8.3 Non-Statistical Sampling & Dual-Purpose Testing

Key Takeaways

  • GAAS permits non-statistical sampling; the same risk factors drive sample size either way, so a well-designed non-statistical sample is usually comparable in size to a statistical one.
  • Haphazard sampling is permitted only in non-statistical sampling, while block sampling is generally discouraged under GAAS due to the extreme risk of unrepresentative sample selection.
  • Dual-purpose testing executes a test of control (evaluating attribute deviation) and a substantive test of details (evaluating monetary misstatement) simultaneously on the identical sample.
  • The sample size for a dual-purpose test must be the larger of the sample sizes determined for the two distinct objectives, and results must be evaluated independently against control and substantive thresholds.
  • Specialized attribute techniques include Stop-or-Go (sequential) sampling to minimize sample size when deviations are rare and Discovery sampling to detect at least one instance of fraud or critical non-compliance.
Last updated: September 2026

8.3 Non-Statistical Sampling & Dual-Purpose Testing

Core Principle: While statistical sampling provides mathematical rigor, auditors frequently utilize non-statistical sampling in practice. AU-C 530 permits non-statistical sampling provided the auditor exercises disciplined professional judgment. Furthermore, when efficiency demands, auditors design dual-purpose tests that evaluate both internal control operating effectiveness and monetary statement accuracy using the exact same sample of transactions.


1. Non-Statistical Attribute Sampling & The GAAS Comparability Rule

In practice, many audit engagements utilize non-statistical sampling due to its practical flexibility and ease of application. However, candidates often misunderstand what "non-statistical" truly means under GAAS.

                             NON-STATISTICAL SAMPLING PRINCIPLES
                                             |
                +----------------------------+----------------------------+
                |                                                         |
       [ PROFESSIONAL JUDGMENT ]                               [ THE COMPARABILITY RULE ]
       Auditor subjectively sets                               Sample size must be comparable
       parameters and evaluates results                        to a statistical sample under
       without mathematical tables                             identical audit risk parameters!

The Nature of Non-Statistical Sampling

In non-statistical attribute sampling:

  • The auditor uses professional judgment rather than mathematical algorithms to determine the sample size.
  • The auditor may use haphazard selection in addition to random or systematic methods.
  • The auditor does not mathematically calculate an Upper Deviation Rate (UDR). Instead, the auditor qualitatively compares the sample deviation rate to the tolerable rate while applying judgment regarding the adequacy of the allowance for sampling risk.

The Critical GAAS Comparability Mandate

AU-C 530 Guidance: The factors that drive sample size (tolerable rate, acceptable risk, and expected deviation rate) affect sample size the same way whether the approach is statistical or non-statistical, and the AICPA Audit Sampling Guide expects a non-statistical sample to be comparable in size to an efficient statistical sample for the same parameters.

  • The Rule in Action: An auditor cannot claim: "Because I am using non-statistical sampling, I will only test 10 disbursement vouchers instead of the 60 required by statistical tables." Such an arbitrarily small sample would leave sampling risk too high. The auditor must consider the identical factors—Tolerable Deviation Rate, Acceptable Risk of Overreliance, and Expected Population Deviation Rate—and arrive at a defensible, comparable sample size.
  • Workpaper Documentation: The auditor must document the rationale for the sample size, the parameters evaluated, the selection method used, and the qualitative justification for relying on the control based on the sample findings.

2. Sample Selection Techniques in Non-Statistical Sampling

While statistical sampling strictly requires probabilistic selection (random-number or systematic selection), non-statistical sampling permits non-probabilistic methods. However, each method has distinct operational constraints:

                                SAMPLE SELECTION TECHNIQUES
                                             |
               +-----------------------------+-----------------------------+
               |                                                           |
       [ HAPHAZARD SELECTION ]                                     [ BLOCK SELECTION ]
       - Selection without conscious bias                          - Selecting contiguous items
       - Permitted ONLY in non-statistical                         - (e.g., all checks in May)
       - Prone to subconscious human bias                          - HIGH RISK OF UNREPRESENTATIVE SAMPLE
       - Cannot mathematically measure risk                        - GENERALLY DISCOURAGED UNDER GAAS

1. Haphazard Selection

  • Mechanics: The auditor selects sample units from the population without any conscious bias, preference, or deliberate inclusion/exclusion (e.g., flipping through a paper voucher file cabinet and pulling out invoices without regard to thickness, filing tab position, date, or amount).
  • Limitations: True randomness is impossible for humans to achieve subconsciously. Auditors subconsciously tend to avoid damaged, difficult-to-reach, or unusually bulky file folders, or may unconsciously select neater documents.
  • Standard Rule: Permitted exclusively in non-statistical sampling. Because the mathematical probability of selection is unknown, it cannot be used in statistical attribute sampling.

2. Block Selection (Cluster Sampling)

  • Mechanics: Selecting a contiguous sequence or block of transactions (e.g., examining all 75 sales invoices recorded between October 10 and October 15, or all checks written during the final week of December).
  • Severe Operational Vulnerability: Block sampling carries a very high risk of selecting an unrepresentative sample. Transaction patterns, personnel staffing, and internal control effectiveness during a single five-day window may reflect unique temporary conditions (e.g., a software crash, employee turnover, seasonal sales rushes) that do not represent the operating effectiveness of controls across the full 365-day fiscal year.
  • Standard Rule: Generally not recommended or heavily restricted under GAAS. It is strictly prohibited in statistical sampling and should only be used non-statistically if the auditor selects multiple blocks across different operating cycles and seasons with robust justification.

Comparison Table: Sample Selection Techniques

Selection MethodPermitted in Statistical?Permitted in Non-Statistical?Description & Evaluation
Random-NumberYESYESGold standard; mathematically eliminates selection bias. Every unit has equal probability.
Systematic SelectionYESYESSelects every k-th item after a random start. Must evaluate population for periodicity.
Haphazard SelectionNOYESSelection without conscious bias. Unacceptable in statistical sampling because selection probabilities are unknown.
Block SelectionNODISCOURAGEDSelects contiguous items. Severe risk of unrepresentative sample; generally rejected unless multi-block justified.

3. Dual-Purpose Testing Architecture

In modern audit engagements, audit efficiency is paramount. Auditors frequently execute dual-purpose tests to satisfy two distinct audit objectives with a single procedure:

                                    DUAL-PURPOSE TEST
                                            |
                 +--------------------------+--------------------------+
                 |                                                     |
     [ OBJECTIVE 1: TEST OF CONTROL ]                        [ OBJECTIVE 2: SUBSTANTIVE TEST ]
     - Qualitative Attribute Testing                         - Quantitative Monetary Testing
     - Evaluates control deviation rate                      - Evaluates dollar misstatement
     - Binary outcome (compliant / deviation)                - Dollar outcome (overstatement / under)
     - Compared to Tolerable Deviation Rate (TDR)            - Compared to Tolerable Misstatement (TM)

Definition & Practical Example

Dual-Purpose Test Defined: An audit procedure designed to serve simultaneously as a test of control (evaluating whether a control attribute operated effectively) and as a substantive test of details (evaluating whether an account balance or transaction contains a monetary misstatement) on the exact same sample of items (AU-C 330 application guidance).

Realistic Dual-Purpose Scenario: The Expenditure Cycle

An auditor selects a sample of 75 cash disbursement voucher packets and performs the following simultaneous procedures on each packet:

  1. Control Testing (Attribute): Inspects the packet for the purchasing manager's written approval signature and checks that the receiving report was stamped "MATCHED" to the vendor invoice.
  2. Substantive Testing (Details): Recalculates the mathematical accuracy of unit prices, quantities, and sales tax; verifies that the check cleared the bank for the exact invoice amount; and confirms that the expense was debited to the correct general ledger account code.

The Three Mandatory Requirements for Dual-Purpose Tests

  1. Appropriate Population: The selected population must be appropriate for both audit objectives. For example, testing shipping documents can evaluate both credit approval controls and sales cutoff/understatement, but testing receiving reports would not evaluate sales.
  2. Sample Size Determination (The Dominance Rule):

    The Dual-Purpose Sizing Rule: The auditor must calculate the required sample size for the test of control and the required sample size for the substantive test of details independently. The sample size for the dual-purpose test must be the LARGER of the two sample sizes!

    • Example: If tests of controls require 45 items and substantive tests of details require 70 items, the auditor must select at least 70 items for the dual-purpose test.
  3. Independent Evaluation: The auditor must evaluate the results separately against their respective criteria:
    • Control deviations are evaluated against the Tolerable Deviation Rate (TDR).
    • Monetary misstatements are projected and evaluated against Tolerable Misstatement (TM).

The Asymmetry Between Control Deviations and Monetary Errors

Candidates must understand the profound asymmetry between control failures and dollar misstatements:

   +-------------------------------------------------------------------------------------------------+
   |                     THE CONTROL DEVIATION VS. MONETARY MISSTATEMENT ASYMMETRY                   |
   |                                                                                                 |
   |   1. A MONETARY MISSTATEMENT ALMOST ALWAYS IMPLIES A CONTROL FAILURE:                           |
   |      If an invoice was billed at the wrong price or calculated incorrectly, the internal        |
   |      controls failed to prevent or detect the dollar misstatement.                              |
   |                                                                                                 |
   |   2. A CONTROL DEVIATION DOES NOT NECESSARILY CAUSE A MONETARY MISSTATEMENT:                    |
   |      An invoice may be completely missing the supervisor's approval signature (control           |
   |      deviation), but the invoice amount, pricing, and mathematics may be 100% correct           |
   |      (zero monetary misstatement).                                                              |
   +-------------------------------------------------------------------------------------------------+

Exam Trap: Do not confuse a control deviation with a monetary error. A client can have a 10% control deviation rate with zero dollar misstatements in the sample. However, a high deviation rate indicates that the system is vulnerable, requiring expanded substantive testing.


4. Specialized Attribute Sampling Methodologies

In addition to classical attribute sampling, auditing standards recognize two specialized attribute sampling models tailored for specific engagement circumstances: Stop-or-Go Sampling and Discovery Sampling.

                               SPECIALIZED ATTRIBUTE SAMPLING MODELS
                                                 |
                   +-----------------------------+-----------------------------+
                   |                                                           |
        [ STOP-OR-GO (SEQUENTIAL) ]                                   [ DISCOVERY SAMPLING ]
        - Phased / stepwise testing                                   - Used when EPDR = 0%
        - Minimizes sample size in clean cycles                       - Critical deviations or fraud
        - Expands only if deviations appear                           - HALT IMMEDIATELY ON FIRST DEVIATION!

1. Stop-or-Go (Sequential) Sampling

  • Objective: To minimize sample size and maximize audit efficiency in transaction cycles where the auditor expects exceptionally few or zero deviations.
  • How it Works:
    1. Stage 1: The auditor selects a small initial sample (e.g., 25 items).
    2. If zero deviations are identified, the auditor "stops" testing immediately and concludes that the control is operating effectively at the desired confidence level.
    3. If one or more deviations are discovered, the auditor "goes" to Stage 2, selecting an additional predetermined number of items (e.g., 30 more items) and re-evaluates cumulative deviations.
    4. The process continues through a planned maximum table sequence.
  • Benefit: Prevents unnecessary over-testing of well-controlled systems while establishing a disciplined expansion protocol if deviations are encountered.

2. Discovery Sampling

  • Objective: Designed for situations where the auditor expects virtually zero deviations (EPDR = 0%), but seeks a high level of confidence that a critical control failure, illegal act, or fraud is not present above a specified tolerable rate.
  • Primary Applications:
    • Investigating suspected defalcations, ghost employees on payroll, or unauthorized wire transfers.
    • Testing compliance with critical regulatory covenants (e.g., banking capital adequacy, nuclear safety compliance, or defense contract certifications).
  • The Absolute Discovery Decision Rule:

    The Zero-Tolerance Rule: The sample size is calculated to provide, for example, a 95% probability of discovering at least one deviation if the true population deviation rate equals or exceeds the tolerable rate. If even ONE deviation is identified, sampling immediately stops! The auditor does not expand the sample; the auditor concludes that the control is ineffective or that fraud is present, and immediately initiates a forensic or substantive investigation.

Comprehensive Comparison: The Three Attribute Sampling Models

DimensionClassical Fixed-Size Attribute SamplingStop-or-Go (Sequential) SamplingDiscovery Sampling
Primary Audit PurposeStandard testing of controls across normal business cycles.Efficiency optimization in highly reliable control environments.Fraud investigations, critical non-compliance, or illegal acts.
Expected Deviation Rate (EPDR)Normal historical rate (e.g., 1% – 3%).Low or zero expected deviations.Must be 0% (zero deviations expected).
Testing SequenceSingle, fixed sample size selected and tested all at once.Multi-stage (stepwise) testing; sample expands only if deviations found.Single sample tested until completion or until first deviation appears.
Action Upon Finding a DeviationQuantify Upper Deviation Rate and compare to Tolerable Rate.Expand sample to next predetermined stage and continue testing.HALT SAMPLING IMMEDIATELY! Presume control breakdown or fraud; escalate.

5. Practical Scenarios & Exam Pitfalls

Scenario 1: Sizing the Dual-Purpose Sample

An auditor plans a dual-purpose test on the purchasing cycle. To test the operating effectiveness of purchasing controls (three-way matching), attribute sampling tables dictate a sample size of 50 items. To substantively test inventory pricing and accounts payable cutoff, monetary variables tables dictate a sample size of 85 items.

  • Question: How many voucher packets must the auditor select for the dual-purpose test?
  • Correct Practice: The auditor must select 85 items (the larger of the two required sample sizes). The auditor tests all 85 items for control compliance and for monetary misstatements.

Scenario 2: The Non-Statistical Sizing Shortcut

A staff auditor notes: "Under statistical attribute sampling at 5% ARO and 7% TDR, the required sample size is 55 items. However, because our firm uses non-statistical sampling on this client, I will only select 15 items to save time."

  • CPA Exam Analysis: This is not acceptable. The risk factors that call for about 55 items do not change because the method is non-statistical, so 15 items would leave sampling risk too high. Selecting 15 items introduces unacceptably high sampling risk that cannot be justified under professional standards.
Test Your Knowledge

An auditor decides to utilize non-statistical sampling rather than statistical sampling for tests of controls over purchase order approvals. In determining the appropriate sample size, what is expected of the auditor?

A
B
C
D
Test Your Knowledge

An audit team designs a dual-purpose test for the revenue cycle. Sizing calculations determine that 45 items are required to test the operating effectiveness of the customer credit approval control, while 70 items are required to substantive-test sales invoice pricing and mathematical accuracy. Which of the following rules governs the execution and evaluation of this dual-purpose test?

A
B
C
D
Test Your Knowledge

An auditor is investigating suspected unauthorized payroll payments in an entity where zero unauthorized payments are expected. The auditor wants high confidence of identifying at least one unauthorized payment if the true population occurrence rate is 2% or higher, and plans to halt testing immediately if any unauthorized payment is found. Which sampling approach is specifically designed for this scenario?

A
B
C
D
Test Your Knowledge

An audit junior wishes to select a sample of cash disbursement vouchers across the fiscal year using block sampling by selecting all 60 vouchers processed during the first two weeks of November. Why does GAAS generally discourage or restrict the use of block sampling?

A
B
C
D