample?
  4. What did the testing show?
  5. What does the result mean for the population?

For organizations managing recurring audits, sampling becomes easier to govern when the population, selected items, evidence, exceptions, findings, and corrective actions remain connected throughout the audit lifecycle.

Ready to Streamline Your Audit Sampling Process?

Connect sampling with the broader audit lifecycle so that sample selection, evidence, exceptions, findings, and corrective actions remain traceable in one system.

Share