Audit Sampling Methodologies in ISMS Auditing

Key Takeaways

  • Audit sampling involves evaluating less than 100% of a population of items (e.g., access tickets, firewall changes) to form a reasonable conclusion about the entire population.
  • ISO 19011 Annex 3 recognizes two main sampling approaches: Judgemental (non-statistical) sampling based on auditor knowledge/risk, and Statistical sampling based on mathematical probability.
  • Sample size determination depends on control execution frequency, population volume, inherent security risk, and tolerable error thresholds.
  • Sampling risk represents the possibility that the auditor's conclusion based on a sample differs from the conclusion that would be reached if the entire population were audited.
  • Multi-site sampling formulas (such as $y = \sqrt{x}$ under IAF MD 1) allow certification bodies to audit a representative sample of sites while ensuring full ISMS scope coverage.
Last updated: July 2026

Audit Sampling Methodologies in ISMS Auditing

In modern organizations, information security processes generate vast volumes of operational data. A large enterprise may process 50,000 user identity requests, implement 10,000 firewall change tickets, and generate millions of event log entries annually. Auditing 100% of these records is physically impossible and economically unfeasible. Therefore, auditors rely on audit sampling to gather sufficient, representative evidence to draw valid audit conclusions.

Governed by ISO 19011:2018 (Annex 3), audit sampling is defined as the application of audit procedures to less than 100% of the items within a population of audit relevance. To maintain audit credibility, the Lead Auditor must select sampling methodologies that minimize sampling risk—the risk that the auditor's sample-based conclusion is different from the conclusion that would be reached if the entire population were subjected to the same audit procedure.


1. Judgemental vs. Statistical Sampling

ISO 19011 categorizes audit sampling into two primary approaches: Judgemental (Non-Statistical) Sampling and Statistical Sampling.

Comparison of Sampling Methodologies

AttributeJudgemental (Non-Statistical) SamplingStatistical Sampling
Selection BasisAuditor knowledge, professional judgement, risk assessment, and contextual experience.Random selection based on mathematical probability theory (e.g., simple random, systematic).
Sample RepresentativenessFocused on high-risk, complex, or historically problem-prone items.Scientifically representative of the entire numerical population.
Quantifiable Sampling RiskCannot be mathematically measured or expressed in statistical confidence intervals.Quantifiable using mathematical formulas (e.g., 95% confidence level with 5% margin of error).
Best Used WhenEvaluating qualitative controls, complex policy compliance, or small populations.Auditing large, homogeneous populations of quantitative records (e.g., 100,000 access logs).
Primary LimitationSusceptible to auditor bias; findings cannot be mathematically extrapolated to the full population.Requires larger sample sizes; may miss qualitative context or deliberate high-risk anomalies.

2. Sample Size Selection Guidelines

When conducting judgemental sampling of operational control execution, auditors determine sample sizes based on control frequency and risk level. The table below represents the standard sample size guidance accepted under PECB Lead Auditor guidelines and international auditing practices:

Control Execution FrequencyTotal Annual Population VolumeRecommended Minimum Sample Size (Low/Moderate Risk)Recommended Minimum Sample Size (High Risk / Critical Control)
Annual (e.g., Strategy review, annual penetration test)11 (100% testing)1 (100% testing)
Quarterly (e.g., Access reviews, firewall rule reviews)424 (100% testing)
Monthly (e.g., Patch management cycles, backup restores)122–35–6
Weekly (e.g., Vulnerability scans, facility inspections)52510–15
Daily (e.g., Media disposal logs, visitor entries)~250–36515–2025–40
Automated / Continuous (e.g., Identity creation, change tickets)1,000+25–3045–60

3. Multi-Site Sampling Framework (IAF MD 1 / ISO/IEC 17021-1)

When an organization operates multiple operational locations under a single centralized ISMS (e.g., a retail chain with 100 branch offices or a logistics provider with 50 warehouses), certification bodies apply multi-site sampling rules defined in IAF MD 1.

Eligibility Criteria for Multi-Site Sampling

  1. All sites operate under a single, centrally managed and administered ISMS.
  2. All sites are subject to central management review and internal audit programs.
  3. All sites follow uniform security policies, procedures, and control frameworks.

Mathematical Sampling Formulas

For a normal risk profile, the minimum number of sites to be sampled per audit cycle is calculated using the square-root formula:

Sample Size (y)=x\text{Sample Size } (y) = \sqrt{x}

Where $x$ is the total number of operational sites.

  • Normal Risk: $y = \sqrt{x}$ (rounded up to the next whole number).
  • High Risk / Complex Operations: $y = 1.2 \sqrt{x}$.
  • Low Risk / Simplified Operations: $y = 0.6 \sqrt{x}$.

Example: For an organization with $x = 49$ identical branch offices operating under a single central ISMS, the Lead Auditor must sample at least $y = \sqrt{49} = 7$ sites during the certification audit.


4. Managing Sampling Risk and Exception Handling

Sampling risk manifests in two dangerous forms:

  1. Risk of Incorrect Acceptance (Beta Risk): The auditor concludes a control is effective based on a sample when, in reality, the population contains unacceptable nonconformities. (High security impact).
  2. Risk of Incorrect Rejection (Alpha Risk): The auditor concludes a control is ineffective based on an unrepresentative bad sample when the overall population is compliant. (Efficiency impact).

The Auditor's Exception Rule

If an auditor selects a sample of 25 items and encounters one single nonconformity (exception), the auditor must NOT simply ignore it as an anomaly. The Lead Auditor must take one of two actions:

  • Expand the Sample: Double the sample size (e.g., test an additional 25 items) to determine whether the exception was an isolated incident or systemic failure.
  • Investigate Root Cause: Require the auditee to explain the specific breakdown before determining whether to issue a Minor or Major Nonconformity.

5. Worked Scenario: Sampling User Off-Boarding Access Revocations

Background

Lead Auditor Nathan was evaluating Annex A 6.5 (Responsibilities after termination or change of employment) and Annex A 8.2 (Privileged access rights) at Global Logistics Corp. The HR termination log showed that 400 employees departed the company during the 12-month audit period.

Sampling Plan Execution

  1. Determining Sample Size: Applying the sample size matrix for continuous/frequent manual controls, Nathan selected a initial sample size of 30 terminated employee records using systematic random sampling across all four quarterly HR termination reports.
  2. Audit Requirement: Company policy mandated that all network, VPN, and application access must be revoked within 24 hours of the employee's official termination date.

Testing Results & Sample Expansion

  • Out of the 30 sampled records, 27 records showed full access revocation executed within 12 to 18 hours.
  • However, records #14 and #22 showed that access to the production ERP system remained active for 14 days and 30 days post-termination, respectively. Record #22 belonged to a departed IT Administrator who had logged into the ERP system 5 days after leaving the company.

Auditor Decision

Because two severe exceptions were identified in the initial sample of 30, Nathan expanded the sample by an additional 30 records (totaling 60 records).

  • In the expanded sample of 30 additional records, Nathan identified 5 additional instances of delayed access revocation exceeding 15 days.

Conclusion

The expanded sample proved that the exception was not an isolated error, but a systemic control breakdown between HR notification and IT access management. Nathan documented a Major Nonconformity against Clause 8.1 (Operational planning and control) and Annex A 6.5, citing a 11.6% failure rate across the total sample of 60 records.

Test Your Knowledge

Under ISO 19011, what is the primary distinction between judgemental sampling and statistical sampling?

A
B
C
D
Test Your Knowledge

An organization operates 64 identical retail store locations under a single centralized ISMS. Applying the standard IAF MD 1 multi-site normal risk sampling formula (y = sqrt(x)), how many sites must the certification audit team sample?

A
B
C
D
Test Your Knowledge

If an auditor selects a sample of 25 user access change tickets and discovers one nonconformity, what is the correct immediate response under ISO 19011 guidelines?

A
B
C
D