Audit sampling does not mean selecting a convenient handful of invoices and treating the result as representative. Under ICAI's SA 530, Audit Sampling, sampling is a structured way to obtain and evaluate audit evidence about selected items so the auditor can form a conclusion about the population from which they were drawn.
The practical challenge is deciding when sampling is appropriate, how large the sample should be, how items should be selected, and what to do when the sample contains errors or control deviations. The standard does not prescribe a universal sample size because those decisions depend on the audit objective, population, assessed risk and other engagement-specific factors.
What counts as audit sampling?
SA 530 deals with applying audit procedures to less than 100% of items within an audit-relevant population where all sampling units have a chance of selection, so that the auditor has a reasonable basis for drawing conclusions about the entire population. Sampling can be statistical or non-statistical.
This is different from testing specific items. An auditor may deliberately examine all unusually large transactions, related-party entries or other high-risk items. Those procedures can be valuable, but the results from deliberately selected items generally cannot be projected to the remaining population in the same way as a properly designed sample.
Step 1: Define the audit objective and population
Before deciding sample size, state exactly what the procedure is intended to prove. A test of controls might ask whether purchase orders were authorised throughout the year. A substantive test might ask whether recorded trade receivables are overstated.
The population must be appropriate and complete for that objective. If the objective is to test sales recorded during the year, a sales listing missing one month is not a sound sampling population. The sampling unit also needs to be clear: it could be an invoice, customer balance, cheque, credit entry or monetary unit.
Step 2: Decide whether sampling is the right approach
Sampling is not mandatory for every procedure. Depending on the risk and population, the auditor may test 100% of items, select specific high-risk items, use analytical procedures, or use a sample. A small population of individually material items may make full testing more sensible than sampling.
A common practical approach is to remove individually significant or specially risky items for separate testing and then consider sampling the remaining population. The auditor should document why the chosen approach responds appropriately to the assessed risk.
Step 3: Set tolerable misstatement or tolerable deviation
For substantive sampling, tolerable misstatement is the application of performance materiality to the particular sampling procedure. SA 530 explains that it may equal or be lower than performance materiality. Lower tolerable misstatement generally means a larger sample because less error can be accepted in the tested population.
For tests of controls, the relevant concept is the tolerable rate of deviation. The auditor considers how much departure from the prescribed control can be accepted while still relying on the control at the planned level.
Step 4: Consider expected errors and risk
Expected misstatement or expected control deviation also affects sample design. If the auditor expects more errors in the population, more evidence will usually be required. Likewise, if the auditor wants a lower risk that the sample conclusion differs from the conclusion that would be reached by examining the entire population, sample size generally increases.
This is why copying last year's sample size without reconsidering current-year risk, materiality, population and expected error can produce weak audit evidence.
Step 5: Select items without bias
SA 530 requires the auditor to select items in a way that gives each sampling unit in the population a chance of selection. The standard's application material discusses methods such as random selection, systematic selection and haphazard selection, while noting considerations and limitations associated with each method.
Haphazard selection does not mean choosing whatever is easiest to retrieve. The auditor must avoid conscious bias or predictability. A sample consisting only of transactions from the first week of every month, for example, may fail to represent transactions processed at other times.
Statistical versus non-statistical sampling
Statistical sampling uses random selection and probability theory to evaluate sample results, including measurement of sampling risk. A non-statistical approach does not satisfy both characteristics. Both approaches can be acceptable under SA 530 when properly designed and applied.
The important point is not whether software produces a mathematically impressive number. The sample must answer the audit objective, and professional judgment remains necessary in defining the population, risk, tolerable error and treatment of exceptions.
Worked example
Suppose an auditor wants substantive evidence over a population of 4,000 sales invoices. Several unusually large invoices and related-party transactions are identified as specific risk items and tested separately. The remaining invoices form the sampling population.
The auditor determines a tolerable misstatement for this procedure based on performance materiality, considers expected misstatement and the desired level of sampling risk, and selects a sample using an appropriate unbiased method. If testing identifies a misstatement, the auditor investigates its nature and cause and, where applicable, projects the misstatement found in the sample to the population.
If the projected result approaches or exceeds tolerable misstatement, simply recording that the tested invoices were mostly correct is not enough. The auditor must evaluate whether the sample still provides a reasonable basis for a conclusion and may need additional procedures.
What to do when an exception is found
The auditor should investigate the nature and cause of each identified deviation or misstatement and evaluate its possible effect on the purpose of the audit procedure and other areas of the audit. An error caused by a one-off data-entry mistake may have different implications from an error revealing a systematic control failure.
SA 530 also addresses anomalies: a misstatement or deviation demonstrably not representative of the population. Treating an exception as anomalous requires a high degree of certainty and appropriate additional procedures; it should not become an easy way to exclude inconvenient errors.
Common audit-sampling mistakes
- Starting with a sample size instead of an objective: the audit question, population and assertion should come first.
- Using an incomplete population: sampling cannot compensate for an unreliable source listing.
- Confusing specific-item testing with sampling: purposively selected high-value items do not automatically support a conclusion on the untested population.
- Reusing last year's sample mechanically: risk, materiality, population size and expected errors can change.
- Ignoring exceptions: every deviation or misstatement requires evaluation of cause and implications.
- Failing to evaluate the final result: the auditor must conclude whether sampling provided a reasonable basis for conclusions about the tested population.
Documentation checklist
- Audit objective and relevant assertion.
- Definition and completeness of the population.
- Sampling unit and selection method.
- Tolerable misstatement or tolerable deviation rate.
- Factors considered in determining sample size.
- Specific high-risk items tested outside the sample.
- Exceptions found, their causes and follow-up procedures.
- Projection or evaluation of sample results, where applicable.
- Final conclusion on whether the sample provides a reasonable basis for the audit conclusion.
Practical takeaway
A defensible audit sample begins with a clear audit objective, not a predetermined number of vouchers. Define a reliable population, determine tolerable error and sampling risk, select items without bias, investigate every exception and explicitly evaluate whether the results support a conclusion about the population. ICAI also provides an Implementation Guide to SA 530 with practical guidance for applying the standard.