Picking an audit sample involves selecting a representative subset of data—using statistical or non-statistical methods—to draw conclusions about a larger population, focusing on high-risk areas and specific audit objectives. Effective sampling requires defining the population, determining sample size based on risk and materiality, selecting items (random, systematic, or judgmental), and documenting the process for justification.
Sample Selection
Therefore, all items in the population should have an opportunity to be selected. Random-based selection of items represents one means of obtaining such samples. Ideally, the auditor should use a selection method that has the potential for selecting items from the entire period under audit.
Sample size calculations depend on four variables: • Size of population. Degree of accuracy required. Degree of confidence required. How often you expect your audit criteria to be met.
A successful internal audit function relies on four fundamental pillars, often referred to as the “4 C's”: Competence, Confidentiality, Communication, and Collaboration. These principles guide auditors in delivering meaningful and impactful results. Let's explore each of these elements in detail.
Statistical sampling requires that sample items are selected at random so that each sampling unit has a known chance of being selected. The sampling units might be physical items (such as invoices) or monetary units. With non-statistical sampling, an auditor uses professional judgment to select the items for a sample.
3.1. Probability sampling methods
A good, robust and usable research sample is characterised by 4 key pillars:
There are five elements of a finding:
Audit evidence is critical for verifying the accuracy of financial statements and supporting auditors' opinions. Different types of audit evidence include physical examination, documentation, observations, inquiries, confirmations, analytical procedures, and reperformance.
The Big 4 are the largest accounting and auditing firms in the world: Deloitte LLP (Deloitte), PricewaterhouseCoopers (PwC), Ernst & Young (EY) and Klynveld Peat Marwick Goerdeler (KPMG). They're so big that their joint revenue in 2024 was—you guessed it—$212 billion.
For sample size estimation, researchers need to (1) provide information regarding the statistical analysis to be applied, (2) determine acceptable precision levels, (3) decide on study power, (4) specify the confidence level, and (5) determine the magnitude of practical significance differences (effect size).
Some balances, such as debt, may be tested 100% but more often, such as is the case with accounts receivable, the auditor will use sampling applications to obtain sufficient evidence to support the opinion and will not test 100% of the population.
The prominent 10-times rule suggests that the minimum sample size should be 10 times the maximum number of arrowheads pointing at a latent variable anywhere in the partial least squares path model. Despite its prominence in research practice, this rule of thumb lacks systematic validation.
Yes, a 10% sample size is often acceptable and a good rule of thumb, especially for large populations, because it generally maintains the independence assumption for statistical tests and provides decent accuracy, though a smaller margin of error or high-stakes decisions might need more, while a very small population might need to survey everyone. It's a balance between precision, cost, and population size; a sample around 10% of the population (up to about 1000) is often sufficient, even if the population is huge, as results stabilize.
The sample design
Audit selection rules are criteria that you select on the Create Audit Selection Rule page. These rules determine which expense reports are automatically selected for audit if the audit selection rule is true.
Internal Audit Reports: The 5 Cs
Criteria: What needs to be audited and why? Condition: What are the observed circumstances surrounding any issues? Consequence: How do the issues found affect the company? This might include financial, regulatory, security, publicity, or other effects.
Physical Evidence
This type of evidence is tangible and as a result, it is the most reliable and persuasive form of evidence that can be used in any internal and external audit. Such evidence can be: Counted. Inspected.
An audit checklist may be a document or tool that to facilitate an audit programme which contains documented information such as the scope of the audit, evidence collection, audit tests and methods, analysis of the results as well as the conclusion and follow up actions such as corrective and preventive actions.
For reports to help your team in any situation, they have to be clear, concise, complete, consistent, and courteous.
The document outlines the 7 E's—Effectiveness, Efficiency, Economy, Excellence, Ethics, Equity, and Ecology—as essential themes for auditors to enhance organizational success.
There are a number of ways to select a sample. The most important consideration is to make the sample as representative as possible of the population. The best way to do this is to randomly choose the sample, and be aware of the possible sources of bias.
The golden rule is: the larger your sample size, the more reliable and valid your results are likely to be.