Because checking 100% of a transaction population is often impractical due to time and resource constraints, internal auditors use sampling frameworks to select representative subsets of data for detailed testing.
[Define Target Population] ---> [Select Sampling Methodology] ---> [Evaluate Sample Testing Results]
Auditors select from three primary sampling methods based on the engagement objectives:
- Attribute Sampling (Statistical): Used primarily in control testing to evaluate the frequency of a specific characteristic or deviation rate within a population. The auditor defines an acceptable risk of overreliance, a tolerable deviation rate, and an expected population deviation rate to calculate a statistically valid sample size using probability tables. The testing results are used to estimate the maximum error rate for the entire population.
- Variable Sampling (Statistical): Used primarily in substantive testing to estimate the total monetary value or quantity of a population, or to calculate the total value of misstatements within a balance. Examples include using Mean-per-Unit estimation or Dollar-Unit Sampling to project sample errors across an entire balance sheet line item.
- Judgmental Sampling (Non-Statistical): A non-statistical sampling method where the auditor selects specific items for review based on their professional judgment, experience, and knowledge of risk factors. Examples include selecting only high-value items, targeting transactions processed on weekends, or focusing on transactions initiated by newly hired personnel. While efficient for targeting known risks, judgmental sampling results cannot be statistically projected across the broader population.
Â