CPA Quiz: Sampling Techniques
20 questions · exam conditions
0:00
Sampling TechniquesQuestion 1 of 20

In an audit of a nonissuer wholesaler, you plan substantive sampling over vendor invoices to test occurrence of purchases. The population includes 14,000 invoices, but 35 invoices are individually significant and together comprise 48% of the total purchases balance. The team is deciding how to design the sampling approach for the remaining invoices. Which sampling method should the auditor use?

Test the 35 individually significant invoices 100% and apply either statistical or non-statistical sampling to the remaining population, ensuring the remaining items have a chance of selection
Exclude the 35 invoices from testing because sampling is intended to cover the entire population without focusing on large items
Select only the smallest invoices for testing because they are more numerous and therefore more representative
Use inquiry of accounts payable personnel instead of sampling because inquiry is sufficient for occurrence of purchases when controls appear strong
← Back to quizzes

CPA Quiz

CPA Quiz: Sampling Techniques

Practice Sampling Techniques in CPA with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Sampling Techniques, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

In an audit of a nonissuer wholesaler, you plan substantive sampling over vendor invoices to test occurrence of purchases. The population includes 14,000 invoices, but 35 invoices are individually significant and together comprise 48% of the total purchases balance. The team is deciding how to design the sampling approach for the remaining invoices. Which sampling method should the auditor use?

  1. Test the 35 individually significant invoices 100% and apply either statistical or non-statistical sampling to the remaining population, ensuring the remaining items have a chance of selection (correct answer)
  2. Exclude the 35 invoices from testing because sampling is intended to cover the entire population without focusing on large items
  3. Select only the smallest invoices for testing because they are more numerous and therefore more representative
  4. Use inquiry of accounts payable personnel instead of sampling because inquiry is sufficient for occurrence of purchases when controls appear strong
Explanation: AU-C 530 requires that when a population contains individually significant items, these should typically be tested 100% while sampling can be applied to the remaining population, ensuring all items have a chance of selection. The key facts are that 35 invoices are individually significant (48% of the balance) and the auditor needs to test occurrence of the remaining purchases. Answer A correctly prescribes testing all individually significant items and then applying appropriate sampling to the remainder. Answer B violates the principle of testing significant items, Answer C inappropriately biases selection toward small items, and Answer D incorrectly suggests inquiry alone is sufficient for a substantive assertion. The professional judgment framework is: stratify the population by separating individually significant items for 100% examination, then apply sampling techniques to the remaining population to achieve appropriate audit coverage.

Question 2

You are performing an audit of a nonissuer manufacturer and plan to use sampling to test depreciation expense by examining additions to property, plant, and equipment (PP&E) for proper capitalization and start dates. The PP&E addition population is 420 items totaling $12.5 million, and the entity has inconsistent documentation for smaller tools and equipment. The auditor wants to reduce the risk of missing large misstatements while still covering the full population. Which sampling method should the auditor use?

  1. Monetary-unit sampling for the PP&E additions because it provides higher selection probability for larger recorded amounts while still allowing selection across the population (correct answer)
  2. Block selection of the last two months of additions because it is a representative period and easier to audit
  3. Haphazard selection restricted to items under $5,000 because smaller items are more likely to be misstated
  4. Select only items with missing documentation and ignore documented items because sampling should focus exclusively on exceptions
Explanation: AU-C 530 recognizes monetary-unit sampling (MUS) as particularly effective for substantive testing when the auditor wants higher selection probability for larger recorded amounts while maintaining coverage of the entire population. The key facts are that PP&E additions vary significantly in size, the auditor wants to reduce risk of missing large misstatements, and full population coverage is desired. Answer A correctly identifies MUS as the optimal method because it automatically gives larger items higher selection probability while still allowing any item to be selected. Answer B violates random selection principles and may not be representative, Answer C inappropriately biases selection toward small items contrary to the stated objective, and Answer D violates the fundamental principle that sampling requires selection from the defined population. The professional judgment framework is: when testing populations with high variability and concern about large misstatements, MUS provides optimal coverage by probability-weighting selection by recorded amount.

Question 3

You are the auditor of a nonissuer manufacturing company in a financial statement audit. The entity has 18,000 sales invoices for the year, and controls over sales invoice approval are automated but the auditor noted prior-year deviations due to manual overrides. The engagement partner wants a sampling approach for testing the operating effectiveness of the invoice-approval control that allows quantification of sampling risk and supports projecting results to the population. Which sampling method should the auditor use?

  1. Non-statistical attribute sampling using haphazard selection because it is sufficient to support a quantified sampling risk conclusion
  2. Statistical attribute sampling because it permits quantifying sampling risk and evaluating deviations against a defined tolerable deviation rate (correct answer)
  3. Non-statistical monetary-unit sampling because it is designed to test control deviations in binary form
  4. Judgmental selection of only the largest invoices because focusing on higher-dollar items reduces control testing sample size requirements
Explanation: AU-C 530 requires that when an auditor needs to quantify sampling risk and project results to the population, statistical sampling methods must be used. The key facts are that the engagement partner specifically wants quantification of sampling risk and the ability to project results, which are hallmarks of statistical sampling. Statistical attribute sampling (Answer B) is the correct choice because it provides a mathematical basis for measuring sampling risk and allows the auditor to make quantitative statements about the population based on sample results. Non-statistical attribute sampling (Answer A) cannot provide quantified sampling risk conclusions, monetary-unit sampling (Answer C) is designed for substantive testing of monetary amounts rather than control deviations, and judgmental selection (Answer D) violates the fundamental sampling principle that all items must have a chance of selection. The professional judgment framework is: when quantification of sampling risk is required for controls testing, use statistical attribute sampling with proper random selection methods.

Question 4

In the audit of a nonissuer e-commerce company, you performed a substantive sample of 80 refund transactions (population 6,400 refunds) to test authorization and accuracy. You found 1 refund processed without required approval and a separate $1,200 over-refund due to data entry error; the control environment is otherwise stable. What is the most appropriate way to evaluate misstatements based on sample results?

  1. Treat the unapproved refund as a control deviation and the $1,200 over-refund as a misstatement, then consider whether each indicates a systemic issue requiring expanded procedures and whether projected misstatement could exceed tolerable misstatement (correct answer)
  2. Offset the $1,200 over-refund against any under-refunds found in prior-year workpapers and conclude no misstatement exists in the current year
  3. Conclude the population is fairly stated because the errors are immaterial individually and therefore cannot affect the financial statements
  4. Disregard the unapproved refund because authorization relates only to compliance, not to financial statement assertions
Explanation: AU-C 530 requires separate evaluation of control deviations and monetary misstatements, with consideration of whether findings indicate systemic issues requiring expanded procedures. The key facts are that one control deviation (missing approval) and one monetary misstatement ($1,200 over-refund) were identified in different transactions. Answer A correctly requires treating these as separate issues - the control deviation for evaluating control effectiveness and the misstatement for projecting to the population and comparing to tolerable misstatement. Answer B inappropriately attempts to offset current year findings with prior year results, Answer C fails to project the identified misstatement to the population, and Answer D incorrectly dismisses the relevance of authorization controls to financial reporting. The professional judgment framework is: evaluate control deviations and monetary misstatements separately, project each type of finding appropriately, and consider whether the nature of errors indicates broader issues requiring additional audit procedures.

Question 5

In the audit of a nonissuer software company, you plan substantive testing of accounts receivable existence using positive confirmations. The population is 1,200 customer balances totaling $8.4 million, with a few very large accounts and many small balances; prior-year confirmations had a moderate rate of nonresponses. What factors should the auditor consider in determining sample size?

  1. The number of days sales outstanding and the client's credit policy, because these primarily determine confirmation sample size
  2. Tolerable misstatement, expected misstatement, and assessed risk of material misstatement for accounts receivable (correct answer)
  3. Whether the client uses electronic invoicing, because electronic invoicing eliminates the need for confirmations and therefore sample size
  4. The auditor's control risk assessment for payroll, because payroll controls affect the reliability of receivables confirmations
Explanation: AU-C 530 specifies that sample size for substantive tests of details depends on tolerable misstatement, expected misstatement, and the assessed risk of material misstatement for the relevant assertion. The key facts are that this is substantive testing of accounts receivable existence through confirmations, with a population containing both large and small balances. Answer B correctly identifies the three primary factors required by auditing standards for substantive sampling. Answer A references operational metrics rather than audit risk factors, Answer C incorrectly suggests electronic invoicing eliminates confirmation requirements, and Answer D inappropriately links payroll controls to receivables confirmation sample size. The professional judgment framework for substantive sampling is: determine (1) the maximum misstatement you can accept, (2) the misstatement you expect to find, and (3) the risk assessment for the assertion being tested, then use these to calculate appropriate sample size.

Question 6

You are auditing a nonissuer financial services company. For a test of controls over new vendor setup, you selected 50 vendor additions and found 2 instances where required independent approval was missing. The control is important to mitigating fraud risk, and the auditor's tolerable deviation rate was set low. Based on the results, how should the auditor extrapolate the findings?

  1. Conclude the control is effective because only 2 deviations were found and the sample size exceeded 30
  2. Evaluate the sample deviation rate in relation to the tolerable deviation rate, consider sampling risk, and determine whether reliance on the control remains appropriate or whether additional testing or a revised audit approach is needed (correct answer)
  3. Project the 2 deviations as dollar misstatements to the financial statements and compare to overall materiality to determine control reliance
  4. Ignore the deviations because fraud risks are addressed only through substantive procedures, not tests of controls
Explanation: AU-C 530 requires that control test results be evaluated by comparing the sample deviation rate to the tolerable deviation rate while considering sampling risk, particularly when the control addresses fraud risks. The key facts are that 2 deviations were found in 50 items (4% deviation rate), the control is important for fraud prevention, and tolerable deviation rate was set low. Answer B correctly requires evaluation against tolerable rate with consideration of sampling risk and potential need for revised audit approach. Answer A fails to properly evaluate results against tolerable rate, Answer C incorrectly attempts to convert control deviations to dollar misstatements, and Answer D incorrectly claims controls testing is irrelevant to fraud risks. The professional judgment framework for evaluating control deviations is: calculate the sample deviation rate, consider sampling risk (especially for low tolerable rates), and determine whether planned reliance remains appropriate or whether the audit approach needs modification.

Question 7

During the audit of a nonissuer construction contractor, you selected a non-statistical sample of 60 job cost transactions to test classification between cost of sales and capitalized costs. You identified 3 misclassifications totaling $18,000, and the population consists of 6,000 transactions totaling $9.0 million. What is the most appropriate way to evaluate misstatements based on sample results?

  1. Assume the misstatement rate is zero for the untested items because the sample was not statistical and therefore cannot be used for evaluation
  2. Project the sample misstatement to the population on a reasonable basis and consider sampling risk, then compare the result to tolerable misstatement for the relevant assertion (correct answer)
  3. Request management to adjust only the $18,000 identified and conclude the population is fairly stated without further evaluation
  4. Increase performance materiality to exceed the projected misstatement so that additional audit work is not necessary
Explanation: AU-C 530 requires that even when using non-statistical sampling, the auditor must project sample misstatements to the population and consider sampling risk when evaluating results against tolerable misstatement. The key facts are that non-statistical sampling was used, misstatements were identified (3 out of 60 items), and evaluation is needed. Answer B correctly requires projection of the sample misstatement rate to the population and consideration of sampling risk, which can be done judgmentally in non-statistical sampling. Answer A incorrectly suggests non-statistical samples cannot be evaluated, Answer C fails to project misstatements to the untested population, and Answer D inappropriately suggests manipulating audit thresholds to avoid addressing identified issues. The professional judgment framework is: non-statistical sampling still requires projection of sample results and consideration of sampling risk, though these are based on professional judgment rather than statistical calculation.

Question 8

You are performing an audit of a nonissuer retailer and plan a test of controls over the three-way match (purchase order, receiving report, vendor invoice) for accounts payable. The population is 9,500 purchase transactions, and you expect a low deviation rate based on walkthroughs, but the control is key to reducing substantive testing. What factors should the auditor consider in determining sample size?

  1. Tolerable deviation rate, expected deviation rate, and the desired level of assurance (allowable sampling risk) for the control (correct answer)
  2. Materiality for the financial statements, inherent risk for revenue, and the number of locations visited during interim work
  3. The population book value and the auditor's expected misstatement in dollars, because control testing sample size is driven by monetary misstatement
  4. Whether the population contains related-party transactions, because related parties automatically require a 100% test rather than sampling
Explanation: AU-C 530 establishes that sample size for tests of controls depends on three primary factors: tolerable deviation rate, expected deviation rate, and the desired level of assurance (allowable sampling risk). The key facts are that this is a test of controls over a three-way match, the auditor expects a low deviation rate, and the control is important for reducing substantive testing. Answer A correctly identifies all three factors required by professional standards for determining control test sample size. Answer B incorrectly references factors relevant to substantive testing rather than controls testing, Answer C confuses attribute sampling with variables sampling by focusing on monetary amounts, and Answer D incorrectly suggests related-party transactions require 100% testing for controls. The professional judgment framework is: for control testing sample size, always consider (1) how many deviations you can tolerate, (2) how many you expect to find, and (3) how confident you need to be in your conclusion.

Question 9

You are auditing a nonissuer financial services company and using attribute sampling to test a control that requires dual authorization for wire transfers. In a sample of 50 wires, you find 1 deviation where only one authorization was documented; the tolerable deviation rate is 2% and expected deviation rate was 0%. What is the most appropriate way to evaluate misstatements based on sample results?

  1. Evaluate whether the deviation rate, considering sampling risk, could exceed the tolerable deviation rate and determine whether reliance on the control remains appropriate (correct answer)
  2. Conclude the control is effective because only one deviation occurred and it is below overall materiality
  3. Ignore the deviation because documentation is not required if authorization was likely obtained
  4. Project a dollar misstatement to the population based on the wire amount and compare it to tolerable misstatement
Explanation: AU-C 530 requires evaluating if sample deviation rate plus sampling risk exceeds tolerable in attribute sampling to assess reliance. The 1 deviation in 50 wires against 2% tolerable and 0% expected necessitates risk consideration for control effectiveness. This follows standards for projection and evaluation. Concluding effective or ignoring deviates from principles, and projecting dollars misapplies attribute method. Auditors consider risk in deviation assessments. A rule is to forgo reliance if upper deviation limit exceeds tolerable.

Question 10

You are auditing a nonissuer nonprofit organization and testing controls over cash disbursement approvals. The control is performed weekly, and the auditor plans to rely on it to reduce substantive testing of expenses. What factors should the auditor consider in determining sample size for this test of controls?

  1. Frequency of the control, expected deviation rate, tolerable deviation rate, and the risk of assessing control risk too low (correct answer)
  2. Only the number of weeks in the year, because one item per week is required to test a weekly control
  3. Only overall materiality, because control testing sample size is driven by financial statement magnitude
  4. Only inherent risk, because sampling risk is irrelevant in tests of controls
Explanation: AU-C 530 identifies frequency, expected and tolerable deviation rates, and risk of assessing control risk too low as key for sample size in tests of controls. The weekly cash disbursement control requires reliance, so these factors determine sample size to ensure adequate evidence. This aligns with guidance for attribute sampling in recurring controls. Basing on weeks alone, materiality, or inherent risk only overlooks deviation and risk considerations. Auditors should scale samples to control frequency and risk for effective testing. A decision rule is to increase samples for frequent controls with higher planned reliance.

Question 11

In an audit of a nonissuer retailer, the auditor plans a test of controls over the review and approval of manual sales returns. The population consists of 2,400 return transactions, and the auditor expects a low deviation rate based on prior-year results, but assessed control risk is moderately high because returns are processed at multiple locations. What factors should the auditor consider in determining sample size for this test of controls?

  1. Tolerable deviation rate, expected deviation rate, and the desired level of assurance (risk of assessing control risk too low) (correct answer)
  2. Materiality for the financial statements, inherent risk only, and the size of the population as the primary driver
  3. Planned detection risk for substantive procedures only, because sample size for controls is unrelated to reliance
  4. Whether the auditor intends to use dual-purpose tests, because sample size is otherwise fixed by standards
Explanation: AU-C 530 outlines factors for determining sample size in tests of controls, including tolerable deviation rate, expected deviation rate, and the risk of assessing control risk too low. Here, the auditor is testing controls over sales returns in a population of 2,400 transactions with expected low deviations but moderately high control risk due to multiple locations. The correct factors align with guidance as they directly influence sample size to achieve the desired assurance level. Materiality and inherent risk alone are incorrect as they do not drive control testing sample size, and planned detection risk relates to substantive procedures, not controls. Dual-purpose tests do not fix sample size by standards but may require larger samples. Auditors should adjust sample size based on risk assessments and expected deviations to ensure reliable conclusions. A professional judgment framework is to prioritize tolerable and expected rates with assurance needs for efficient testing.

Question 12

In a nonissuer audit, the auditor plans a test of controls over credit memo approval. The auditor sets a low tolerable deviation rate because revenue is a significant account and the control is key; however, the auditor expects a higher deviation rate due to decentralized processing. What factors should the auditor consider in determining sample size for this test of controls?

  1. A lower tolerable deviation rate and higher expected deviation rate generally increase the required sample size (correct answer)
  2. A lower tolerable deviation rate generally decreases the sample size because fewer deviations are allowed
  3. Expected deviation rate does not affect sample size because deviations are evaluated only after testing
  4. Sample size should be based primarily on population size because decentralization affects only selection method, not sample size
Explanation: AU-C 530 states that lower tolerable deviation rates and higher expected rates increase sample size in controls testing. Low tolerable for key revenue control and higher expected from decentralization drive larger samples. This aligns with attribute sampling guidance. Lower tolerable does not decrease size, expected rate does affect planning, and population drives minimally. Auditors adjust for risk factors. A framework is to scale size inversely with tolerable and directly with expected.

Question 13

In a probability-proportional-to-size (PPS) sample with a sampling interval of $20,000, an auditor selected a customer account with a recorded balance of $5,000. The auditor determined the correct audited value of the account was $4,000. What is the projected misstatement for this sampling unit?

  1. $1,000
  2. $4,000 (correct answer)
  3. $5,000
  4. $20,000
Explanation: When the book value of a selected item (5,000)islessthanthesamplinginterval(5,000) is less than the sampling interval (20,000), the projected misstatement is calculated using a tainting factor. The misstatement is $5,000 - $4,000 = $1,000. The tainting factor is the misstatement divided by the book value: $1,000 / $5,000 = 0.20 or 20%. The projected misstatement is the tainting factor multiplied by the sampling interval: 0.20 * $20,000 = $4,000.

Question 14

An auditor plans to use a single sample to perform both a test of controls and a substantive test of details. When designing the sample for this dual-purpose test, the auditor's primary consideration should be that:

  1. The sample size should be the larger of the samples that would otherwise be designed for the two separate purposes. (correct answer)
  2. The test can only be used if the control activities are determined to be effective.
  3. The population must be stratified by monetary value before the sample is selected.
  4. The tolerable deviation rate for the test of controls is set equal to the tolerable misstatement for the substantive test.
Explanation: For a dual-purpose test to be appropriate, the sample must be designed to meet the objectives of both the test of controls and the substantive test. This requires calculating the sample size needed for each test individually based on their respective parameters (e.g., tolerable deviation rate for controls, tolerable misstatement for substantive tests). The auditor must then use the larger of the two calculated sample sizes to ensure the sample is sufficient for both purposes.

Question 15

An auditor used a statistical sampling plan to test a population of 5,000 sales invoices for proper credit approval. A sample of 100 invoices was selected, and three were found without proper approval. The auditor's tolerable deviation rate is 4%. What is the auditor's next required step?

  1. Conclude that the control is ineffective because the sample deviation rate (3%) is close to the tolerable rate (4%).
  2. Calculate the upper deviation rate and compare it to the tolerable deviation rate. (correct answer)
  3. Select another sample of 100 invoices to confirm the initial findings.
  4. Project the number of deviations to the entire population (150) and record it as a control deficiency.
Explanation: In statistical attribute sampling, the sample deviation rate (3/100 = 3%) alone is not sufficient for making a conclusion. The auditor must calculate the upper deviation rate, which adds an allowance for sampling risk to the sample deviation rate. The auditor then compares this upper deviation rate to the predetermined tolerable deviation rate to conclude on the effectiveness of the control.

Question 16

An auditor is planning to audit a client's accounts payable balance. The primary audit objective is to test for understatement (completeness), and the population contains a large number of vendors, many with zero or small balances. Which sampling technique would be least effective for this objective?

  1. Selecting a sample of subsequent cash disbursements to vouch to supporting documents.
  2. Probability-proportional-to-size (PPS) sampling. (correct answer)
  3. Classical variables sampling applied to a list of all vendors.
  4. Selecting a sample of vendors with zero balances for confirmation.
Explanation: Probability-proportional-to-size (PPS) sampling selects individual dollars as sampling units. This method is highly effective for detecting overstatements but is ineffective for detecting understatements, particularly for items with zero or small balances, as they have little to no chance of being selected. The other procedures are all appropriate for testing the completeness of accounts payable.

Question 17

In designing a sample for a test of controls using attribute sampling, what is the relationship between the expected population deviation rate, the tolerable deviation rate, and the required sample size?

  1. An increase in the expected rate has a direct effect on sample size, while an increase in the tolerable rate also has a direct effect.
  2. An increase in the expected rate has an inverse effect on sample size, while an increase in the tolerable rate has a direct effect.
  3. An increase in the expected rate has a direct effect on sample size, while an increase in the tolerable rate has an inverse effect. (correct answer)
  4. An increase in the expected rate has an inverse effect on sample size, while an increase in the tolerable rate also has an inverse effect.
Explanation: The required sample size is directly related to the expected population deviation rate; if more deviations are expected, a larger sample is needed. The required sample size is inversely related to the tolerable deviation rate; if the auditor can tolerate fewer deviations, a larger, more precise sample is needed.

Question 18

An auditor is evaluating the results of an attribute sample for a test of controls. The tolerable deviation rate is 6%, and the sample results indicate an achieved upper deviation rate of 5.5%. Which conclusion is most appropriate?

  1. The auditor should increase planned substantive testing because the control is ineffective.
  2. The auditor can rely on the control as planned because the upper deviation rate is less than the tolerable rate. (correct answer)
  3. The auditor must expand the sample size to reduce the allowance for sampling risk.
  4. The auditor should conclude that the sample deviation rate is equal to the population deviation rate.
Explanation: The decision rule in attribute sampling is to compare the achieved upper deviation rate to the tolerable deviation rate. Since the upper deviation rate (5.5%), which includes an allowance for sampling risk, is less than the tolerable rate (6%), the sample results provide sufficient evidence to support the auditor's planned reliance on the control.

Question 19

An auditor is using systematic selection to choose a sample of 200 items from a population of 10,000 numbered shipping documents. The auditor randomly chooses the 45th document as the starting point. Which document will be the third item selected for the sample?

  1. The 95th document.
  2. The 135th document.
  3. The 145th document. (correct answer)
  4. The 150th document.
Explanation: First, calculate the sampling interval: Population size / Sample size = 10,000 / 200 = 50. The selection process starts with the 45th document. The subsequent items are found by adding the interval. The first item is 45. The second item is 45 + 50 = 95. The third item is 95 + 50 = 145.

Question 20

An auditor testing controls over cash disbursements finds one deviation in a sample. The deviation involved a supervisor overriding the control to approve a payment to a related party that was not properly disclosed. Which of the following statements is most accurate regarding the auditor's evaluation?

  1. As long as the upper deviation rate is less than the tolerable rate, the auditor can ignore this single deviation.
  2. The auditor should consider the qualitative nature of the deviation, as it may indicate fraud or a significant deficiency. (correct answer)
  3. The auditor must immediately expand the sample because a single deviation of this nature proves the control is ineffective.
  4. This deviation is a non-sampling error and should not be considered when projecting the sample results to the population.
Explanation: Auditing standards require the auditor to evaluate not only the frequency (quantitative aspect) of deviations but also their nature and cause (qualitative aspect). A deviation involving management override, especially concerning a related party, is qualitatively significant. It may indicate a higher risk of fraud or a significant control deficiency, even if the overall sample deviation rate is low. This requires further investigation and communication, not just a simple quantitative conclusion.