8.2 Attribute Sampling for Tests of Controls
Key Takeaways
- Attribute sampling is a statistical methodology used in tests of controls to estimate the proportion of items in a population that possess a specific characteristic or deviation from internal controls.
- Sample size determination depends on three core parameters: Tolerable Deviation Rate (inverse relationship), Acceptable Risk of Overreliance (inverse relationship), and Expected Population Deviation Rate (direct relationship), while population size has negligible impact for populations over 2,000 units.
- Statistical sample selection mandates probabilistic techniques—chiefly random-number selection or systematic selection with a random start, provided the auditor actively evaluates the population for periodicity.
- The fundamental decision rule requires comparing the Upper Deviation Rate (UDR = Sample Deviation Rate + Allowance for Sampling Risk) to the Tolerable Deviation Rate (TDR): planned reliance is supported only if UDR <= TDR.
- All identified deviations demand qualitative analysis to uncover whether deviations arose from isolated human error, systemic failures, or intentional management override and potential fraud.
8.2 Attribute Sampling for Tests of Controls
Core Principle: Attribute sampling is an audit sampling technique used primarily in tests of controls to estimate the rate of occurrence of a specific attribute (control deviation or compliance) within a population. It answers a qualitative, binary question: Did the internal control operate as designed, or did it fail? Because controls either function or do not function, attribute testing focuses on deviation frequencies rather than monetary values.
1. Purpose & Foundational Logic of Attribute Sampling
In financial statement audits, the auditor performs risk assessment procedures to evaluate the design and implementation of internal controls. If the auditor plans to assess control risk below the maximum level (i.e., planning to rely on internal controls to reduce substantive testing), GAAS mandates that the auditor must perform tests of controls to obtain audit evidence that the controls operated effectively throughout the entire period of reliance.
ATTRIBUTE SAMPLING DYNAMICS
|
+--------------------+--------------------+
| |
[ COMPLIANT ] [ DEVIATION ]
- Signature present - Signature missing
- Three-way match verified - Quantity mismatch ignored
- Credit check approved - Unauthorized credit release
The Nature of an Attribute
An attribute is a specific operating characteristic of an internal control procedure. Attribute sampling evaluates whether the attribute is present (compliance) or absent (deviation):
- Examples of Attributes Tested:
- Did an authorized manager sign the purchase order before issuance?
- Does the voucher packet include a vendor invoice, receiving report, and purchase order with matching quantities and prices?
- Did the billing department check customer credit approval prior to shipping merchandise?
- Were payroll timecards approved by a designated department supervisor?
- Binary Measurement: Attribute testing does not measure dollar amounts. A deviation occurs whether an unauthorized disbursement voucher is for $12 or $1,200,000. Dollar misstatement evaluation is the domain of variables sampling.
2. The Four Parameters Governing Attribute Sample Size
In statistical attribute sampling, sample size (n) is not an arbitrary guess. It is determined using statistical formulas or published attribute sampling tables (such as AICPA sample size tables) based on four parameters:
+-------------------------------------------------------------------------------------------------------+
| FOUR ATTRIBUTE SAMPLE SIZE PARAMETERS |
| |
| 1. TOLERABLE DEVIATION RATE (TDR) 2. ACCEPTABLE RISK OF OVERRELIANCE (ARO) |
| - Maximum deviation rate auditor accepts - Risk of assessing control risk too low (Beta) |
| - INVERSE relationship with sample size - INVERSE relationship with sample size |
| (Lower TDR -> Larger sample size) (Lower ARO / Higher confidence -> Larger sample) |
| |
| 3. EXPECTED POPULATION DEVIATION RATE (EPDR) 4. POPULATION SIZE (N) |
| - Best estimate of deviations before testing - Total number of items in the population |
| - DIRECT relationship with sample size - NEGLIGIBLE EFFECT if population > 2,000 items |
| (Higher EPDR -> Larger sample size) (Whether N = 5,000 or 500,000, sample is same) |
+-------------------------------------------------------------------------------------------------------+
1. Tolerable Deviation Rate (TDR)
- Definition: The maximum rate of deviations from a prescribed internal control that the auditor is willing to accept without altering the planned assessed level of control risk.
- Relationship with Sample Size: Inverse.
- As the auditor demands a lower Tolerable Deviation Rate (e.g., dropping from 8% to 4%), the auditor requires greater precision, which dictates a larger sample size.
- High planned reliance on a control (assessing control risk at low) demands a lower TDR, necessitating more extensive testing.
2. Acceptable Risk of Overreliance (ARO / Risk of Assessing Control Risk Too Low)
- Definition: The risk that the auditor is willing to accept that the sample results support the auditor's planned reliance on the control when the true population deviation rate actually exceeds the tolerable rate.
- Confidence Level: ARO is the complement of the statistical confidence level (1 - ARO = Confidence Level). For example, a 5% ARO corresponds to a 95% confidence level; a 10% ARO corresponds to a 90% confidence level.
- Relationship with Sample Size: Inverse.
- As the auditor reduces acceptable risk (e.g., from 10% down to 5%, wanting higher confidence), the auditor must examine a larger sample size.
3. Expected Population Deviation Rate (EPDR)
- Definition: The auditor's best advance estimate of the deviation rate in the population before sampling begins. It is based on prior-year audit results, changes in client personnel, preliminary walkthroughs, or a small pilot sample.
- Relationship with Sample Size: Direct.
- As the expected deviation rate increases, the required sample size increases because the auditor needs a larger buffer to differentiate normal deviations from intolerable rates.
- The Critical Rule of EPDR vs. TDR:
Rule: The auditor should NEVER perform tests of controls if the Expected Population Deviation Rate is equal to or exceeds the Tolerable Deviation Rate (EPDR >= TDR). If you already anticipate that the control fails more often than you can tolerate, testing controls is a complete waste of time. The auditor assesses control risk at maximum and moves directly to substantive testing.
4. Population Size (N)
- The Negligible Effect Principle: Candidates are often shocked to learn that in populations exceeding 2,000 to 5,000 sampling units, the size of the population has a virtually negligible effect on the required sample size.
- Statistical Reason: Sampling mathematics is based on probability distributions (hypergeometric and binomial). Once a population is sufficiently large, the finite population correction factor approaches 1.0. A random sample of 60 items provides virtually the same statistical confidence and precision whether drawn from a population of 5,000 invoices or 5,000,000 invoices!
Summary Table: Parameter Directionality and Sample Size Impact
| Parameter | Change in Parameter | Effect on Sample Size (n) | Underlying Audit Logic |
|---|---|---|---|
| Tolerable Deviation Rate (TDR) | Increases | Decreases | Auditor is willing to accept more defects; less evidence needed. |
| Tolerable Deviation Rate (TDR) | Decreases | Increases | Auditor requires high control precision; more evidence needed. |
| Acceptable Risk of Overreliance (ARO) | Increases | Decreases | Auditor accepts higher risk of making a mistake; fewer items tested. |
| Acceptable Risk of Overreliance (ARO) | Decreases | Increases | Auditor demands higher statistical confidence; more items tested. |
| Expected Population Deviation Rate (EPDR) | Increases | Increases | More defects expected; larger sample required to confirm UDR <= TDR. |
| Expected Population Deviation Rate (EPDR) | Decreases | Decreases | Low defect rate expected; smaller sample sufficient. |
| Population Size (N > 2,000) | Increases / Decreases | Virtually No Effect | Sampling error is driven by absolute sample size, not population fraction. |
3. Sample Selection Methodologies
Statistical attribute sampling requires probabilistic sample selection techniques to ensure that personal bias does not influence the sample draw:
SAMPLE SELECTION METHODS
|
+-----------------------------+-----------------------------+
| |
[ PROBABILISTIC (STATISTICAL) ] [ NON-PROBABILISTIC ]
| |
+-------+-------+ +-------+-------+
| | | |
RANDOM- SYSTEMATIC HAPHAZARD BLOCK
NUMBER SELECTION SELECTION SELECTION
SELECTION (Random Start) (Judgmental) (Contiguous)
1. Random-Number Selection
- Every item in the population has an equal chance of selection.
- Uses computerized random-number generators, audit software (e.g., IDEA, ACL), or published random number tables matched against pre-numbered client documents (e.g., check numbers 10001 through 25000).
- This is the most widely used and statistically unassailable selection method.
2. Systematic Selection with a Random Start
- Mechanics:
- Calculate the sampling interval (k): k = Population Size (N) / Sample Size (n)
- Select a random starting point between 1 and k.
- Select every k-th item throughout the entire population sequence.
- Example: Population N = 10,000, required sample size n = 100. Interval k = 10,000 / 100 = 100. The auditor picks a random starting number between 1 and 100 (e.g., 42). The sample items will be 42, 142, 242, 342, ..., up to 9,942.
- The Periodicity Trap (Cyclical Bias):
Exam Warning: The primary inherent vulnerability of systematic selection is periodicity (cyclical ordering in the population). If transactions occur in recurring patterns that align with the interval k (e.g., every 100th voucher represents a monthly executive bonus or a weekly tax wire), the sample will be severely biased. The auditor must inspect the population for periodicity before using systematic sampling or use multiple random starts.
Prohibited Methods in Statistical Sampling
- Haphazard Selection: Selecting items without conscious bias, but without a mathematical technique. Permitted only in non-statistical sampling because probabilities of selection cannot be mathematically determined.
- Block Selection: Selecting contiguous items (e.g., all checks written between May 1 and May 10). Generally prohibited or discouraged under GAAS because transactions in a narrow time block are rarely representative of the entire year.
4. Evaluating Attribute Sample Results: SDR, UDR, and the Decision Rule
After testing the selected sample, the auditor evaluates the results through a structured three-step quantitative process:
+-------------------------------------------------------------------------------------------------+
| QUANTITATIVE EVALUATION PROCESS |
| |
| 1. SAMPLE DEVIATION RATE (SDR) = Deviations Found / Sample Size (n) |
| 2. UPPER DEVIATION RATE (UDR) = SDR + Allowance for Sampling Risk (from Tables) |
| 3. THE DECISION RULE: |
| - IF UDR <= Tolerable Rate --> RELY on control as planned (Control risk low/moderate) |
| - IF UDR > Tolerable Rate --> DO NOT RELY as planned (Increase control risk/substantive) |
+-------------------------------------------------------------------------------------------------+
1. Sample Deviation Rate (SDR)
The actual percentage of deviations observed in the sample:
2. Upper Deviation Rate (UDR / Upper Precision Limit)
The auditor cannot assume the population deviation rate is equal to the sample deviation rate; sampling risk must be added. The Upper Deviation Rate (UDR) represents the maximum population deviation rate expected at the specified Acceptable Risk of Overreliance: In practice, auditors do not manually calculate ASR; they locate the UDR directly in AICPA statistical evaluation tables using the sample size, number of deviations identified, and the ARO percentage.
3. The Authoritative Decision Rule
The auditor compares the Upper Deviation Rate (UDR) directly to the Tolerable Deviation Rate (TDR):
- If UDR ≤ TDR: The statistical evidence supports planned reliance on internal controls. The auditor concludes the control operated effectively and assesses control risk at the planned level.
- If UDR > TDR: The statistical evidence does not support planned reliance. There is an unacceptably high risk that the true population deviation rate exceeds what the auditor can tolerate. The auditor must:
- Assess control risk at a higher level (or at maximum).
- Re-evaluate planned substantive procedures by expanding their nature, timing, and extent (e.g., performing tests of details at year-end with larger sample sizes).
- Test alternative compensating controls, if available and properly designed.
The Fatal CPA Exam Trap: SDR vs. TDR
Exam Trap: The most common mistake candidates make on the AUD exam is comparing the Sample Deviation Rate (SDR) to the Tolerable Deviation Rate! Candidates see that SDR (e.g., 2%) is lower than TDR (e.g., 6%) and conclude that the control is acceptable. WRONG! You must compare the Upper Deviation Rate (UDR) to TDR! Even if the sample deviation rate is low, the allowance for sampling risk may push the UDR above the tolerable rate.
Detailed Numerical Case Walkthrough
An auditor plans an attribute sample for credit approval compliance:
- Population: N = 15,000 sales invoices.
- Audit Parameters: ARO = 5% (95% confidence), Tolerable Deviation Rate (TDR) = 6.0%, Expected Population Deviation Rate (EPDR) = 1.0%.
- Sample Size Determination: Assume the firm's attribute sampling table or software indicates a sample of about 80 invoices for these parameters.
- Audit Testing Execution: The auditor examines the 80 invoices and discovers 2 deviations (two invoices lacked credit approval documentation).
- Step 1: Calculate SDR:
- Step 2: Determine UDR: Consulting the AICPA statistical evaluation table for n = 80 at 5% ARO with 2 deviations, the Upper Deviation Rate is 7.7% (consisting of 2.5% SDR + 5.2% Allowance for Sampling Risk).
- Step 3: Apply the Decision Rule:
- Compare UDR (7.7%) to TDR (6.0%).
- Result: UDR (7.7%) > TDR (6.0%).
- Audit Conclusion: Even though the sample deviation rate (2.5%) is far below the tolerable rate (6.0%), the auditor CANNOT rely on the control as planned! There is more than a 5% chance that the true population deviation rate exceeds 6.0%. The auditor must elevate assessed control risk and expand substantive tests of revenue and receivables.
5. Qualitative Evaluation of Deviations
Statistical evaluation is only half of the auditor's responsibility. Under AU-C 530, the auditor must investigate the nature and cause of every identified deviation:
QUALITATIVE INVESTIGATION OF DEVIATIONS
|
+-----------------------------+-----------------------------+
| |
[ ISOLATED / SYSTEMIC ERRORS ] [ POTENTIAL FRAUD ]
- New employee training issue - Management override of controls
- Temporary software bug - Forged signatures / fictitious sales
- Misunderstanding of instructions - Intentional circumvention for bonus
| |
Response: Assess control risk; Response: Evaluate fraud implications
expand substantive procedures and communicate per AU-C 240
Critical Qualitative Questions
- What is the Nature and Cause of the Deviation? Did the deviation occur because of an inadvertent clerical slip, employee illness, vacation replacement, or an ambiguous written policy?
- Is the Deviation Systemic or Isolated? Did deviations occur uniformly across the entire year, or were they concentrated during a specific two-week period when a temporary employee covered the position?
- Does the Deviation Indicate Fraud or Management Override? If an authorization signature was deliberately forged, or if a credit check was intentionally overridden for a company owned by an executive's relative, the quantitative UDR is secondary. Any intentional circumvention indicates a lack of management integrity, which calls for evaluating fraud implications and required communications under AU-C 240 and reconsidering reliance on related controls across the cycle.
6. Special Situations: Voided, Missing, and Inapplicable Documents
When conducting attribute testing on physical or electronic records, auditors routinely encounter anomalous documents. GAAS establishes strict handling protocols:
1. Properly Voided Documents
- Scenario: The auditor selects check #10405. The physical check is stamped "VOID" and retained in the check sequence; the general ledger shows zero disbursement.
- Treatment: If the document was voided legitimately in accordance with entity internal control procedures and does not represent an unrecorded transaction, it is not a deviation. The auditor selects a replacement document at random from the population.
2. Missing or Unlocatable Documents
- Scenario: The auditor requests voucher packet #8022. The client searches the archive but cannot find the voucher or supporting documentation.
- Treatment: The auditor MUST treat the missing document as a control deviation! The auditor cannot simply pick another item to replace it, nor can the auditor accept management's verbal reassurance that "it was definitely approved." If the auditor cannot apply the audit procedure or satisfactory alternative procedures, it is recorded as a deviation.
3. Inapplicable Documents
- Scenario: The auditor selects document #3044 from a population defined as sales invoices, but discovers that #3044 is an internal warehouse inventory transfer slip erroneously indexed in the sales batch.
- Treatment: The document is not part of the defined population. If properly voided or misfiled without indicating a control breakdown, the auditor replaces it with a properly selected sales invoice.
An auditor is determining the required sample size for an attribute sampling test of controls over purchase order authorizations. Which of the following combinations of changes in audit parameters will result in the largest increase in the required sample size?
An auditor tests internal controls over sales invoice approvals using attribute sampling. The audit plan establishes a tolerable deviation rate of 7% and an acceptable risk of overreliance of 5%. In a sample of 100 sales invoices, the auditor identifies 3 deviations, resulting in a sample deviation rate of 3%. Statistical evaluation tables indicate that for a sample size of 100 with 3 deviations at a 5% risk of overreliance, the upper deviation rate is 7.6%. Which of the following actions should the auditor take?
While performing an attribute sample of 80 cash disbursement vouchers to verify that all payments were authorized by an approved signature, the auditor discovers that 2 selected voucher packets cannot be located by client personnel. How should the auditor treat these missing vouchers?
An auditor intends to use systematic selection to draw an attribute sample of 100 payroll checks from an annual population of 5,000 sequentially numbered payroll checks. Which of the following statements correctly describes this sampling approach and its primary inherent risk?