8.1 Audit Sampling Principles & Sampling Risk (AU-C 530)
Key Takeaways
- Audit sampling under AU-C 530 involves applying audit procedures to less than 100% of items in a population such that all sampling units have an opportunity of selection, enabling the auditor to evaluate population characteristics.
- Non-sampling procedures—including inquiry, observation, analytical procedures, and 100% examination of items exceeding a specific dollar threshold—do not constitute audit sampling because not all population units have a chance of selection.
- GAAS permits both statistical and non-statistical sampling; both require extensive professional judgment, but only statistical sampling allows the auditor to mathematically measure sampling risk and objectively determine sample size.
- In tests of controls, the Risk of Overreliance (Beta risk) impairs audit effectiveness and may lead to an inappropriate audit opinion, while the Risk of Underreliance (Alpha risk) impairs audit efficiency by causing unnecessary substantive testing.
- Non-sampling risk stems from human errors such as misinterpreting evidence, applying inappropriate procedures, or failing to recognize deviations; it cannot be measured mathematically and must be controlled through supervision, planning, and quality control.
8.1 Audit Sampling Principles & Sampling Risk (AU-C 530)
Core Principle: Under AU-C 530 (Audit Sampling), audit sampling is defined as the application of audit procedures to less than 100% of items within a population of audit relevance such that all sampling units have a chance of selection, in order to provide the auditor with a reasonable basis on which to draw conclusions about the entire population. Sampling is not an end in itself; it is a vital evidence-gathering tool designed to obtain sufficient appropriate audit evidence while balancing audit efficiency and audit effectiveness.
1. The Scope & Formal Definition of Audit Sampling
Auditors are constantly tasked with evaluating vast volumes of transactions, account balances, and control activities. Examining every single transaction across an enterprise is neither economically feasible nor theoretically necessary to obtain reasonable assurance. However, not every audit procedure that examines fewer than 100% of items constitutes audit sampling under professional standards.
POPULATION OF AUDIT EVIDENCE
|
+------------------------+------------------------+
| |
[ 100% EXAMINATION ] [ LESS THAN 100% ]
Testing all items in |
an account balance +-------------------------+-------------------------+
(NOT audit sampling) | |
ALL ITEMS HAVE A CHANCE NOT ALL ITEMS HAVE A CHANCE
OF SELECTION OF SELECTION
| |
[ AUDIT SAMPLING ] [ NON-SAMPLING TESTING ]
(AU-C 530 Governed) - Testing specific items
- Statistical sampling - Large / key items
- Non-statistical sampling - Walkthroughs / inquiry
The Two Mandatory Criteria of Audit Sampling
For an audit procedure to meet the formal definition of audit sampling under AU-C 530, two conditions must be satisfied simultaneously:
- Less than 100% of the population is tested: The auditor examines a subset of the population of interest.
- All sampling units have an opportunity (chance) for selection: Every item in the population has a probability (which may or may not be equal, but must be greater than zero) of being selected into the sample.
What is a Sampling Unit?
A sampling unit is the individual item or element that makes up the population. Depending on the audit objective and sampling design, a sampling unit may be:
- A physical document (e.g., a customer sales invoice, vendor voucher packet, receiving report, or payroll check).
- An individual balance (e.g., a customer subsidiary ledger account balance in accounts receivable).
- A individual transaction or journal entry line item.
- An individual monetary unit (e.g., each single dollar within an account balance, as utilized in Monetary Unit Sampling / MUS).
2. Audit Procedures That Do Not Constitute Audit Sampling
Candidates frequently confuse any selective audit testing with audit sampling. GAAS explicitly identifies numerous audit procedures that involve examining fewer than 100% of items but do not constitute audit sampling because they do not give all population items a chance of selection or do not seek to draw an inference about the entire population.
Non-Sampling Audit Activities
- Inquiry and Observation: Asking management about accounting policies or observing client personnel executing an inventory count or segregation of duties. Observation provides evidence only of the control's operation at the exact point in time when observed; it does not generate an audit trail of physical sampling units that can be statistically extrapolated.
- Testing Specific / High-Value Items (Targeted Testing): The auditor decides to examine 100% of transactions exceeding a predetermined dollar threshold (e.g., all capital asset acquisitions over $100,000, or all customer balances greater than performance materiality). While this tests a subset of the total population, it is testing specific items, not sampling. Items below the threshold have zero chance of selection in this procedure, and the results cannot be extrapolated to the remaining population.
- Analytical Procedures: Evaluating financial information through analysis of plausible relationships among financial and non-financial data (e.g., ratio analysis, trend comparisons, or regression models). Analytical procedures evaluate entire populations in the aggregate rather than sampling individual transactions.
- Procedures Testing Controls Without an Audit Trail: Many crucial internal controls do not leave documentary evidence of performance (e.g., observing that only authorized personnel have physical access to the server room or observing that employees adhere to clean-desk policies). Because no written record or transaction unit is generated, sampling cannot be applied.
- Walkthroughs: Tracing one or two transactions through the entire accounting system from inception to financial statement posting. The purpose of a walkthrough is to confirm the auditor's understanding of the transaction flow and design of controls, not to evaluate operating effectiveness or project a deviation rate across the population.
Comparison: Audit Sampling vs. Alternative Evidence-Gathering Methods
| Audit Method | Percentage Examined | Selection Probability | Basis for Population Inference? | AU-C 530 Applies? |
|---|---|---|---|---|
| Audit Sampling | Less than 100% | Every unit has a chance of selection | Yes: Extrapolates sample results to the population | Yes |
| 100% Examination | Exactly 100% | 100% (all units examined) | No: Directly measures population with zero sampling risk | No |
| Testing Specific Items | Less than 100% (e.g., all items > $50,000) | Only items meeting criteria have a chance; others have 0% | No: Results cannot be projected to unexamined items | No |
| Analytical Procedures | Aggregated data | Not applicable (tests aggregate relationships) | No: Evaluates balance plausibility, not individual units | No |
| Walkthrough | 1–2 items | Deliberately chosen representative transactions | No: Evaluates design/implementation, not operating rate | No |
3. Statistical vs. Non-Statistical Sampling
Auditing standards explicitly recognize and permit two general approaches to audit sampling: statistical sampling and non-statistical sampling. Both approaches are fully acceptable under GAAS, and when properly applied, both can provide sufficient appropriate audit evidence.
AUDIT SAMPLING METHODOLOGIES
|
+-----------------------------+-----------------------------+
| |
[ STATISTICAL SAMPLING ] [ NON-STATISTICAL SAMPLING ]
- Uses laws of probability - Relies on professional judgment
- Objectively calculates sample size - Sample size determined subjectively
- Quantifies sampling risk mathematically - Cannot mathematically quantify risk
- Requires random selection - Permits haphazard selection
What Makes a Sampling Approach Statistical?
Under AU-C 530, a sampling approach is classified as statistical if and only if it possesses two distinct characteristics:
- Random Selection: Sample items are selected using a probabilistic selection method (e.g., random-number tables, random-number generators, or systematic selection with a random start) such that selection bias is completely eliminated and every unit has a known probability of selection.
- Mathematical Measurement of Results: The auditor uses statistical measurement techniques (the laws of probability) to evaluate sample results, including an explicit mathematical quantification of sampling risk (precision and confidence level).
If a sampling plan lacks either of these two characteristics, it is classified as non-statistical sampling (sometimes referred to as judgmental sampling).
Comprehensive Comparison: Statistical vs. Non-Statistical Sampling
| Dimension | Statistical Sampling | Non-Statistical (Judgmental) Sampling |
|---|---|---|
| Sample Size Determination | Calculated mathematically using probability formulas and statistical tables based on specified parameters. | Determined by auditor professional judgment without formal probability formulas (similar circumstances should still produce similar sample sizes). |
| Selection Technique | Must be probabilistic (random-number or systematic selection with a random start). | Can be probabilistic, but also permits haphazard selection (selection without conscious bias). |
| Measurement of Sampling Risk | Objectively quantified in mathematical terms (e.g., 95% confidence level, 3% allowance for sampling risk). | Subjectively evaluated through auditor judgment; cannot be mathematically measured or stated. |
| Primary Advantages | - Facilitates designing an objectively efficient sample size.<br>- Quantifies the sufficiency of audit evidence obtained.<br>- Provides mathematically defensible workpapers.<br>- Protects auditor against claims of arbitrary sample sizing. | - Greater flexibility in design and execution.<br>- Lower initial training costs.<br>- Avoids time-consuming random number matching for manual paper records.<br>- Well-suited for non-complex transaction cycles. |
| Primary Disadvantages | - Higher training and software costs.<br>- Time and expense of constructing computerized sampling frames and random draws.<br>- Less flexibility when dealing with non-standard populations. | - Inability to mathematically quantify sampling risk.<br>- Risk of selecting unrepresentative or arbitrarily small samples.<br>- Vulnerable to subconscious auditor bias. |
| GAAS Permissibility | Fully permitted under AU-C 530. | Fully permitted under AU-C 530. |
The Indispensable Role of Professional Judgment
Exam Trap: A common exam misconception is that statistical sampling replaces or eliminates the need for auditor professional judgment. This is completely false! Statistical sampling is an audit tool, not a decision-maker. The auditor must exercise extensive professional judgment in:
- Defining the population and the sampling unit.
- Establishing the audit objective and identifying what constitutes a deviation or misstatement.
- Setting the tolerable deviation rate or tolerable misstatement.
- Determining the acceptable level of sampling risk (risk of overreliance or risk of incorrect acceptance).
- Estimating the expected population deviation rate or expected misstatement.
- Qualitatively analyzing the root causes of identified errors (e.g., distinguishing clerical error from intentional fraud).
4. The Nature and Anatomy of Sampling Risk
Whenever an auditor tests less than 100% of a population, a fundamental hazard arises:
Sampling Risk Defined: The risk that the auditor's conclusion based on a sample may be different from the conclusion that would be reached if the entire population were subjected to the exact same audit procedure (AU-C 530).
Sampling risk is an unavoidable consequence of sampling. It exists simply because a sample—no matter how rigorously selected—may not be perfectly representative of the population from which it was drawn. There is always a statistical probability that an uncharacteristic cluster of errors was selected, or conversely, that the errors lurking in the population were entirely bypassed by the sample.
SAMPLING RISK
|
+-----------------------------+-----------------------------+
| |
[ IN TESTS OF CONTROLS ] [ IN SUBSTANTIVE TESTING ]
| |
+---------+---------+ +---------+---------+
| | | |
OVERRELIANCE UNDERRELIANCE INCORRECT INCORRECT
(Beta / Type II) (Alpha / Type I) ACCEPTANCE REJECTION
Affects AUDIT Affects AUDIT (Beta / Type II) (Alpha / Type I)
EFFECTIVENESS EFFICIENCY Affects AUDIT Affects AUDIT
EFFECTIVENESS EFFICIENCY
Auditing standards divide sampling risk into four specific types, categorized by the nature of the audit procedure being performed:
- Two types in Tests of Controls: Risk of Overreliance and Risk of Underreliance.
- Two types in Substantive Testing: Risk of Incorrect Acceptance and Risk of Incorrect Rejection.
5. Sampling Risk in Tests of Controls
In testing the operating effectiveness of internal controls, the auditor is evaluating an attribute (the presence or absence of a control activity, such as an authorization signature or three-way matching). The auditor faces two distinct sampling risks:
1. Risk of Overreliance (Assessing Control Risk Too Low)
- The Reality vs. The Sample: The sample results indicate that the control is operating effectively (e.g., very few or zero deviations observed in the sample), when in fact the true population deviation rate exceeds the tolerable rate, meaning the control is ineffective.
- Statistical Classification: Type II Error (Beta Risk).
- Audit Impact: Directly affects AUDIT EFFECTIVENESS.
- Why it Matters: When the auditor concludes that internal controls are effective, the auditor reduces the planned extent of subsequent substantive procedures (e.g., performing fewer confirmations or testing smaller sample sizes for details of balances). Because controls are actually ineffective and substantive testing was inappropriately reduced, material misstatements in the financial statements may go completely undetected. This creates the catastrophic audit hazard of issuing an unmodified (clean) audit opinion on materially misstated financial statements.
- Auditor Mindset: The Risk of Overreliance is the auditor's primary audit concern because it directly jeopardizes the audit opinion and exposes the CPA firm to severe legal liability.
2. Risk of Underreliance (Assessing Control Risk Too High)
- The Reality vs. The Sample: The sample results indicate that the control is ineffective (e.g., several deviations happen to be captured in the sample), when in fact the true population deviation rate is low and the control is operating effectively.
- Statistical Classification: Type I Error (Alpha Risk).
- Audit Impact: Directly affects AUDIT EFFICIENCY.
- Why it Matters: When the auditor mistakenly concludes that internal controls cannot be relied upon, the auditor increases assessed control risk to maximum and unnecessarily expands substantive testing. The audit team performs far more substantive work than was actually needed. Ultimately, the correct audit conclusion is reached and the audit opinion is valid, but the engagement team wastes substantial time, drives up audit costs, and causes unnecessary client friction.
6. Sampling Risk in Substantive Testing
In performing substantive tests of details (e.g., confirming accounts receivable or testing inventory valuation), the auditor is evaluating monetary amounts (variables sampling). The auditor faces two parallel substantive sampling risks:
1. Risk of Incorrect Acceptance
- The Reality vs. The Sample: The sample results support the conclusion that the recorded account balance is not materially misstated, when in fact the population is materially misstated.
- Statistical Classification: Type II Error (Beta Risk).
- Audit Impact: Directly affects AUDIT EFFECTIVENESS.
- Why it Matters: This is the substantive twin of the Risk of Overreliance. The auditor concludes the financial statements are free of material misstatement when material errors or fraud actually exist. The auditor issues an unmodified opinion on misleading financial statements, exposing the auditor to regulatory sanction and litigation.
2. Risk of Incorrect Rejection
- The Reality vs. The Sample: The sample results support the conclusion that the recorded account balance is materially misstated, when in fact the balance is fairly stated.
- Statistical Classification: Type I Error (Alpha Risk).
- Audit Impact: Directly affects AUDIT EFFICIENCY.
- Why it Matters: When a sample indicates a material misstatement, the auditor does not immediately issue an adverse opinion. Instead, the auditor conducts extensive additional testing, expands the sample, analyzes reconciling items, and negotiates with client management. Eventually, the additional evidence demonstrates that the balance was fairly stated all along. The final audit opinion is correct, but extensive audit hours were wasted.
Comprehensive Summary: The 2x2 Sampling Risk Matrix
| Audit Testing Phase | Type I Error (Alpha Risk) | Type II Error (Beta Risk) |
|---|---|---|
| Core Dimension Affected | AUDIT EFFICIENCY (Costs more time/money) | AUDIT EFFECTIVENESS (May cause wrong opinion!) |
| Tests of Controls (Attribute Sampling) | Risk of Underreliance<br>(Assessing Control Risk Too High)<br>Sample shows control is broken, but it actually works. Auditor unnecessarily increases substantive tests. | Risk of Overreliance<br>(Assessing Control Risk Too Low)<br>Sample shows control works, but it is actually broken. Auditor inappropriately reduces substantive tests. |
| Substantive Testing (Variables Sampling) | Risk of Incorrect Rejection<br>Sample indicates balance is misstated, but it is actually fair. Auditor performs unnecessary investigations. | Risk of Incorrect Acceptance<br>Sample indicates balance is fair, but it is actually misstated. Auditor fails to detect material misstatement. |
| Auditor's Primary Concern | Secondary concern (costs firm profitability). | Primary concern (creates audit failure and litigation). |
7. Non-Sampling Risk
Sampling risk is only one component of overall audit risk. Even if an auditor examines 100% of a population, the auditor can still reach the wrong conclusion due to non-sampling risk.
Non-Sampling Risk Defined: The risk that the auditor reaches an erroneous conclusion for any reason not related to sampling risk (AU-C 530).
Unlike sampling risk, which is purely mathematical and can be quantified in statistical sampling, non-sampling risk cannot be measured mathematically.
NON-SAMPLING RISK FACTORS
|
+--------------------+--------------+--------------+--------------------+
| | | |
[ AUDITOR ERROR ] [ INAPPROPRIATE ] [ FLAWED EVIDENCE ] [ FATIGUE & BIAS ]
Failing to detect PROCEDURES Misinterpreting Rushing work near
errors present in Applying procedures audit documentation deadline; accepting
sampled documents that don't test assertion or client records flawed explanations
Primary Causes of Non-Sampling Risk
- Human Oversight & Failure to Recognize Errors: An auditor selects a voucher packet that contains an unauthorized payment or missing signature, but the auditor carelessly glances at the document, marks it as compliant, and fails to record the deviation.
- Applying Inappropriate Audit Procedures: The auditor applies an audit procedure that is not capable of achieving the audit objective (e.g., confirming accounts payable balances using vendor lists provided by the client rather than testing unrecorded liabilities via subsequent cash disbursements).
- Misinterpreting Audit Evidence: The auditor examines an ambiguous shipping document or complex contract and misinterprets its legal terms, erroneously concluding that revenue recognition criteria were met.
- Auditor Fatigue & Time Pressure: Performing repetitive audit procedures late in an engagement can lead to reduced vigilance and superficial reviews.
- Improper Reliance on Client Explanations: The auditor accepts management's uncorroborated verbal assertions regarding an anomaly without obtaining corroborating third-party documentation.
How Non-Sampling Risk is Controlled
Non-sampling risk cannot be reduced by simply increasing sample size. Increasing sample size may actually increase non-sampling risk due to auditor fatigue! Instead, non-sampling risk is controlled and minimized through:
- Thorough engagement planning and risk assessment.
- Assigning personnel with appropriate technical expertise and industry knowledge.
- Rigorous direction, supervision, and ongoing on-the-job training of audit staff.
- Detailed, multi-tiered supervisory review of all audit workpapers (senior, manager, partner, quality review partner).
- Strict adherence to the CPA firm's internal quality management standards (SQMS No. 1, codified as QM section 10).
8. Real-World Audit Scenarios & Exam Traps
Scenario 1: The Misleading Sample in Inventory Controls
An auditor tests internal controls over perpetual inventory adjustments. Management policy requires that any adjustment exceeding $5,000 must be approved in writing by the Plant Controller. The auditor selects a random sample of 60 adjustments out of 4,000 processed during the year. In the sample, all 60 adjustments have the Controller's signature. The auditor concludes that controls are operating effectively and assesses control risk at low. However, unknown to the auditor, 350 adjustments outside the sample were executed without any supervisory review because the Controller was hospitalized for two months.
- Analysis: The auditor experienced the Risk of Overreliance (Beta Risk). The sample supported control reliance, but the population was actually deficient. This affects audit effectiveness, and if the auditor reduces substantive testing of year-end inventory, inventory could be materially misstated.
Scenario 2: The Large-Item Selection Trap
During the audit of property, plant, and equipment (PP&E), an auditor examines all capital additions exceeding $250,000, which accounts for 82 additions totaling $35 million out of a total population of 1,200 additions totaling $42 million. The auditor concludes: "I performed statistical audit sampling on PP&E additions, and because no misstatements were identified, I conclude that all additions are fairly stated."
- Exam Trap: This is not audit sampling! The auditor tested specific items based on dollar magnitude. The remaining 1,118 additions totaling $7 million had a zero percent chance of selection. The auditor cannot project the sample results to the untested population under AU-C 530.
An auditor is planning audit procedures for the cash disbursement and expenditure cycle of a manufacturing client. Which of the following procedures constitutes audit sampling under AU-C 530?
An audit senior evaluates the risk of overreliance (assessing control risk too low) during tests of controls over sales order credit approvals. How does this specific sampling risk impact the audit engagement?
When choosing between statistical sampling and non-statistical sampling under AU-C 530, which of the following statements correctly identifies a fundamental characteristic of these methodologies?
During the audit of inventory, an auditor fails to notice that several selected receiving reports are dated subsequent to year-end, leading to an incorrect conclusion regarding inventory cutoff. This failure is an example of which of the following risks?