Sampling Methods for IS Auditing
Explore audit sampling methods used in IS auditing, including attribute, variable, and judgmental sampling. Key concepts for the CISA exam.
Why Sampling Matters
In most IS audit engagements, testing every transaction or control instance is impractical. Sampling allows auditors to draw conclusions about an entire population by examining a subset of items. Understanding sampling methods and their appropriate application is a key CISA exam topic.
Types of Audit Sampling
Audit sampling falls into two broad categories: statistical and non-statistical (judgmental). Each has specific methods and use cases.
Statistical Sampling
Statistical sampling uses mathematical principles to select samples and evaluate results. It provides an objective, quantifiable basis for conclusions and allows the auditor to measure sampling risk.
- Attribute sampling: Used to test the rate of occurrence of a specific characteristic (attribute) in a population. For example, an auditor might test what percentage of access requests were properly approved. The result is expressed as a deviation rate.
- Variable sampling: Used to estimate the monetary value or quantity of a population. This method is common in financial auditing when estimating the total value of errors in a set of transactions.
- Stop-or-go sampling: A sequential sampling method that allows auditors to stop testing early if results clearly indicate the error rate is acceptable. This reduces testing effort when few errors are expected.
- Discovery sampling: Designed to detect at least one occurrence of a critical attribute (such as fraud) if it exists in the population at a specified rate. Used when even a single error would be significant.
Non-Statistical (Judgmental) Sampling
Non-statistical sampling relies on the auditor's professional judgment to select items and evaluate results. While it does not provide the same level of statistical precision, it can be appropriate in certain situations:
- Judgmental selection: The auditor selects items based on experience and knowledge of the area being audited.
- Haphazard sampling: Items are selected without a structured method, though the auditor attempts to avoid bias. This is not truly random and should not be confused with statistical sampling.
- Block sampling: Selecting a contiguous set of items, such as all transactions from a specific week. This method carries the risk that the selected block may not represent the full population.
Determining Sample Size
Several factors influence the appropriate sample size:
- Confidence level: Higher confidence requires larger samples.
- Expected error rate: Higher expected error rates require larger samples to achieve the same precision.
- Tolerable error rate: The maximum error rate the auditor will accept. A lower tolerable rate requires a larger sample.
- Population size: While population size affects sample size, the relationship is not proportional. A large population does not always require a proportionally large sample.
CISA Exam Tips
For the CISA exam, know when to use each sampling method. Attribute sampling is most commonly used for compliance testing (testing controls), while variable sampling is used for substantive testing (testing monetary amounts). Remember that statistical sampling provides a defensible, objective basis for conclusions, while judgmental sampling is acceptable when the population is small or when the auditor has strong knowledge of the area being tested.