Audit Fundamentals explores the principles, standards, and real-world practices behind accounting and auditing. Each episode breaks down essential audit topics — including risk assessment, internal controls, audit evidence, financial reporting, and professional standards — through practical conversations and clear explanations that make complex concepts easier to understand.
Attention: This is a machine-generated transcript. As such, there may be spelling, grammar, and accuracy errors throughout. Thank you for your understanding!
Meredith Mednick, CPA, CA: [00:00:00] Picture this. It's your first busy season. You're sitting at a client's office and you've got a stack of invoices in front of you. Or maybe it's a full folder full of PDFs, and your senior auditor walks over and says, hey, we need you to pull a sample of accounts payable transactions for testing. You nod confidently. You say, sure, absolutely. And then the senior walks away and you think, wait, what does that actually mean? How many do I pick? Which ones? And what am I even looking for? If that scenario sounds familiar, or if you want to be ready before that moment even arrives, you're in exactly the right place. Welcome to Audit Fundamentals. I'm your host, Meredith Mednick, CPA, and today we are doing a deep dive into one of the most foundational and most understood tools in the auditor's toolkit audit sampling. Whether you just started at a firm last month or you're heading into your second or third busy season and still feel a little shaky on the mechanics, this episode is for you. Here's what we're going to cover today. We'll explain what audit sampling is, why we use it, and how it fits into our professional standards. Distinguish between statistical and non-statistical sampling and know when to use each approach. We'll identify the main sample selection methods and understand the advantages and disadvantages of each. Apply key concepts like tolerable misstatement, tolerable deviation rate, and sampling risk to real world decisions. We'll walk through the full sampling process from designing the sample all the way to evaluating results and documenting your conclusions, and understand how sampling results influence your overall audit conclusions.
Meredith Mednick, CPA, CA: [00:02:07] That's a lot, but I promise we're going to take it slow and step by step. And we've got a running example with a fictional client to keep everything grounded. Don't forget, after listening to the episode, head to earmark.app and take a short quiz to earn your CPE. All right, let's get into it. Let's start with the most basic question what is audit sampling, and why do we even do it when we're auditing a company's financial statements? Our ultimate goal is to gather enough evidence to form an opinion on whether those statements are fairly presented. But here's the thing. Most clients have thousands, sometimes hundreds of thousands of transactions. Testing every single one of them would be impractical. It would take forever, cost an enormous amount of money, and frankly, it wouldn't change the conclusion we'd reach by testing a well-designed sample. So instead, we apply audit procedures to less than 100% of items in a population, and we use the results to draw conclusions about the entire population. That is what we call audit sampling. Now, and this is important. Not everything we do in an audit is sampling. If you're reviewing a single large contract or you're testing the one journal entry that represents 40% of the company's revenue, that's not sampling, that's testing specific items.
Meredith Mednick, CPA, CA: [00:03:31] Sampling, by definition, involves an expectation that the result can be projected to the population as a whole. The professional standard that governs audit sampling is AUC. Section 5.3 audit sampling issued by the AICPA. This is the authoritative guidance for audits conducted under generally accepted auditing standards or gas. If your firm works on international engagements, there's a parallel standard Isa 530, which is substantially similar. I'm not going to read the standard verbatim, but throughout this episode, I'll point out where the key requirements from AUC 530 come into play. And at the end, I'll tell you exactly where to go to read the full standards yourself. So audit sampling exists because it's both practical and statistically defensible when designed and executed properly. It allows us to gather sufficient appropriate audit evidence without examining every single transaction. That's the why. Now let's talk about the when. Before we go further, we need to understand that audit sampling doesn't apply to every type of audit procedure. There are basically two situations when you use sampling. The first is test of controls. These are procedures we use to evaluate whether the client's internal controls are operating effectively. For example, testing whether purchase orders are being properly approved before a payment is made. The second is substantive tests of details. These are procedures designed to detect material misstatements and account balances or transactions. For example, testing whether the amounts recorded in accounts payable actually agree to the underlying vendor invoices.
Meredith Mednick, CPA, CA: [00:05:22] Now, here's something that trips up auditors all the time. Not all audit procedures involve sampling analytical procedures, like comparing this year's expenses to last year's don't involve sampling. Risk assessment procedures don't typically involve sampling, either, and testing 100% of a population or selecting specific high risk items isn't sampling. In the technical sense. Sampling comes into play when you're testing a subset of a population with the intent to draw conclusions about the whole thing, that's your anchor definition. All right. Let's meet our fictional client. Maple Ridge Manufacturing. Maple Ridge is a mid-size manufacturer of industrial components. Approximately $85 million in revenue publicly held. And their fiscal year end is December 31st. Throughout this episode, we're going to use Maple Ridge as our running example. Whenever I introduce a new concept, we'll see how it would play out on their audit. Here's the scenario. The audit team is testing accounts payable for the year ended December 31st. There are approximately 4200 accounts payable transactions during the year, totaling about $62 million. The team has already assessed risk and determined that accounts payable is a significant account requiring detailed testing. Keep Maple Ridge in your head. We'll come back to them a lot. Okay, now we get into one of the most important distinctions in audit sampling, statistical versus non statistical sampling. Here's a quick reflection question before I explain. Think about what you already know or believe. If statistical sampling involves math and formulas and non statistical sampling doesn't, does that mean non statistical sampling is less rigorous less professional less valid.
Meredith Mednick, CPA, CA: [00:07:19] Let's define our terms. Statistical sampling is a method that uses random selection combined with probability theory to evaluate the results. Because the sample is randomly selected and results are mathematically evaluated, statistical sampling allows you to measure sampling risk. What is sampling risk? That's the risk that your sample doesn't reflect what's actually in the population. We'll talk more about sampling risk in a few minutes. And Non-statistical sampling, sometimes called judgmental sampling, uses the auditor's professional judgment both to select the sample and to evaluate the results. It doesn't rely on probability theory, and it doesn't mathematically quantify sampling risk. Let's go back to our reflection question. Is Non-statistical sampling less rigorous or less valid? The answer is not necessarily. Auc 530 explicitly states that both approaches, statistical and non-statistical can provide sufficient audit evidence when properly applied. The key words are when properly applied, Non-statistical sampling requires well documented professional judgment. It's not an excuse to grab invoices at random and call it a day. What Non-statistical sampling cannot do is mathematically quantify sampling risk. That's the trade off. Let's talk about when to use each. Statistical sampling tends to be used when the population is large and homogeneous. We want to objectively quantify and control sampling risk. Regulators or other stakeholders require a more rigorous, defensible methodology. Non-statistical sampling tends to be used when the population is smaller or more complex.
Meredith Mednick, CPA, CA: [00:09:14] Auditor judgment about risk and significance is central to sample design and efficiency matters, and the added rigor of statistical sampling isn't necessary given other audit work. Here's the practical reality many firms use non-statistical sampling for a significant portion of their work, especially on smaller engagements, because it's efficient and, when properly documented, meets professional standards on larger, more complex engagements, especially public company audits, you'll see more statistical sampling. Let's head back to Maple Ridge. With 4200 transactions and $62 million on the line. The audit team has decided to use statistical sampling for their accounts payable testing. The population is large enough to make it worthwhile, and the firm has a standardized methodology. They apply consistently. Now let's talk about how you actually pick the items to test. There are several sample selection methods, and the method you choose affects whether your results can be statistically evaluated. Method one is random selection. This is exactly what it sounds like. Every item in the population has an equal chance of being selected. You typically use random number generator or audit software to do this. Random selection is a requirement if you're using statistical sampling. You can't have statistical sampling without random selection, because the math only works if the sample was randomly drawn. Method two is systematic selection, which is sometimes called interval selection or every nth selection. You determine a sampling interval, let's say every 20th transaction, and then randomly select a starting point and pick every 20th line item from there.
Meredith Mednick, CPA, CA: [00:11:04] This is still considered random because of that random starting point, and it's frequently used in statistical sampling. Method three haphazard selection. This is where the auditor selects items without any structured technique, but also without intentional bias. In other words, you're not deliberately choosing items because they look interesting or because they're easy to access. Haphazard selection is used in non-statistical sampling and the last method. Method four is block selection. You select a block of consecutive items. For example, all transactions from October 1st through October 31st. Block selection is generally not recommended as a standalone method, because an entire block might share common characteristics that don't represent the whole population. It's the weakest selection method and should only be used with significant caution. Let's translate all of this to Maple Ridge. The audit team is using statistical sampling. They've pulled a complete population of all 4200 transactions and assigned each one a sequential number. Then they use their audit software to randomly generate a list of transaction numbers to test clean. Systematic. Defensible. If they were using non statistical sampling, they might use haphazard selection. Going through the population and selecting items without a deliberate pattern. They might also supplement that with specific high risk items they want to test regardless of the sample. Another reflection question. If your senior asks you to pull a sample and doesn't specify a method, what questions should you ask before you start selecting items? Think about it for a moment.
Meredith Mednick, CPA, CA: [00:12:52] What would you need to know? You'd want to know. Are we using statistical or non-statistical sampling? What's our selection method? Has the population been defined and is it complete? And is there a firm methodology guide I should be following? Remember those four questions? It will save you a lot of rework. Write them down. One of the first questions new auditors usually ask is how do I know how many items to test? The answer is it depends. That's not a cop out. It really does depend on several factors. Let me walk you through the main ones. The first factor is risk. The higher the assessed risk of material misstatement, the larger your sample needs to be. If Maple Ridge is accounts payable has a high inherent risk, maybe because there's been a lot of vendor turnover and the approval process has been inconsistent. You need more evidence. More evidence means more sample items. Conversely, if controls have been assessed as strong and operating effectively, the required sample size for substantive testing might be smaller. The second factor is tolerable misstatement. This is the maximum amount of misstatement in the account being tested that would still allow you to conclude the financial statements are fairly presented. It's derived from your overall materiality for the engagement. Here's the relationship you need to know and remember. Tolerable misstatement and sample size move in opposite directions. The lower your tolerable misstatement, the larger your sample size needs to be.
Meredith Mednick, CPA, CA: [00:14:35] Because if you have a very low threshold for what you tolerate, you need to be more precise and precision requires more data points. For Maple Ridge, let's say the engagement team has set overall materiality at $1.2 million, and tolerable misstatement for accounts payable is at $900,000. That's the maximum error they'd be willing to accept before concluding the balance might be misstatement. The third factor is expected misstatement. If you expect to find a lot of errors, maybe because last year's audit found several misstatements, you need a larger sample to account for that variability. If you expect very few or no errors, you can work with a smaller sample size. Factor four is the tolerable deviation rate for tests of controls. For tests of controls instead of dollars, we're thinking about rates. How often is the control failing? The tolerable deviation rate is the maximum rate of control failures you'd accept and still rely on the control. The expected deviation rate is what you expect to actually find based on prior experience or inquiry. Let's go back to Maple Ridge for a minute. For their purchase order approval control, let's say the tolerable deviation rate is 5%. That means if more than 5% of transactions were processed without proper approval, you cannot rely on that control. The team expects to find a deviation rate of about 1% based on prior year results. That gap between expected the 1% and tolerable 5% gives you room to work with, and it directly affects how many items you need to test.
Meredith Mednick, CPA, CA: [00:16:21] I know that was a lot of variables, but here's the practical truth. Most firms have standardized tables or software tools that calculate your required sample size once you input these variables. You won't be doing this math from scratch at 10 p.m. during busy season. However, you need to understand what's driving the numbers so you can have an intelligent conversation with your team about sample design and so you can catch it when something doesn't look right. Okay, we are about halfway through our episode, and I want to pause to recap what we've covered before we push into execution. Here's where we've been. One audit sampling is the application of audit procedures to less than 100% of a population, with the intent of drawing conclusions about the whole. It's governed by AUC section 532. Sampling applies to tests of controls and substantive tests of details. Not all audit procedures involve sampling. Three statistical sampling uses random selection and probability theory to mathematically quantify sampling risk. Non-statistical sampling relies on professional judgment. Both are valid when properly applied for the main selection. Methods are random, systematic, haphazard, and block. Random and systematic methods are required for statistical sampling. Five. Sample size is driven by risk, tolerable misstatement or deviation rate and expected misstatement or deviation rate. Higher risk and lower tolerance means bigger samples. Take a breath. That foundational layer is going to make everything in the second half.
Meredith Mednick, CPA, CA: [00:18:09] Click. Now let's get into the actual execution of sampling. This is where it gets really practical. You've designed your sample. You know your method, your size and your population. Now it's time to actually do the work. Step one we need to define the population precisely. This sounds obvious, but it's a common source of errors. The population needs to be complete, appropriately defined, and directly related to what you're testing. For example, if you're testing whether accounts payable balances are properly valued, your population should be the recorded accounts payable balance, not just invoices received, not just paid items. Make sure the population you're sampling from actually matches your audit objective. Step two identify individually significant items. Before you define your sample, you should separate out any items that, because of their size, nature, or risk you want to test individually outside of the sample. Auc 530 is clear about this. These might be the top vendors by dollar amount or any transaction above a certain threshold for Maple Ridge. Let's say the team identifies 12 transactions that are each over 500,000. Those are tested when 100%, they are not part of the sample. The remaining population of 4188 transactions is what the statistical sample is drawn from. Step three select and test the sample. Once you've got your randomly selected list, you go get the evidence for accounts payable. That might mean pulling the original invoices, the purchase order and the receiving report, and agreeing these three together.
Meredith Mednick, CPA, CA: [00:19:59] You document your procedure and your findings for each item tested. Step four investigate exceptions. If you find an error, a deviation, or an exception, don't just note it and move on. You need to understand the nature of the error. Is it a one time mistake or does it suggest a systematic problem? Is it intentional? Does it affect other accounts? Let's go back to Maple Ridge. The team has selected a sample of 60 accounts payable transactions from the remaining population of 4188. As they work through the sample, they find three items where the invoice amount doesn't agree to what was recorded. Small differences, each under $5,000. They investigate and determine these were data entry errors, not systemic and not intentional. They note them as misstatements in the working papers. The question now becomes what do we do with all of these errors? Evaluating the results is where a lot of auditors get nervous. You found some errors. Now what? Here's what we do. The first step. We project the misstatement to the population. If you found errors in your sample, you can't just look at the dollar amount of those specific errors you need to project what the error rate implies about the full population. For example, if you tested 60 transactions out of 4188 and found $12,000 in misstatements, you'd project that to the whole population. Roughly speaking, the ratio of errors to your sample applied to the full population dollar value gives you the projected misstatement.
Meredith Mednick, CPA, CA: [00:21:43] Your audit software will handle the calculation. But this concept is essential. Step two compare to the tolerable misstatement. If the projected misstatement is significantly below your tolerable misstatement and you have a reasonable cushion, you may be able to conclude that the balance is not materially misstated. If the projected misstatement is close to or exceeds the tolerable misstatement, you have a problem. You need to either expand the testing request that the client investigate and correct the errors, or modify your audit. Conclusion. Let's bring it back to Maple Ridge. Let's say the team projects the $12,000 in sample errors to a population level misstatement of about $75,000. Remember, our tolerable misstatement is 900,000. $75,000 is well within tolerance. Not even close. Combined with the nature of the errors, isolated data entry mistakes not systemic, the team concludes the accounts payable balance is not materially misstated. What would you do if the projected misstatement came back at $850,000, close to but just under your tolerable misstatement of $900,000? You're technically within tolerance, but does that feel like a clean conclusion? What would you do next? This is where professional judgment comes in. Technically, $50,000 is within the tolerable misstatement level. But being that close without much cushion should make you uncomfortable. You'd want to have a conversation with your senior or manager. You might expand testing. You might ask the client to investigate the errors, because you also need to consider that accounts payable might not be the only account with misstatements.
Meredith Mednick, CPA, CA: [00:23:35] The cumulative effect across all the accounts matters to a $900,000 tolerable misstatement for AP doesn't mean $850,000 in accounts payable. Misstatements is perfectly fine if revenue also has a $700,000 in projected errors. Before we move on to documentation, let's address a concept that's really important and often confused. Sampling risk versus non-sampling risk. Sampling risk is the risk that your sample based conclusion differs from the conclusion you'd reach if you tested the entire population. It's an inherent limitation of sampling. You can never completely eliminate it, but statistical sampling lets you measure and control it. In practice, auditors often target a 5% or 10% level of sampling risk, depending on the context. There are two types of sampling risk that matter in practice for tests of controls, the risk of overreliance, which is concluding that a control is effective when it actually isn't. This is the dangerous one. If you over rely on a control that's broken, you might not do enough substantive testing and you could miss a material misstatement for substantive tests. The risk of incorrect acceptance, which is concluding that a balance is fairly stated when it actually is materially misstated. Again, this is the risky direction for audit quality. Let's move to non-sampling risk, which is totally different. It's not about your sample at all. It's about everything else that could go wrong. Misapplying an audit procedure, misinterpreting evidence, using an inappropriate procedure, or just making a mistake in execution.
Meredith Mednick, CPA, CA: [00:25:24] Non-sampling risk cannot be measured statistically, and the way you control it is through quality control, supervision, review, training and following your firm's methodology. Here's a quick way to remember the difference. Sampling risk is I tested the right things but got unlucky with which ones I picked. Non-sampling risk is I picked fine, but I messed up the testing. Both can lead to audit failures, which is why they both matter. Let's talk about documentation. The thing that proves you did all this work in a way that can be reviewed, inspected, and defended. Auc 530 requires that when audit sampling is used, the auditor document one how the sampling method was applied, including the basis for sample size two the items selected for testing and the results. Three the auditor's evaluation of the results, including the projected misstatement or deviation rate, and four the auditor's conclusion about whether the audit objective was achieved. What does this look like in practice? Most firms have standardized sampling workpapers templates in their audit software that guide you through all of these requirements. Your job is to fill them out completely, clearly, and accurately. A few things I'd like to highlight. Document your population clearly. What it includes, what it excludes, and why. If you removed individually significant items. Explain that and document the rationale. Document any exceptions thoroughly what the error was, what you did to investigate what you concluded and how it was resolved, and always document your conclusion.
Meredith Mednick, CPA, CA: [00:27:11] Don't just show the math. Explain in plain language what the results mean for the audit objective. A reviewer should be able to read your work paper and understand your conclusion without hunting for it. Let's bring it back to Maple Ridge. The accounts payable sampling work paper would show the full population of 4188 transactions, after removing the 12 individually significant items. The random selection methodology. The 60 items tested. The three exceptions found the investigation of each exception, the projected misstatement of $75,000, and our conclusion that the accounts payable balance is not materially misstated. Clean, complete and defensible. So now you might be wondering, how does this all connect to the big picture, which is the audit opinion? Everything we've talked about so far, all of this careful sampling work feeds into the auditors overall conclusion about the financial statements. After all the testing is done, the engagement partner will look at the aggregate of all identified misstatements, both from sampling and from other procedures, and will compare them to overall materiality. If identified and projected, misstatements individually and in the aggregate are below materiality and there are no other significant concerns. The audit team can support an unmodified opinion, which is a clean opinion. If they're above materiality or if there is significant uncertainty, the audit opinion would need to reflect that, potentially through a qualified or adverse opinion, or by requiring the client to correct the errors before the opinion is issued.
Meredith Mednick, CPA, CA: [00:28:56] The point is, your sampling work isn't just paper work, it's a critical piece of the evidentiary Foundation for the opinion. The firm signs its name to every sample you design carefully, every exception you investigate thoroughly, every conclusion you document clearly, it all matters. That's not meant to add pressure. It's meant to give you context for why this stuff is worth learning. Well, all right, we've covered a lot of ground today. Let me leave you with what I think are the key takeaways. One audit sampling is the application of audit procedures to less than 100% of a population used to draw conclusions about the whole. It applies to tests of controls and substantive tests of details. Two both statistical and non-statistical sampling are valid under AUC. 530 when properly applied, statistical sampling quantifies sampling risk through probability theory. Non-statistical sampling relies on well documented professional judgment. Three. Your selection method matters. Random and systematic methods support statistical sampling. Haphazard selection is used for non-statistical. Block selection alone is generally not appropriate for. Sample size is driven by risk, tolerable misstatement or deviation rate and expected errors. Higher risk and lower tolerance require larger samples. Five. Always project sample errors to the population before drawing conclusions. Compare projected misstatements to tolerable misstatement, not just the errors you found in the sample. Six. Sampling risk is the risk that your sample based conclusion differs from the full population. Conclusion. Non-sampling risk covers everything else.
Meredith Mednick, CPA, CA: [00:30:52] Procedures. Judgment. Execution. Remember to control both of those. Us seven. Document everything. Population. Definition. Selection. Method. Results. Exceptions. Projections and conclusion. And plain language. So that anybody who's following along your working paper can understand your conclusions and the work that you did. Eight. Your sampling work matters. It is the evidentiary foundation for the audit opinion. Before wrapping up today's episode, I want you to know where to go if you want to dig deeper. First, you should read AUC section 530 directly. You can find it from the AICPA. It's not as intimidating as it sounds. And now that you have this context, it's going to make a lot more sense. Two. Ask your firm about its audit methodology guide. Every firm has one, and most have standardized sampling approaches and templates. Understanding your firm's specific methodology is essential. The standard set the floor. Your firm's methodology may be more prescriptive. Three. Practice. The next time you're on an engagement and your senior asks you to pull a sample, engage with the. Why. Ask what method you're using. Understand the population. Review the exceptions carefully. That's how this knowledge turns into real skill. Thank you so much for spending this time with me today. I'm Meredith Mednick and this has been audit fundamentals. To claim your CPE credit for this episode, make sure you complete the quiz@earmark.app. You've put in the time. Now go get the credit. Until next time, keep asking good questions. Document your work and trust the process. You've got this.