Skip to content

Audit Sampling

VIVA Subject Guide

1 Introduction

YouTube video

Unless an audit client is very small almost all audit 'testing' relies on sampling. This is because there simply isn’t time to examine all documents, transactions and balances and it wouldn’t be economically viable to do so. If, however, valid statistical conclusions are to be drawn about a population based on a sample, then the sample must be free from bias. In other words every document, transaction or balance in the population has an equal chance of being included in the sample. This is known as audit sampling.

2 Audit sampling

The process involves:

  • Sample design – includes specify the population (is it complete?)

  • Sample size – must be sufficient to reduce sampling risk (as explained in Chapter 9)

  • Sample selection – choose a selection method (see below)

  • Performing audit procedures – test the selected items. This will be either a test of controls or a test of details (a substantive procedure).

  • Evaluate sample results – investigate all ‘errors’ (see later) and conclude on the population.

In statistical sampling:

  • Sample selection must be regarded as random, and

  • Probability theory must be used to evaluate sample results including measurement of sampling risk (which will determine the sample size).

If either of these conditions is not met, sampling is non-statistical.

3 Selection methods

  • Random selection. The best way to remove bias and to obtain a representative sample is to adopt what’s called random selection. Let’s say we wanted to look at purchase invoices throughout the year. There might be 20,000 purchase invoices and we want to inspect 20 of them. What you would do is to number the 20,000 invoices consecutively and then use a random number generator to produce 20 numbers and you would then go and look at the corresponding invoices. The difficulty with this approach is that very often the population is not pre-numbered and to set out initially numbering all 20,000 invoices would be very time-consuming.

  • Systematic ('interval') selection. This is an approximation to pure random selection. Again, if with 20,000 invoices you wanted to look at about 20 invoices you could do that by looking at every 1,000th invoice. So what you would do is that near the beginning of the population you would choose an invoice at random and then count through selecting every 1,000th one. Provided there isn’t some weird correspondence of every 1,000th invoice being from exactly the same supplier, you are going to get pretty close to random selection.

  • Haphazard selection. This is frequently used because it is convenient. For example, the auditor opening a file at random and picking the invoice at which the file is opened. There can be obvious problems with this. The file might always open at a slightly thicker invoice or a slightly larger invoice and that invoice could be from the same small group of suppliers. There might be a relatively small chance of the physically small invoice being chosen. There is also a risk of bias. The auditor may, consciously or unconsciously pick out invoices which appear to be correct (so quickly dealt with) or 'more interesting' (perhaps more likely to have an error). The sample is therefore unlikely to be representative, so cannot be used in statistical sampling.

  • Block selection. For example choosing 20 invoices all in a sequence. Depending on how they are filed, they could all be from the same supplier or may be from different suppliers, but all with the same date. This is not a representative sample. (Clearly it would not be possible in a test of control to conclude on the effectiveness of controls throughout the period.)

  • Stratification. If we know that there are 20,000 invoices, 10 of those are above 100,000 then it might make sense to make sure we choose at least all of those 10 invoices plus another 10 chosen randomly. Stratification means dividing your population into different sub-populations ('layers') with similar characteristics (usually monetary amount). The results of testing each layer must be separately evaluated.

  • Value-weighted selection. This is used in monetary unit sampling and is rather more complex as described on the next page.

4 Monetary unit sampling

Monetary unit sampling uses a form of interval selection but based on monetary amounts (hence 'value-weighted selection'). Here is an illustration, but note that you will not be expected to apply this (or indeed any selection method) in the exam.

Invoice value
($)

Cumulative invoice value
($)

Working

80

80

70

150

5,000/4 = 1,250

400

550

90

640

Choose first at random – say, 605

1,600

2,240

Then: 1,855 ( = 605 + 1,250)

20

2,260

700

2,960

50

3,010

1,010

4,020

Then: 3,105 ( = 1,855 + 1,250)

80

4,100

30

4,130

600

4,730

Then: 4,355 ( = 3,105 + 1,250)

380

5,110

What we have is a list of say customer invoices 80, 70, 400, 90, all the way down to 380.

The right hand column of the table is a cumulative total, so the first one is 80, then 80 plus 70 is 150, 150 plus 400 is 550, 550 plus 90 is 640, so our total receivables is 5110.

We want to look at four invoices out of these receivables. So you take the total, and if we round it to 5,000 and divide by 4 that give 1,250. Choose the first interval at random, here is say 605, and then go up 1,250 at a time. So after 605 plus 1,250 will be 1,855, plus 1,250 will be 3,105, plus 1,250 will be 4,355 and you see where a cumulative total of those values lies. So 1,855 falls within the cumulative total of 2,240 and that corresponds to the invoice value 1,600. The next one 3,105 falls within the cumulative 4,020 and that corresponds to the invoice with value 1,010.

What this process does is increase the chance of selecting higher value transactions. This will direct testing to where there is the greatest potential for misstatement. Note that any invoice value which exceeds the interval (here only 1,600) is guaranteed to be selected. This also has the effect of stratifying the population.

5 Evaluate sample results

Sampling is not complete when the selected items have simply been tested. Consider whether detected errors should be projected, whether their nature or cause suggests a wider issue, whether the sample remains representative, and whether further work is needed.

When a test of controls is performed, there is a binary outcome for each item selected – either the control was applied (effective) or it was not (a ‘deviation’). What proportion of deviations can be accepted and still conclude that the control was effective? Say 2%. Suppose that the deviation rate in the sample is 4%.

  • We would first need to consider the reasons for the deviations. Perhaps some are anomalous (i.e. not representative of the population) for example, if a purchase invoice was not signed as authorised for payment because the manager was in hospital on that date.

  • If, excluding the anomalous errors, the deviation rate is still more than 2%, we could increase the sample size. If the deviation rate in the bigger sample is not more than 2% – fine. But if more than 2%, we cannot rely on the control (as planned) and will have to perform additional substantive audit procedures.

For a test of details, which is concerned with the monetary amounts of selected items, any misstatements found can be quantified.

For example, total purchases are $800,000 and the total amount of the sample is $270,000. Suppose we are prepared to accept an error in the population of not more than $16,000 (i.e. 2% of population). Errors in the sample total $5,600. Investigation shows that $1,500 is an isolated error (anomaly) and $4,100 are due to overpricing.

The error in the population can be projected as:

Projected error

= actual error × population ($) ÷ sample ($)

= $4,100 × $(800,000 – 1,500) ÷ $270,000

= $12,125
(the ‘ratio method’)

Total potential misstatement is therefore $13,625 (1,500 + 12,125). As this is less than $16,000, we can conclude that purchases are not materially overstated (with whatever degree of confidence determined the sample size).

If, however, we had been prepared to accept an error in the population of not more than $8,000 (i.e. 1%), clearly some correction is needed. If management agrees to make the corrections for all the errors identified, the remaining potential error is $8,025 (13,625 – 5,600). Now we need to exercise professional judgment – we might decide we can accept this (just) or extend the test on a larger sample.

Practice questions

Audit evidence and assertions

10 questions

Answer the questions one at a time. Your progress is saved so you can leave and come back.

Open chapter practice