Internal and Forensic Audit · Internal Audit Tools and Techniques
Audit Sampling and Testing Techniques in Internal Audit
Updated 11 October 2026 · Fact-checked
Audit sampling means testing less than 100% of a population and drawing a conclusion about all of it. You choose statistical or non-statistical sampling, set the sample size from risk and tolerable error, select items by a suitable method, test controls or substance, then evaluate errors and project the result.
Understand Audit Sampling and Testing Techniques
An internal auditor cannot check every transaction. A company may have lakhs of invoices in a year. So the auditor tests a part of the population and uses the result to judge the whole. This is audit sampling.
Sampling works only if the sample represents the population. If the sample is biased, the conclusion is unreliable. That is why the choice of method and size matters.
There are two broad approaches. Statistical sampling uses random selection and probability theory to evaluate results and to measure sampling risk. Non-statistical sampling (judgmental sampling) relies on the auditor's judgment for size and selection, and the result cannot be given a mathematical confidence level. Both are acceptable if applied properly and documented. Statistical sampling needs more setup but gives a measurable, defensible result.
Common selection methods are: random selection (every item has an equal chance, often using random number tables or software), systematic selection (every nth item after a random start), monetary unit sampling (each rupee is a unit, so large items are more likely to be picked), stratified selection (population split into groups, such as high, medium and low value, and each is sampled), haphazard selection (picking without a set pattern, but avoiding bias) and block selection (a continuous run of items, such as all vouchers of one week; weak on its own).
There are also two types of tests. Tests of controls check whether a control operated effectively, for example whether each purchase order carries an approval signature. The deviation is a control deviation. Substantive tests check amounts and disclosures directly, such as vouching a payment to an invoice. The error is a misstatement. Sampling risk is the chance that the sample conclusion differs from the conclusion on the whole population. Non-sampling risk comes from errors of the auditor, such as using a wrong procedure or missing an exception, and sampling does not cause it.
Key rules to remember
- Sampling interval (systematic selection)
- Sampling interval = Population size ÷ Sample size
- Choose a random starting point within the first interval, then pick every nth item. For monetary unit sampling, use total book value ÷ sample size.
- Deviation rate
- Sample deviation rate = Number of deviations found ÷ Sample size × 100
- Used in tests of controls. Compare it with the tolerable deviation rate.
- Projected misstatement (simple projection)
- Projected misstatement = (Misstatement found ÷ Value of items tested) × Total population value
- Used in substantive tests. Compare it with tolerable misstatement. Add any known misstatement in items not sampled.
- Sample size drivers
- Larger sample when: risk is higher, tolerable error is lower, expected error is higher, population is more varied
- A rule of direction, not a fixed figure. Population size has little effect once the population is large.
- Acceptance rule
- Accept result if projected error or deviation rate ≤ tolerable level
- If it exceeds the tolerable level, extend testing, revise the risk assessment or report the weakness.
How to solve Audit Sampling and Testing Techniques questions
Use this order for any question on sampling, whether it asks for a method, a comparison or a case.
- 1State the objective of the test: control operation or amount accuracy. This decides the test type.
- 2Define the population and the sampling unit clearly, such as all purchase orders above ₹10,000 in the year.
- 3Decide the approach: statistical or non-statistical, with a reason linked to the facts.
- 4Fix the sample size by risk, tolerable error and expected error. Say whether each factor raises or lowers the size.
- 5Choose the selection method and justify it, for example stratified because values vary widely.
- 6Perform the test and record deviations or misstatements with causes.
- 7Evaluate the result: compute the deviation rate or projected misstatement and compare with the tolerable level.
- 8Conclude and document: accept, extend the sample, or report the control weakness to management and the audit committee.
Quickest way: Four-line sampling answer
When to use it: Use when the question is short, such as a difference, a list of methods or a brief case, and time is tight.
- Write the definition of sampling in one line.
- List the options asked for (approaches or methods) with a one-line use for each.
- Link to the facts: pick the method that fits the population and risk.
- Close with the evaluation rule: compare the result with the tolerable level and document.
Common mistakes in Audit Sampling and Testing Techniques
Saying statistical sampling is always better or always required.
Students link the word statistical with accuracy.
Fix: Say both are acceptable. Statistical sampling gives a measurable risk, but it needs more effort. Choose by cost, population and risk.
Calling non-statistical sampling unplanned or random.
Confusion between judgmental and haphazard picking.
Fix: Non-statistical sampling is planned by judgment on size and items. Its results cannot be given a probability level.
Mixing tests of controls with substantive tests.
Both use samples and vouching.
Fix: Controls tests look at whether a procedure operated and count deviations. Substantive tests look at amounts and count misstatements.
Treating block selection as a fully reliable method.
It is easy to apply and looks complete.
Fix: A block may not represent the year. Use it only with other methods or when the block is large and adequate.
Stating sample size as a fixed number, such as 10% of items.
Students seek a rule of thumb.
Fix: Size depends on risk, tolerable error, expected error and variation. Explain the factors instead of quoting a percentage.
Ignoring errors found in the sample when concluding.
Students stop at selection and testing.
Fix: Always project the error to the population, compare with the tolerable level, and state the action.
Worked examples
Example 1
An internal auditor of Sundaram Traders Ltd. has 4,000 purchase invoices for the year. She plans to select 80 by systematic selection. Find the sampling interval, and state how she selects the items if the random start is 12.
Show the solution
- Sampling interval = Population ÷ Sample size = 4,000 ÷ 80 = 50.
- The random start must be within the first interval, and 12 is between 1 and 50, so it is valid.
- Selected items are numbers 12, 62, 112, 162 and so on, adding 50 each time.
- The last selected item is 12 + 79 × 50 = 3,962, which is within 4,000, so the count is 80.
Answer: The sampling interval is 50. She selects invoice numbers 12, 62, 112 and so on up to 3,962, giving 80 items.
Example 2
In a substantive test, an internal auditor of Kaveri Foods Ltd. tests trade receivables of book value ₹40,00,000 out of a total of ₹2,00,00,000. She finds overstatement of ₹60,000 in the tested items. Tolerable misstatement is ₹2,50,000. Project the error and state the conclusion.
Show the solution
- Error rate in the tested items = ₹60,000 ÷ ₹40,00,000 = 0.015, or 1.5%.
- Projected misstatement = 0.015 × ₹2,00,00,000 = ₹3,00,000.
- Compare: ₹3,00,000 is higher than the tolerable misstatement of ₹2,50,000.
- The sample result therefore does not support the receivables balance as stated.
- Action: extend testing or ask management to investigate and correct, find the cause of the overstatement, and report it.
Answer: Projected misstatement is ₹3,00,000, above the tolerable ₹2,50,000. The auditor should not accept the balance as it stands. She should extend the tests, find the cause, and report the matter.
Exam tips
- For a difference question, write two or three points of contrast, such as selection basis, risk measurement and effort, and avoid saying one is better.
- Always name the test type in case questions. State whether the objective is a control check or an amount check.
- Show the calculation in numbers when data is given. Interval, deviation rate or projection earns marks even if the conclusion is simple.
- End every case answer with a conclusion and an action, such as extending the sample or reporting to the audit committee.
- Mention sampling risk and non-sampling risk by name where the question asks about limits of sampling.
Practice questions from Internal Audit Tools and Techniques
- At Ganga Foods Ltd, a team member asks who owns the working papers prepared during an internal audit performed by an outsourced firm for the…
- While planning the audit of Kaveri Pharma's procurement, the internal auditor lists key risks, identifies the controls meant to mitigate eac…
- During an internal audit of Kaveri Textiles Ltd, the auditor wants to confirm that the stores department actually holds the quantity of yarn…
- An internal auditor at Hindustan Agro Ltd suspects fictitious vendors. Which sequence of procedures would give the most reliable evidence ab…
- An internal auditor at Sundaram Textiles Ltd wants to confirm that every purchase invoice paid during the quarter is supported by a goods re…
Audit Sampling and Testing Techniques in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Audit Sampling and Testing Techniques: frequently asked questions
What is the difference between statistical and non-statistical sampling?
Statistical sampling uses random selection and probability theory to size the sample and evaluate results, so sampling risk can be measured. Non-statistical sampling relies on the auditor's judgment, and its results have no mathematical confidence level. Both are valid if they are applied properly and documented.
What are the main types of sampling methods in audit?
The main methods are random, systematic, monetary unit, stratified, haphazard and block selection. Each suits a different population. For example, stratified selection suits populations with widely varying values.
How do I decide the sample size in internal audit?
Sample size depends on the assessed risk, the tolerable error, the expected error and the variation in the population. Higher risk, lower tolerable error or higher expected error means a larger sample. There is no single fixed percentage.
What is the difference between a test of controls and a substantive test?
A test of controls checks whether a control operated effectively and counts deviations. A substantive test checks the amounts or disclosures themselves and counts misstatements. Controls tests help decide how much substantive testing is needed.