Sampling Techniques
Help Questions
CPA Auditing and Attestation (AUD) › Sampling Techniques
In an audit of a nonissuer wholesaler, you plan substantive sampling over vendor invoices to test occurrence of purchases. The population includes 14,000 invoices, but 35 invoices are individually significant and together comprise 48% of the total purchases balance. The team is deciding how to design the sampling approach for the remaining invoices. Which sampling method should the auditor use?
Select only the smallest invoices for testing because they are more numerous and therefore more representative
Exclude the 35 invoices from testing because sampling is intended to cover the entire population without focusing on large items
Test the 35 individually significant invoices 100% and apply either statistical or non-statistical sampling to the remaining population, ensuring the remaining items have a chance of selection
Use inquiry of accounts payable personnel instead of sampling because inquiry is sufficient for occurrence of purchases when controls appear strong
Explanation
AU-C 530 requires that when a population contains individually significant items, these should typically be tested 100% while sampling can be applied to the remaining population, ensuring all items have a chance of selection. The key facts are that 35 invoices are individually significant (48% of the balance) and the auditor needs to test occurrence of the remaining purchases. Answer A correctly prescribes testing all individually significant items and then applying appropriate sampling to the remainder. Answer B violates the principle of testing significant items, Answer C inappropriately biases selection toward small items, and Answer D incorrectly suggests inquiry alone is sufficient for a substantive assertion. The professional judgment framework is: stratify the population by separating individually significant items for 100% examination, then apply sampling techniques to the remaining population to achieve appropriate audit coverage.
You are performing an audit of a nonissuer manufacturer and plan to use sampling to test depreciation expense by examining additions to property, plant, and equipment (PP&E) for proper capitalization and start dates. The PP&E addition population is 420 items totaling $12.5 million, and the entity has inconsistent documentation for smaller tools and equipment. The auditor wants to reduce the risk of missing large misstatements while still covering the full population. Which sampling method should the auditor use?
Block selection of the last two months of additions because it is a representative period and easier to audit
Monetary-unit sampling for the PP&E additions because it provides higher selection probability for larger recorded amounts while still allowing selection across the population
Haphazard selection restricted to items under $5,000 because smaller items are more likely to be misstated
Select only items with missing documentation and ignore documented items because sampling should focus exclusively on exceptions
Explanation
AU-C 530 recognizes monetary-unit sampling (MUS) as particularly effective for substantive testing when the auditor wants higher selection probability for larger recorded amounts while maintaining coverage of the entire population. The key facts are that PP&E additions vary significantly in size, the auditor wants to reduce risk of missing large misstatements, and full population coverage is desired. Answer A correctly identifies MUS as the optimal method because it automatically gives larger items higher selection probability while still allowing any item to be selected. Answer B violates random selection principles and may not be representative, Answer C inappropriately biases selection toward small items contrary to the stated objective, and Answer D violates the fundamental principle that sampling requires selection from the defined population. The professional judgment framework is: when testing populations with high variability and concern about large misstatements, MUS provides optimal coverage by probability-weighting selection by recorded amount.
You are the auditor of a nonissuer manufacturing company in a financial statement audit. The entity has 18,000 sales invoices for the year, and controls over sales invoice approval are automated but the auditor noted prior-year deviations due to manual overrides. The engagement partner wants a sampling approach for testing the operating effectiveness of the invoice-approval control that allows quantification of sampling risk and supports projecting results to the population. Which sampling method should the auditor use?
Statistical attribute sampling because it permits quantifying sampling risk and evaluating deviations against a defined tolerable deviation rate
Non-statistical attribute sampling using haphazard selection because it is sufficient to support a quantified sampling risk conclusion
Judgmental selection of only the largest invoices because focusing on higher-dollar items reduces control testing sample size requirements
Non-statistical monetary-unit sampling because it is designed to test control deviations in binary form
Explanation
AU-C 530 requires that when an auditor needs to quantify sampling risk and project results to the population, statistical sampling methods must be used. The key facts are that the engagement partner specifically wants quantification of sampling risk and the ability to project results, which are hallmarks of statistical sampling. Statistical attribute sampling (Answer B) is the correct choice because it provides a mathematical basis for measuring sampling risk and allows the auditor to make quantitative statements about the population based on sample results. Non-statistical attribute sampling (Answer A) cannot provide quantified sampling risk conclusions, monetary-unit sampling (Answer C) is designed for substantive testing of monetary amounts rather than control deviations, and judgmental selection (Answer D) violates the fundamental sampling principle that all items must have a chance of selection. The professional judgment framework is: when quantification of sampling risk is required for controls testing, use statistical attribute sampling with proper random selection methods.
In the audit of a nonissuer e-commerce company, you performed a substantive sample of 80 refund transactions (population 6,400 refunds) to test authorization and accuracy. You found 1 refund processed without required approval and a separate $1,200 over-refund due to data entry error; the control environment is otherwise stable. What is the most appropriate way to evaluate misstatements based on sample results?
Offset the $1,200 over-refund against any under-refunds found in prior-year workpapers and conclude no misstatement exists in the current year
Treat the unapproved refund as a control deviation and the $1,200 over-refund as a misstatement, then consider whether each indicates a systemic issue requiring expanded procedures and whether projected misstatement could exceed tolerable misstatement
Conclude the population is fairly stated because the errors are immaterial individually and therefore cannot affect the financial statements
Disregard the unapproved refund because authorization relates only to compliance, not to financial statement assertions
Explanation
AU-C 530 requires separate evaluation of control deviations and monetary misstatements, with consideration of whether findings indicate systemic issues requiring expanded procedures. The key facts are that one control deviation (missing approval) and one monetary misstatement ($1,200 over-refund) were identified in different transactions. Answer A correctly requires treating these as separate issues - the control deviation for evaluating control effectiveness and the misstatement for projecting to the population and comparing to tolerable misstatement. Answer B inappropriately attempts to offset current year findings with prior year results, Answer C fails to project the identified misstatement to the population, and Answer D incorrectly dismisses the relevance of authorization controls to financial reporting. The professional judgment framework is: evaluate control deviations and monetary misstatements separately, project each type of finding appropriately, and consider whether the nature of errors indicates broader issues requiring additional audit procedures.
In the audit of a nonissuer software company, you plan substantive testing of accounts receivable existence using positive confirmations. The population is 1,200 customer balances totaling $8.4 million, with a few very large accounts and many small balances; prior-year confirmations had a moderate rate of nonresponses. What factors should the auditor consider in determining sample size?
Tolerable misstatement, expected misstatement, and assessed risk of material misstatement for accounts receivable
The auditor’s control risk assessment for payroll, because payroll controls affect the reliability of receivables confirmations
The number of days sales outstanding and the client’s credit policy, because these primarily determine confirmation sample size
Whether the client uses electronic invoicing, because electronic invoicing eliminates the need for confirmations and therefore sample size
Explanation
AU-C 530 specifies that sample size for substantive tests of details depends on tolerable misstatement, expected misstatement, and the assessed risk of material misstatement for the relevant assertion. The key facts are that this is substantive testing of accounts receivable existence through confirmations, with a population containing both large and small balances. Answer B correctly identifies the three primary factors required by auditing standards for substantive sampling. Answer A references operational metrics rather than audit risk factors, Answer C incorrectly suggests electronic invoicing eliminates confirmation requirements, and Answer D inappropriately links payroll controls to receivables confirmation sample size. The professional judgment framework for substantive sampling is: determine (1) the maximum misstatement you can accept, (2) the misstatement you expect to find, and (3) the risk assessment for the assertion being tested, then use these to calculate appropriate sample size.
You are auditing a nonissuer financial services company. For a test of controls over new vendor setup, you selected 50 vendor additions and found 2 instances where required independent approval was missing. The control is important to mitigating fraud risk, and the auditor’s tolerable deviation rate was set low. Based on the results, how should the auditor extrapolate the findings?
Evaluate the sample deviation rate in relation to the tolerable deviation rate, consider sampling risk, and determine whether reliance on the control remains appropriate or whether additional testing or a revised audit approach is needed
Project the 2 deviations as dollar misstatements to the financial statements and compare to overall materiality to determine control reliance
Ignore the deviations because fraud risks are addressed only through substantive procedures, not tests of controls
Conclude the control is effective because only 2 deviations were found and the sample size exceeded 30
Explanation
AU-C 530 requires that control test results be evaluated by comparing the sample deviation rate to the tolerable deviation rate while considering sampling risk, particularly when the control addresses fraud risks. The key facts are that 2 deviations were found in 50 items (4% deviation rate), the control is important for fraud prevention, and tolerable deviation rate was set low. Answer B correctly requires evaluation against tolerable rate with consideration of sampling risk and potential need for revised audit approach. Answer A fails to properly evaluate results against tolerable rate, Answer C incorrectly attempts to convert control deviations to dollar misstatements, and Answer D incorrectly claims controls testing is irrelevant to fraud risks. The professional judgment framework for evaluating control deviations is: calculate the sample deviation rate, consider sampling risk (especially for low tolerable rates), and determine whether planned reliance remains appropriate or whether the audit approach needs modification.
During the audit of a nonissuer construction contractor, you selected a non-statistical sample of 60 job cost transactions to test classification between cost of sales and capitalized costs. You identified 3 misclassifications totaling $18,000, and the population consists of 6,000 transactions totaling $9.0 million. What is the most appropriate way to evaluate misstatements based on sample results?
Project the sample misstatement to the population on a reasonable basis and consider sampling risk, then compare the result to tolerable misstatement for the relevant assertion
Assume the misstatement rate is zero for the untested items because the sample was not statistical and therefore cannot be used for evaluation
Request management to adjust only the $18,000 identified and conclude the population is fairly stated without further evaluation
Increase performance materiality to exceed the projected misstatement so that additional audit work is not necessary
Explanation
AU-C 530 requires that even when using non-statistical sampling, the auditor must project sample misstatements to the population and consider sampling risk when evaluating results against tolerable misstatement. The key facts are that non-statistical sampling was used, misstatements were identified (3 out of 60 items), and evaluation is needed. Answer B correctly requires projection of the sample misstatement rate to the population and consideration of sampling risk, which can be done judgmentally in non-statistical sampling. Answer A incorrectly suggests non-statistical samples cannot be evaluated, Answer C fails to project misstatements to the untested population, and Answer D inappropriately suggests manipulating audit thresholds to avoid addressing identified issues. The professional judgment framework is: non-statistical sampling still requires projection of sample results and consideration of sampling risk, though these are based on professional judgment rather than statistical calculation.
You are performing an audit of a nonissuer retailer and plan a test of controls over the three-way match (purchase order, receiving report, vendor invoice) for accounts payable. The population is 9,500 purchase transactions, and you expect a low deviation rate based on walkthroughs, but the control is key to reducing substantive testing. What factors should the auditor consider in determining sample size?
The population book value and the auditor’s expected misstatement in dollars, because control testing sample size is driven by monetary misstatement
Tolerable deviation rate, expected deviation rate, and the desired level of assurance (allowable sampling risk) for the control
Whether the population contains related-party transactions, because related parties automatically require a 100% test rather than sampling
Materiality for the financial statements, inherent risk for revenue, and the number of locations visited during interim work
Explanation
AU-C 530 establishes that sample size for tests of controls depends on three primary factors: tolerable deviation rate, expected deviation rate, and the desired level of assurance (allowable sampling risk). The key facts are that this is a test of controls over a three-way match, the auditor expects a low deviation rate, and the control is important for reducing substantive testing. Answer A correctly identifies all three factors required by professional standards for determining control test sample size. Answer B incorrectly references factors relevant to substantive testing rather than controls testing, Answer C confuses attribute sampling with variables sampling by focusing on monetary amounts, and Answer D incorrectly suggests related-party transactions require 100% testing for controls. The professional judgment framework is: for control testing sample size, always consider (1) how many deviations you can tolerate, (2) how many you expect to find, and (3) how confident you need to be in your conclusion.
You are auditing a nonissuer financial services company and using attribute sampling to test a control that requires dual authorization for wire transfers. In a sample of 50 wires, you find 1 deviation where only one authorization was documented; the tolerable deviation rate is 2% and expected deviation rate was 0%. What is the most appropriate way to evaluate misstatements based on sample results?
Project a dollar misstatement to the population based on the wire amount and compare it to tolerable misstatement
Conclude the control is effective because only one deviation occurred and it is below overall materiality
Evaluate whether the deviation rate, considering sampling risk, could exceed the tolerable deviation rate and determine whether reliance on the control remains appropriate
Ignore the deviation because documentation is not required if authorization was likely obtained
Explanation
AU-C 530 requires evaluating if sample deviation rate plus sampling risk exceeds tolerable in attribute sampling to assess reliance. The 1 deviation in 50 wires against 2% tolerable and 0% expected necessitates risk consideration for control effectiveness. This follows standards for projection and evaluation. Concluding effective or ignoring deviates from principles, and projecting dollars misapplies attribute method. Auditors consider risk in deviation assessments. A rule is to forgo reliance if upper deviation limit exceeds tolerable.
You are auditing a nonissuer nonprofit organization and testing controls over cash disbursement approvals. The control is performed weekly, and the auditor plans to rely on it to reduce substantive testing of expenses. What factors should the auditor consider in determining sample size for this test of controls?
Only the number of weeks in the year, because one item per week is required to test a weekly control
Only overall materiality, because control testing sample size is driven by financial statement magnitude
Only inherent risk, because sampling risk is irrelevant in tests of controls
Frequency of the control, expected deviation rate, tolerable deviation rate, and the risk of assessing control risk too low
Explanation
AU-C 530 identifies frequency, expected and tolerable deviation rates, and risk of assessing control risk too low as key for sample size in tests of controls. The weekly cash disbursement control requires reliance, so these factors determine sample size to ensure adequate evidence. This aligns with guidance for attribute sampling in recurring controls. Basing on weeks alone, materiality, or inherent risk only overlooks deviation and risk considerations. Auditors should scale samples to control frequency and risk for effective testing. A decision rule is to increase samples for frequent controls with higher planned reliance.