Statistical Sampling Techniques in IS Auditing
Learn about statistical sampling techniques used in IS auditing, including attribute sampling, variable sampling, and how to determine appropriate sample sizes.
Sampling in IS Auditing
Statistical sampling enables auditors to draw conclusions about entire populations by examining a representative subset. For CISA candidates, understanding sampling methods, their applications, and their limitations is crucial for both the exam and professional practice.
Why Sampling Matters
While data analytics tools increasingly allow full population testing, sampling remains relevant when complete data analysis is impractical, when physical inspection is required, or when the cost of full testing exceeds its benefits. Proper sampling provides a mathematically defensible basis for audit conclusions.
Types of Statistical Sampling
Attribute Sampling
Attribute sampling tests whether a specific characteristic, or attribute, exists in a population. It is used primarily for compliance testing of internal controls. The auditor selects a sample and determines the rate at which a particular attribute, such as the presence of an authorization signature, occurs.
- Fixed-rate sampling estimates the occurrence rate of an attribute in the population
- Stop-or-go sampling is used when the auditor expects a low error rate and wants to minimize sample size
- Discovery sampling is designed to detect at least one occurrence of a critical attribute when the expected error rate is extremely low
Variable Sampling
Variable sampling estimates the numerical value or amount associated with a population. It is used primarily for substantive testing. Common techniques include:
- Stratified mean per unit divides the population into subgroups for more precise estimates
- Difference estimation estimates the total difference between audited and book values
- Ratio estimation uses the ratio of audited to book values in the sample to estimate the population total
Determining Sample Size
Sample size depends on several factors including the desired confidence level, the tolerable error rate, the expected error rate in the population, and the population size. Higher confidence levels and lower tolerable error rates require larger samples. As the expected error rate approaches the tolerable error rate, sample sizes increase significantly.
Non-Statistical Sampling
Non-statistical, or judgmental, sampling relies on auditor expertise rather than mathematical probability. While it can be effective, it does not provide a statistical basis for projecting results to the population. CISA candidates should understand that statistical sampling provides greater objectivity and defensibility.
Exam Focus Areas
The CISA exam frequently tests knowledge of when to use attribute versus variable sampling. Remember that attribute sampling supports compliance testing of controls, while variable sampling supports substantive testing of account balances. Understand the factors affecting sample size and the implications of sampling risk, which includes both the risk of incorrect acceptance and the risk of incorrect rejection.