CPA AUDITING & ATTESTATION (AUD) • PERFORMING FURTHER PROCEDURES AND OBTAINING EVIDENCE

Sampling Techniques — Apply Audit Sampling Methods

How auditors draw defensible conclusions about entire populations by examining only a strategically selected subset of items.

Historical Context & Motivation

Auditing every single transaction in a company's ledger was once the gold standard of assurance work. In the era before digital record-keeping, a small proprietorship might generate only a few hundred entries per year, making a complete examination feasible. As industrialization expanded the scale of commerce in the late nineteenth and early twentieth centuries, however, the sheer volume of recorded transactions rendered 100-percent testing economically impractical for most engagements. Auditors needed a principled way to examine less than the full population while still issuing opinions that carried professional weight. Audit sampling emerged as the disciplined answer to that challenge, borrowing heavily from the statistical inference techniques that were simultaneously revolutionizing quality control in manufacturing and survey research in the social sciences.

1930s
Early Judgmental Sampling
Auditors begin selectively testing high-value or unusual items rather than examining every transaction. No formal framework governs sample sizes; professional judgment and experience are the primary guides.
1962
AICPA Introduces Statistical Sampling Guidance
The American Institute of CPAs publishes early guidance encouraging the use of statistical methods in auditing, legitimizing probability-based sampling as a professional practice.
1981
SAS No. 39 — Audit Sampling
Statement on Auditing Standards No. 39 formally distinguishes statistical from nonstatistical sampling and establishes that both approaches can provide sufficient appropriate audit evidence when properly designed.
2001–2012
Clarified Standards (AU-C 530)
The Auditing Standards Board adopts ISA 530 as part of the Clarity Project, codifying requirements for sample design, sample size determination, performance, and evaluation of results under AU-C Section 530.
2020s
Data Analytics and Hybrid Approaches
Advances in data analytics allow auditors to test entire populations for certain assertions, but sampling remains essential for substantive tests requiring human judgment—particularly when examining supporting documentation.

The central question audit sampling addresses is deceptively simple: How can an auditor test fewer than all items in a population yet still draw a reasonable conclusion about the population as a whole? Answering this question requires understanding both the statistical underpinnings and the professional standards that govern how samples are designed, executed, and evaluated in audit engagements.

Core Principles & Definitions

AU-C Section 530 defines audit sampling as the application of an audit procedure to less than 100 percent of items within a population of audit relevance, where all sampling units have a chance of being selected, so that the auditor has a reasonable basis for drawing conclusions about the entire population. The phrase "all sampling units have a chance of being selected" is critical—it distinguishes sampling from cherry-picking and from approaches that examine only specific items meeting certain criteria (such as all items above a threshold), which the standards classify as procedures applied to specific items rather than as audit sampling.

1

Sampling Risk

The risk that the auditor's conclusion based on a sample differs from the conclusion that would result from testing the entire population. It exists in both tests of controls (risk of over-reliance and under-reliance) and substantive tests (risk of incorrect acceptance and incorrect rejection).
2

Nonsampling Risk

The risk that the auditor reaches an erroneous conclusion for reasons unrelated to sampling—such as applying the wrong procedure, failing to recognize a deviation, or misinterpreting results. This risk can be mitigated through adequate training, supervision, and quality control.
3

Tolerable Rate / Tolerable Misstatement

The maximum rate of deviation (for tests of controls) or monetary misstatement (for substantive tests) the auditor is willing to accept in the population and still conclude that the audit objective has been achieved.
4

Expected Rate / Expected Misstatement

The auditor's estimate of the actual deviation rate or misstatement in the population based on prior-year results, walkthroughs, and professional judgment. Higher expected rates require larger sample sizes to maintain confidence.
5

Confidence Level

The complement of sampling risk. A 95% confidence level implies a 5% sampling risk—the probability that the sample conclusion differs from the population truth. Higher desired confidence requires larger samples.
KEY TAKEAWAY
Think of audit sampling like taste-testing a large pot of soup. If the soup has been thoroughly stirred (the population is well-defined), one well-chosen spoonful can tell you whether the whole pot needs more salt. The size of the spoonful (sample size) depends on how confident you want to be and how much seasoning variation you expect. If you always taste from only one corner, you face sampling risk—your spoonful may not represent the whole pot.

Visual Explanation — The Audit Sampling Framework

This flowchart illustrates the end-to-end audit sampling process. After defining the objective and population, the auditor selects either a statistical or nonstatistical approach. Statistical sampling enables quantitative measurement of sampling risk, while nonstatistical sampling relies on the auditor's professional judgment. Both paths converge at the evaluation stage, where results are projected to the population.

The diagram above captures the sequential logic that governs every sampling application in an audit. Notice that the framework begins with a clear articulation of the audit objective—whether the auditor is testing the operating effectiveness of a control or searching for monetary misstatements in an account balance. The population must then be defined to ensure it is complete and appropriate to the objective. For example, if the objective is to test whether sales invoices are supported by shipping documents, the population consists of all sales invoices for the period—not a subset of them. Regardless of whether a statistical or nonstatistical approach is chosen, the final step requires the auditor to project sample findings to the population and assess whether the results, including an allowance for sampling risk, support the planned audit conclusion.

Mathematical Framework — Sample Size Determination

Although nonstatistical sampling relies on professional judgment rather than formulas, statistical sampling demands formal computation of sample sizes. Two primary models dominate practice: attribute sampling for tests of controls and variables sampling (including monetary-unit sampling) for substantive tests of details. Understanding the key inputs and their directional effects on sample size is essential for CPA candidates.

Attribute Sampling — Tests of Controls

ATTRIBUTE SAMPLE SIZE (SIMPLIFIED)
n = (R × (1 − p)) / (TDR − EDR)²
Where n = sample size, R = reliability factor (derived from the confidence level; e.g., R ≈ 3.0 for 95% confidence with zero expected deviations), p = expected population deviation rate, TDR = tolerable deviation rate, EDR = expected deviation rate. In practice, auditors typically use AICPA sample-size tables rather than computing this formula directly.

Monetary-Unit Sampling (MUS) — Substantive Tests

MUS SAMPLE SIZE
n = (BV × RF) / TM
Where n = sample size, BV = recorded book value of the population, RF = reliability factor for the desired confidence level (e.g., 3.0 at 95% confidence with zero expected misstatements), TM = tolerable misstatement. The sampling interval (SI) equals BV / n, and every nth dollar in the cumulative population triggers selection of the transaction containing it.

Directional Effects on Sample Size

Key factors affecting sample size in both attribute and variables sampling
FactorChange in FactorEffect on Sample Size
Tolerable deviation rate / Tolerable misstatementIncrease ↑Decrease ↓
Expected deviation rate / Expected misstatementIncrease ↑Increase ↑
Desired confidence level (1 − Sampling risk)Increase ↑Increase ↑
Population size (when large)Increase ↑Little or no effect (for large populations)
Population variability (std. deviation)Increase ↑Increase ↑
💡 CPA Exam Tip
The CPA exam frequently tests your understanding of the inverse relationship between tolerable deviation rate (or tolerable misstatement) and sample size. Remember: the more error you are willing to tolerate, the fewer items you need to test to confirm the population falls within that tolerance.

Detailed Breakdown of Sampling Methods

Audit sampling methods fall into two broad categories: statistical sampling and nonstatistical sampling. Statistical sampling requires random selection and probability-based evaluation; nonstatistical sampling uses professional judgment for both selection and evaluation. Within statistical sampling, the primary selection techniques include simple random sampling, systematic sampling, and probability-proportional-to-size (PPS) sampling, while nonstatistical selection methods include haphazard sampling and block sampling.

This taxonomy diagram classifies the major audit sampling methods. Under statistical sampling, simple random, systematic, and PPS/MUS are the primary selection techniques. Under nonstatistical sampling, haphazard and block selection are used. The bottom section maps each method to its typical test type: attribute sampling for controls and variables/MUS for substantive tests.

Selection Method Details

Comparison of audit sampling selection methods
MethodHow It WorksBest Used ForKey Consideration
Simple RandomAssign numbers to all items; use a random number generator or table to select.Homogeneous populations; attribute testingRequires a complete, numbered sampling frame.
SystematicCalculate interval k = N / n; pick a random start between 1 and k; select every kth item.Large populations with items in no predictable patternBeware of systematic patterns in the population that align with the interval.
PPS / MUSEach dollar in the population is a sampling unit; items with higher recorded values have a proportionally higher chance of selection.Substantive testing of account balances, especially for overstatementAutomatically stratifies; items ≥ sampling interval are guaranteed selection. Less effective for understatements.
HaphazardSelect items without a structured technique, attempting to give all items an opportunity for selection.Nonstatistical sampling when random selection is impracticalAuditor must consciously avoid bias (e.g., favoring items on top of a file).
BlockSelect contiguous sequences (e.g., all transactions in March and September).Rarely used as the sole selection methodHigh risk of nonrepresentativeness unless multiple blocks from different periods are selected.

Worked Example — Monetary-Unit Sampling Application

Suppose you are auditing the accounts receivable balance of Greenfield Manufacturing, Inc. The recorded book value of accounts receivable is $5,000,000. Management has assessed the risk of material misstatement as moderate. You plan to use monetary-unit sampling at a 95% confidence level, tolerable misstatement of $250,000, and an expected misstatement of $0 (i.e., you expect no misstatements based on prior-year results). Walk through the following steps to determine sample size, select items, and evaluate findings.

MUS Application — Greenfield Manufacturing A/R
1
Step 1 — Determine the Reliability FactorAt a 95% confidence level with zero expected misstatements, the reliability factor (RF) from the Poisson-based AICPA table is 3.00. This factor represents the natural logarithm-based coefficient for a 5% risk of incorrect acceptance.
RF = 3.00
2
Step 2 — Compute the Sample SizeApply the MUS formula: n = (BV × RF) / TM = ($5,000,000 × 3.00) / $250,000 = $15,000,000 / $250,000 = 60 sampling units.
n = 60 items
3
Step 3 — Determine the Sampling IntervalThe sampling interval (SI) = BV / n = $5,000,000 / 60 = $83,333. Alternatively, SI = TM / RF = $250,000 / 3.00 = $83,333. Any individual customer balance ≥ $83,333 is automatically selected (these are called "top-stratum" or "individually significant" items in PPS sampling).
Sampling Interval = $83,333
4
Step 4 — Select the SampleGenerate a random start between $1 and $83,333—suppose it is $47,219. Arrange all customer balances in a cumulative dollar listing. The first item selected is the transaction whose cumulative dollars include the $47,219th dollar. The next selected item contains the ($47,219 + $83,333) = $130,552nd cumulative dollar, and so on, until 60 items are selected.
5
Step 5 — Execute Procedures and Evaluate ResultsAssume testing reveals one misstatement: a customer balance recorded at $12,000 has an audited value of $9,000, yielding a tainting percentage of ($12,000 − $9,000) / $12,000 = 25%. The projected misstatement for that sampling interval is 25% × $83,333 = $20,833. Adding the basic precision (RF × SI for zero misstatements = 3.00 × $83,333 = $250,000) and the incremental allowance for the discovered misstatement, the upper limit of misstatement (ULM) exceeds the basic precision. If the ULM remains below tolerable misstatement (after adjusting for the incremental allowance), the auditor may conclude the balance is not materially misstated.
Projected misstatement = $20,833; compare ULM to TM of $250,000

Statistical vs. Nonstatistical Sampling — Strengths & Limitations

A perennial source of confusion among CPA candidates is whether one sampling approach is "better" than the other. AU-C 530 explicitly states that both statistical and nonstatistical sampling, when properly designed and executed, can provide sufficient appropriate audit evidence. The choice depends on the engagement circumstances, the auditor's skill set, and the nature of the population being tested. The following comparison highlights the trade-offs.

Side-by-side comparison of statistical and nonstatistical audit sampling
DimensionStatistical SamplingNonstatistical Sampling
Selection methodMust use random selection (random number generator, systematic with random start, PPS)May use haphazard, block, or judgmental selection
Measurement of sampling riskQuantifiable — provides a computed confidence level and precision intervalNot quantifiable — auditor must judgmentally assess whether sampling risk is acceptably low
DefensibilityEasier to defend in litigation or regulatory review due to mathematical basisMore susceptible to challenge, though acceptable under GAAS
Expertise requiredHigher — requires knowledge of probability theory and statistical evaluation techniquesLower — relies on the auditor's professional experience and understanding of the entity
Cost / EfficiencyMay require software tools; sample sizes can be larger for very low tolerable ratesGenerally simpler to administer; auditor can use judgment to constrain the sample
Projection of resultsResults can be projected mathematically, with a computed allowance for sampling riskResults must still be projected to the population, but the allowance for sampling risk is judgmental
KEY TAKEAWAY
Imagine two engineers inspecting a bridge. One uses strain gauges and load calculators to quantify the probability of structural failure; the other walks the span, taps the girders, and uses decades of field experience to form a judgment. Both can reach a valid conclusion about the bridge's safety—but the first can express the remaining risk as a number. In auditing, statistical sampling is the strain gauge, and nonstatistical sampling is the experienced walkthrough. Neither is inherently superior; both require competence and professional skepticism.

Connection to Advanced Theory — Stratification, Dual-Purpose Testing & Data Analytics

As audit engagements grow in complexity, sampling techniques evolve to handle heterogeneous populations and multifaceted test objectives. Three advanced topics regularly appear on the CPA exam and in modern practice: stratification, dual-purpose testing, and the emerging intersection of data analytics with sampling.

Basic vs. Advanced sampling concepts
ConceptBasic Sampling ApplicationAdvanced Extension
Population treatmentTest the entire population as one group using a single sample.Stratify the population into sub-groups (e.g., by dollar value) and sample each stratum separately, reducing variability and potentially reducing overall sample size.
Test purposeSingle-purpose: test controls OR test details, but not both.Dual-purpose testing: simultaneously test operating effectiveness of a control and perform a substantive test on the same item. The sample size must be the larger of what each individual test would require.
Evidence evaluationEvaluate sample results manually, project to population, compare to tolerable threshold.Use data analytics to test 100% of the population for certain characteristics (e.g., three-way match), then apply sampling only to exceptions or high-risk items identified by the analytics, creating a hybrid approach.
Misstatement projectionPoint estimate projection (sample misstatement rate × population).Ratio or difference estimation: use the relationship between audited and book values in the sample to project total population misstatement more precisely, particularly effective when misstatement sizes correlate with item values.

Looking ahead, the integration of machine learning and continuous auditing platforms is reshaping how sampling interacts with technology. While the fundamental principles of AU-C 530 remain stable, the profession is actively debating how to integrate full-population testing via analytics into the sampling framework without losing the conceptual rigor that probability theory provides. For CPA candidates, mastering the current framework—including stratification, dual-purpose testing, and classical projection methods—provides the intellectual foundation necessary to adapt to these evolving practices.

Practice Problems

PROBLEM 1CONCEPTUAL
An auditor selects all purchase orders above $50,000 for testing, plus a random sample of purchase orders below $50,000. Is the testing of items above $50,000 considered "audit sampling" under AU-C 530? Explain your reasoning.
PROBLEM 2BASIC CALCULATION
An auditor is performing monetary-unit sampling on an inventory balance of $8,400,000. The tolerable misstatement is $420,000, and the reliability factor at the desired confidence level with zero expected misstatements is 2.30. What is the required sample size and the sampling interval?
PROBLEM 3INTERMEDIATE
An auditor is testing the operating effectiveness of a control over cash disbursements. Last year, the deviation rate was 1.5%. This year, the auditor sets tolerable deviation rate at 7%, expected deviation rate at 2%, and desires 95% confidence. Using the AICPA attribute sampling table, the required sample size is 88. During testing, the auditor finds 4 deviations. (a) Calculate the sample deviation rate. (b) Explain how the auditor should evaluate whether the control can be relied upon.
PROBLEM 4APPLIED
RiverTech Solutions has 12,000 accounts receivable confirmation items with a total book value of $24,000,000. The auditor decides to stratify the population into three strata: Stratum A (balances ≥ $10,000, 300 items, total $9,000,000), Stratum B (balances $2,000–$9,999, 2,700 items, total $10,800,000), and Stratum C (balances < $2,000, 9,000 items, total $4,200,000). The auditor plans to confirm all items in Stratum A and sample from Strata B and C. Explain the rationale for this stratification strategy and identify the portion that constitutes audit sampling.
PROBLEM 5CRITICAL THINKING
A colleague argues that with modern data analytics tools capable of testing 100% of transactions for anomalies, traditional audit sampling is obsolete. Critically evaluate this position. Under what circumstances might sampling remain necessary even when full-population analytics are available? Reference the distinction between sampling and nonsampling risk in your analysis.

Lesson Summary

Audit sampling, governed by AU-C Section 530, enables auditors to draw conclusions about an entire population by testing a strategically selected subset. The two overarching approaches—statistical sampling and nonstatistical sampling—both yield sufficient appropriate evidence when properly designed. Key inputs to sample size include tolerable deviation rate or tolerable misstatement (inversely related to sample size), expected deviation rate or expected misstatement (directly related), and the desired confidence level (directly related). Attribute sampling applies to tests of controls, while variables sampling and monetary-unit sampling (MUS) serve substantive tests of details.

Regardless of the approach chosen, the auditor must define the population to ensure completeness and appropriateness, select items in a manner that gives every sampling unit a chance of inclusion, perform the planned procedure on each selected item, and project the results to the population with an appropriate allowance for sampling risk. Advanced techniques such as stratification, dual-purpose testing, and integration with data analytics extend the framework's practical reach while preserving the conceptual discipline that sampling theory demands.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Sampling Techniques — Apply Audit Sampling Methods