How do you evaluate the results of a control test sample?
Intermediate
Count the deviations (control failures) in the sample, compute the sample deviation rate, and for statistical sampling determine the upper deviation rate (adding an allowance for sampling risk). If the upper deviation rate is at or below the tolerable rate, the auditor may rely on the control; if it exceeds, control risk is higher and substantive procedures increase.
Sample 60, deviations 2 -> 3.3% sample rate;
if upper deviation rate <= tolerable rate -> rely on control.
Real-world exampleFinding 2 exceptions in 60 items, the auditor computes the upper deviation rate and decides whether reliance is still justified.
Common follow-ups: What is the upper deviation rate? | What if deviations exceed tolerable?
What do you do when a sample reveals a misstatement or deviation?
Advanced
Investigate the nature and cause of each exception (error vs fraud, isolated vs systematic). Consider whether it's an anomaly (rare, non-representative) which requires strong justification and extra work; otherwise project it. Reassess whether related risks and controls are affected, and extend procedures if the projected misstatement approaches or exceeds tolerable misstatement.
Real-world exampleA deviation traced to one new clerk's training gap is investigated to confirm it isn't systematic before concluding.
Common follow-ups: When can a misstatement be treated as an anomaly? | Why investigate the cause of exceptions?
A representative sample is one whose characteristics reflect those of the population, so conclusions drawn from it validly apply to the whole. Achieving representativeness requires appropriate selection (giving items a chance of selection) and adequate size. A biased or too-small sample can mislead the auditor about the population.
Real-world exampleA properly randomized sample of invoices mirrors the population's error rate, supporting a valid conclusion.
Common follow-ups: What threatens representativeness? | How does selection method affect it?
What is attribute sampling versus variables sampling?
Advanced
Attribute sampling tests the rate of occurrence of a characteristic—used in tests of controls to estimate the deviation rate (a yes/no attribute like 'was it approved?'). Variables sampling estimates a numerical amount—used in substantive testing to estimate monetary misstatement. Attribute answers 'how often?'; variables answers 'how much?'.
Real-world exampleAttribute sampling measures how often approvals were missing; variables sampling estimates the dollar misstatement in balances.
Common follow-ups: Which is used for controls vs substantive? | What does each estimate?
When is 100% testing or specific-item selection used instead of sampling?
Intermediate
Test 100% when the population is small, each item is high value, or a significant risk warrants it and data analytics make full testing feasible. Specific-item selection targets particular items (all items over a threshold, unusual or suspicious items, or items for information)—but testing selected items isn't sampling because conclusions don't extend to the rest of the population.
Real-world exampleThe auditor tests all ten material journal entries individually rather than sampling, given their size and risk.
Common follow-ups: Does specific-item testing let you conclude on the whole population? | When is 100% testing efficient?
The confidence level is the complement of sampling risk—e.g., 95% confidence means a 5% sampling risk of a wrong conclusion. Higher required confidence (lower acceptable sampling risk) increases the sample size. The auditor sets confidence based on how much assurance the sample must provide given other evidence and assessed risk.
Real-world exampleRequiring 95% rather than 90% confidence for a high-risk area increases the needed sample size.
Common follow-ups: How does confidence relate to sample size? | What is the complement of confidence?
What are the limitations and risks of relying on sampling?
Advanced
Sampling inherently accepts sampling risk—the sample may not reflect the population, missing errors (over-reliance/incorrect acceptance) or wrongly rejecting good populations. Poorly designed samples, unrepresentative selection, small sizes, or ignoring the population's nature undermine conclusions. Sampling also can't reliably detect rare but material items unless value-weighted or specifically targeted.
Real-world exampleA rare but material fraudulent transaction might not appear in a random sample, so it's targeted via specific selection or analytics instead.
Common follow-ups: How can rare material items evade sampling? | What design flaws undermine sampling?
How does reliance on internal controls affect substantive sample sizes?
Intermediate
If tests of controls support a lower control-risk assessment, the auditor can accept higher detection risk and reduce the extent (sample size) of substantive procedures. Conversely, weak or untested controls mean higher control risk, lower acceptable detection risk, and larger substantive samples. Control reliance and substantive extent are inversely related.
Real-world exampleEffective, tested purchase controls let the auditor reduce the substantive sample of purchase transactions.
Common follow-ups: How does control reliance change detection risk? | What happens to samples if controls are weak?