Audit sampling allows an auditor to test less than 100% of a relevant population and still obtain a reasonable basis for conclusions about that population. It is not simply a shortcut for checking a few convenient invoices. Under ICAI's SA 530, Audit Sampling, the sample has to be designed, selected, tested and evaluated in a way that responds to the audit purpose and the characteristics of the population.
What is audit sampling under SA 530?
SA 530 defines audit sampling as applying audit procedures to less than 100% of items within a population of audit relevance so that all sampling units have a chance of selection, enabling the auditor to draw conclusions about the entire population. A population is the complete set of data from which the sample is selected.
This definition matters because selecting only the largest, easiest or most familiar transactions may be useful for targeted testing, but it is not automatically audit sampling. The auditor must distinguish between sampling, testing specific items and 100% examination, because the conclusion that can be drawn from each approach is different.
Statistical versus non-statistical sampling
SA 530 applies to both statistical and non-statistical sampling. Statistical sampling uses random selection and probability theory to evaluate results, including measurement of sampling risk. A non-statistical approach does not have both of those characteristics.
Non-statistical does not mean informal or arbitrary. The auditor still needs a sample design and size that reduce sampling risk to an acceptably low level, and each sampling unit in the population should have a chance of selection. Professional judgment remains central.
What is sampling risk?
Sampling risk is the possibility that the conclusion based on the sample differs from the conclusion the auditor would have reached if the entire population had been subjected to the same procedure. In tests of controls, this can mean concluding that controls are more effective than they really are, or less effective than they really are. In tests of details, it can mean concluding that a material misstatement does not exist when it does, or the reverse.
Sampling risk is different from non-sampling risk. Non-sampling risk can arise when the auditor uses an inappropriate procedure, misinterprets evidence or fails to recognise a deviation or misstatement. Increasing sample size can address sampling risk, but it does not cure a badly designed procedure.
Step 1: define the purpose and population
Before choosing a sample, the auditor should identify the objective of the audit procedure and the population from which the sample will be drawn. The population must be appropriate and complete for that objective. For example, testing recorded sales invoices for occurrence addresses a different direction of risk from testing dispatch records for completeness of recorded sales.
The sampling unit also needs to be defined. Depending on the procedure, it might be an invoice, customer balance, individual transaction, monetary unit or another identifiable unit.
Step 2: consider stratification and high-value items
SA 530 explains that audit efficiency may improve by stratifying a population into sub-populations with identifying characteristics. For a monetary population, the auditor may separate higher-value items from the remainder. Large or unusual items can also be selected for specific examination outside the sample when that is appropriate.
This is useful because a population containing a handful of very large balances and thousands of small transactions may not be best addressed by treating every item identically. But the auditor must be clear about which portion of the population a sample conclusion covers.
Step 3: determine an appropriate sample size
SA 530 requires a sample size sufficient to reduce sampling risk to an acceptably low level. There is no universal number such as 25, 30 or 60 that is automatically adequate for every audit. Sample size depends on the procedure and relevant factors, including the level of assurance sought, expected deviation or misstatement, tolerable deviation or misstatement, population characteristics and, where relevant, stratification.
A firm's methodology or sampling tool can help translate these factors into a sample size, but the audit file should still show the inputs and rationale. A number produced by software is not a substitute for understanding the population and audit objective.
Step 4: select items without bias
SA 530 requires the auditor to select items so that each sampling unit in the population has a chance of selection. The standard's application material discusses methods including random selection, systematic selection and haphazard selection, while warning that block selection ordinarily cannot be used for audit sampling because most populations are structured so that contiguous items may share characteristics.
Haphazard selection is not the same as deliberately choosing convenient items. It requires avoiding conscious bias or predictability, such as always selecting month-end transactions or items with easy-to-find documentation.
Step 5: perform the procedure and deal with exceptions
The selected audit procedure should be performed on each selected item. If the procedure cannot be applied to a selected item, SA 530 requires the auditor to perform the procedure on a replacement item where appropriate or treat the item according to the standard's requirements when the designed procedure or a suitable alternative cannot be performed.
When a deviation or misstatement is found, the auditor should investigate its nature and cause and consider its possible effect on the audit objective and other audit areas. An apparently isolated exception may indicate a process failure or a wider population issue.
Step 6: project misstatements where required
For tests of details, SA 530 requires the auditor to project misstatements found in the sample to the population. The projected amount helps the auditor obtain a broad view of the scale of misstatement, but it may not by itself be sufficient to determine the adjustment or final audit conclusion.
An anomalous misstatement may be treated differently only when the auditor has a high degree of certainty that it is not representative of the population, supported by additional audit procedures.
Step 7: evaluate the results
The final question is whether the sample results provide a reasonable basis for conclusions about the population. If they do not, the auditor may need to request management to investigate identified misstatements and make adjustments, or modify the nature, timing and extent of further audit procedures.
Worked example: testing purchase transactions
Assume an auditor wants evidence about the occurrence and accuracy of a large population of routine purchase transactions. The auditor first removes individually significant or unusual transactions for specific testing. The remaining homogeneous population is then sampled using the firm's methodology. Each selected transaction is vouched to appropriate evidence and checked against the audit objective.
If several selected transactions contain pricing errors, the auditor should not merely list the exceptions and close the test. The errors should be investigated, projected where required, compared with tolerable misstatement, and assessed for whether they indicate a wider purchasing or control issue.
Practical audit sampling checklist
- State the audit objective: identify the assertion and what the procedure is intended to prove.
- Define and validate the population: confirm that the population is complete and appropriate for the objective.
- Define the sampling unit: document exactly what can be selected.
- Separate specific items where appropriate: identify individually significant, unusual or risk-focused items.
- Document sample-size inputs: record the methodology, tolerable error, expected error and assurance assumptions relevant to the design.
- Use an unbiased selection method: preserve the random seed, interval, selection output or other evidence where applicable.
- Investigate every exception: understand cause and implications rather than treating exceptions as a mechanical count.
- Project and evaluate: where required, project sample misstatements and conclude whether the sample provides a reasonable basis for the population conclusion.
Common mistakes to avoid
- Using a fixed sample size every year without considering changes in risk or population.
- Calling convenience selection or only high-value testing a representative sample.
- Drawing a completeness conclusion from a population that starts only with recorded ledger entries when the procedure requires another source population.
- Replacing an exception simply because supporting evidence is difficult to obtain.
- Failing to project misstatements in tests of details when projection is required.
- Documenting the selected items but not the sampling objective, population, design assumptions and final evaluation.
Practical takeaway
Good audit sampling is a chain of decisions: define the objective, validate the population, choose the sampling unit, determine a defensible sample size, select without bias, investigate exceptions, project results where required and evaluate whether the evidence supports the population conclusion. ICAI also provides an Implementation Guide to SA 530 for practitioners who want additional practical guidance. The strongest audit file shows not only which items were tested, but why the sample could support the conclusion drawn from it.