Audit attribute sampling is a statistical technique for testing whether an internal control operates effectively: you inspect a probability-based sample of items for a single pass-or-fail characteristic, count the deviations, and project that result to the population within a defined confidence level. It is used almost exclusively in tests of controls, because it measures frequency of failure rather than the dollar magnitude of misstatement. If the control passes, you can reduce substantive testing on the related balance; if it fails, that efficiency disappears and direct testing has to expand.
What Attribute Sampling Measures
The attribute is a binary trait tied to a specific control. A purchase order either carries the required approval, or it does not. A three-way match between invoice, receiving report, and purchase order either exists, or it does not. Every item you look at is classified as compliant or as a deviation. No middle ground, no dollar amount attached.
That focus on frequency is what separates attribute sampling from variables sampling, which estimates a monetary figure such as the total misstatement in an account balance. The question here is not “how much is wrong?” but “how often does the control fail?” PCAOB Auditing Standard 2315 governs how the sample is planned, performed, and evaluated for both tests of controls and substantive tests of details.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling
Planning Inputs That Drive Sample Size
Three parameters set during planning determine how many items you need to test. Setting them is where the judgment lives, and the interaction of the three is what the statistical tables solve for.
Tolerable Deviation Rate
The tolerable deviation rate is the highest failure rate you are willing to accept and still conclude the control works well enough to rely on. For a control that is the primary safeguard over a sensitive area such as cash disbursements, auditors often set the tolerable rate around 5 percent or lower. A secondary control that supports another strong procedure may justify 10 percent or more. AS 2315 ties the appropriate tolerable rate to the planned level of control risk and to how much assurance you need from the sample alone versus other evidence such as inquiry and observation.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling
A lower tolerable rate demands a larger sample. Setting it too high creates the worse problem: concluding an unreliable control is effective and building the rest of the audit on that assumption.
Expected Deviation Rate
The expected deviation rate is your best preliminary estimate of the population’s actual failure rate, drawn from prior-year results, walkthroughs, or a small preliminary sample. If you have no reason to expect deviations, set it near zero.
One hard rule: the expected rate must always be lower than the tolerable rate. If you genuinely expect the control to fail at or above the level you are willing to tolerate, running the test is pointless. Move directly to expanded substantive procedures. A higher expected rate also enlarges the sample, because more data is needed to distinguish a population that barely passes from one that barely fails.
Acceptable Risk of Overreliance
The acceptable risk of overreliance is the probability you will accept that the sample leads you to conclude a control is effective when it actually is not. Most auditors set this at 5 percent or 10 percent, corresponding to 95 percent or 90 percent confidence in the result.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling
Which figure fits depends on how heavily the audit relies on the control. When the control is the sole basis for reducing substantive testing on a material account, 5 percent is the safer choice. When other controls or analytical procedures corroborate, 10 percent may be enough.
Looking Up the Sample Size
Once the three parameters are set, the minimum sample size comes from a standard statistical table or audit software. The tables are built on the binomial distribution, which models the probability of a given number of failures in a fixed number of independent trials.2Office of the Comptroller of the Currency. Sampling Methodologies
The relationships are consistent. Lower tolerable rate, larger sample. Lower risk of overreliance, larger sample. Higher expected deviation rate, larger sample. As a concrete example: a 5 percent tolerable rate, 5 percent risk of overreliance, and expected deviation rate of zero produces a sample of roughly 59 items. Push the expected rate up to 1 percent with the other two constant, and the required sample climbs to about 93.
Population size itself has almost no effect on the required sample once the population is reasonably large.3Public Company Accounting Oversight Board. AU Section 350 Audit Sampling Precision is driven by the three risk inputs. A population of 5,000 items and one of 500,000 can call for the same sample if the parameters match.
Selecting the Items
Selection matters because a biased sample destroys the statistical conclusion. AS 2315 requires items to be chosen so the sample can be expected to represent the population, meaning every item has an opportunity to be selected.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling
Random Selection
A computer-based random number generator is the cleanest method. Every item has an equal probability of being drawn, which removes auditor bias. Define the population, number the items if they are not already numbered, and let the generator pick. Most audit software has this built in, and it is the default for attribute sampling.
Systematic Selection
Systematic selection calculates a fixed interval and takes every Nth item after a random start. For 5,000 items and a sample of 100, the interval is 50. Pick a starting point between 1 and 50, say 23, then test items 23, 73, 123, and so on. Efficient and close to random, but it will bias the sample if the population is arranged in a pattern that aligns with the interval. Check the ordering before using it.
Haphazard Selection Is Not Enough
Haphazard selection means grabbing items without a deliberate pattern and without a random mechanism. It feels unbiased. It isn’t. Subconscious tendencies push you toward items in the middle of a stack, away from thin folders, or around certain time periods. Because the selection is not truly random, results cannot reliably be projected to the population, and haphazard selection does not support a statistical conclusion in attribute sampling.
Testing Each Item
For each selected item, examine the evidence and decide whether the attribute is present. If the control requires a manager’s electronic approval on purchase orders over a threshold, open each selected PO and look for the timestamp. Present is compliant; absent is a deviation. Record the outcome for every item.
Voided, Inapplicable, and Missing Items
Some selected items will not be clean tests. A voided transaction or an unused document number in a sequential system is not a real transaction. Confirm the void or gap is legitimate, then replace the item using the same selection method.
Missing documentation is different. If you cannot locate the support for a selected item and cannot determine what happened to it, AS 2315 directs you to treat the item as a deviation when evaluating the sample.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling If the control were truly operating, the evidence would exist. Count it as a failure.
Evaluating the Results
Once every sampled item has been tested, the raw deviation count becomes a statistical conclusion about the population. The arithmetic is easy; the interpretation is where auditors sometimes go wrong.
Sample Deviation Rate
Divide deviations by items tested. Three deviations in a sample of 100 is a sample deviation rate of 3 percent. That is the best single-point estimate of the population’s failure rate, but it is not the answer, because it ignores sampling risk. A different sample from the same population could easily produce a different count.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling
Upper Deviation Rate
The upper deviation rate builds sampling risk back in. It represents the worst-case population deviation rate at the confidence level implied by your risk of overreliance. Look up the intersection of the actual sample size and the number of deviations found, under the column for your risk of overreliance.
An illustration: 60 items tested at a 5 percent risk of overreliance, with zero deviations, yields an upper deviation rate of about 5 percent from the standard table. That supports 95 percent confidence that the true population deviation rate does not exceed 5 percent. Two deviations in those same 60 items would push the upper deviation rate considerably higher, reflecting the added uncertainty.
Comparing to the Tolerable Rate
The comparison that decides the test is upper deviation rate against tolerable deviation rate. If the upper deviation rate is below the tolerable rate, the control passes and the planned reduction in substantive testing holds. If the upper deviation rate exceeds the tolerable rate, the control fails, even when the raw sample rate looks modest. A sample deviation rate of 3 percent can produce an upper deviation rate of 7 or 8 percent depending on sample size and confidence level, which overshoots a 5 percent tolerable threshold. The upper deviation rate drives the conclusion, not the raw rate.
When the Control Fails the Test
A failed test of controls forces changes to the audit plan immediately. The planned reduction in substantive testing depended on the control working, so that reduction reverses. Control risk for the related assertion rises, and the higher risk assessment calls for more direct testing of dollar amounts: more transactions checked for accuracy, expanded confirmations, more granular analytical procedures, or a mix. The audit gets larger, slower, and more expensive. That trade-off is the whole point of testing controls in the first place, and it only pays off when the control actually holds.
Communicating Control Deficiencies
A failed control test can also trigger reporting obligations. Auditors of public companies must communicate all significant deficiencies and material weaknesses in internal control to management and the audit committee in writing before issuing the auditor’s report.4Public Company Accounting Oversight Board. Communications About Control Deficiencies in an Audit of Financial Statements A material weakness is a deficiency severe enough that there is a reasonable possibility a material misstatement will not be prevented or detected on a timely basis. A significant deficiency is less severe but still important enough for the audit committee to hear about.
The written communication must distinguish the two categories, note that the audit’s objective was to report on the financial statements rather than provide assurance on internal control, and restrict the communication’s use to the board, audit committee, and management. Auditors are prohibited from issuing a written statement that no significant deficiencies were found, because such a statement could be misread as broad assurance on the control environment.4Public Company Accounting Oversight Board. Communications About Control Deficiencies in an Audit of Financial Statements
Sampling Risk Is Not the Only Risk
Attribute sampling manages sampling risk, the chance that the sample leads to a different conclusion than a full population test would produce. It does nothing about nonsampling risk, which covers everything else that can go wrong. Nonsampling risk includes choosing a procedure that does not actually test what you think it tests. Confirming recorded receivables, for example, reveals nothing about unrecorded receivables. It also includes failing to spot a deviation while looking directly at it. An auditor who examines a purchase order with a photocopied approval and marks it compliant has introduced an error no sample size formula can correct.5Public Company Accounting Oversight Board. AU Section 350.11 Audit Sampling
The standard treats nonsampling risk as controllable through adequate planning, supervision, and quality control. Sampling risk is handled by the math. Nonsampling risk is handled by the people doing the work.
Documentation the Workpapers Must Contain
PCAOB AS 1215 requires documentation prepared in sufficient detail that an experienced auditor with no prior connection to the engagement can understand its purpose, source, and conclusions.6Public Company Accounting Oversight Board. Audit Documentation For an attribute sampling application, the workpapers should cover each phase:
- Objective: the specific control tested and the financial statement assertion it addresses.
- Population definition: source system, time period, and total count of items the sample was drawn from.
- Planning parameters: the tolerable deviation rate, expected deviation rate, and risk of overreliance, with the rationale for each.
- Sample size: the calculated minimum and the number actually tested.
- Selection method: random, systematic, or otherwise, along with the tool or seed used.
- Results: deviations found, the nature of each one, the sample deviation rate, and the upper deviation rate.
- Conclusion: whether the upper deviation rate cleared the tolerable rate, and the resulting impact on the audit plan.
Memoranda, schedules, and electronic files are all acceptable formats. What matters is traceability: a reviewer should be able to follow the thread from planning rationale through tested items to the conclusion without gaps.6Public Company Accounting Oversight Board. Audit Documentation
Which Standard Applies
For audits of public companies, PCAOB AS 2315 governs audit sampling. It covers both statistical and nonstatistical approaches and applies to tests of controls as well as substantive tests of details. The standard defines sampling as applying an audit procedure to less than 100 percent of the items in a balance or transaction class to evaluate a characteristic of the whole.1Public Company Accounting Oversight Board. AS 2315 Audit Sampling
For audits of nonpublic entities, the AICPA’s AU-C Section 530 provides parallel guidance under generally accepted auditing standards. The framework is the same: define the objective, size and select the sample, perform the procedure, evaluate the results. The statistical mechanics of attribute sampling do not change with the regulatory framework. Documentation expectations and reporting obligations do.