Discovery sampling in auditing is a statistical method for answering a single yes-or-no question: does a specific, high-risk error or control failure exist anywhere in a population of transactions? The auditor calculates a sample size based on how much confidence is needed, examines each selected item for one defined deviation, and treats even a single exception as proof that the control cannot be relied on. It is the tool of choice when any occurrence of the error would be serious on its own and the expected rate is zero.
When to Use Discovery Sampling
Discovery sampling fits a narrow set of conditions. The control being tested is expected to work every time. Any failure would be material by itself, whether because it points to fraud, a systemic breakdown, or both. And the auditor needs a defensible statistical basis for concluding that the population is essentially clean.
Testing dual-authorization on large wire transfers is the textbook case. If company policy requires two officers to approve any transfer above a threshold, the auditor expects every transfer in scope to carry both signatures. Discovery sampling gives a statistical backbone to that expectation. Regulators and internal audit teams reach for it in similar situations: authorization controls, segregation-of-duties checks, and any test where a single deviation would trigger investigation.
The method is not designed to measure how often something goes wrong. It confirms, or fails to confirm, that a problem does not exist at a rate above a very low threshold. That framing decides whether it belongs in a given audit at all.
The Three Inputs That Set Sample Size
Sample size in discovery sampling comes from three inputs. Get any of them wrong and the sample either wastes effort or fails to support the conclusion.
The first is the confidence level, sometimes called reliability. This is the probability that the sample will catch at least one deviation if the true rate in the population exceeds the tolerable threshold. High-risk audits typically use 95% or 99%. A 95% level means the auditor accepts a 5% risk of missing existing deviations, which the PCAOB describes as the allowable risk of assessing control risk too low.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2315 – Audit Sampling
The second is the maximum tolerable deviation rate. In discovery sampling this is set very low, often between 0.1% and 1%, because the whole point is to detect rare events. Lower tolerable rates demand larger samples.
The third is the expected population deviation rate, which in discovery sampling is assumed to be zero. The auditor believes the control is working perfectly and wants statistical evidence to back that belief.
Population size matters far less than most people expect. Once a population exceeds a few thousand items, the required sample size barely changes whether there are 10,000 or 10 million transactions. Sample size is driven almost entirely by the confidence level and the tolerable rate. At 95% confidence with a 0.5% tolerable rate, the required sample is approximately 600 items. Raising confidence to 99% at the same tolerable rate pushes it to roughly 920. Auditors work from statistical tables or software to pull these numbers rather than calculating from scratch.
Selecting the Items
Every item in the population must have an equal chance of being selected. Without that, the statistical conclusion falls apart. Two selection methods are standard.
Random number selection uses software to generate numbers that map to transaction identifiers, invoice numbers, or record positions. The auditor pulls only the items matching those numbers. It is the default for statistical samples because it is clean and defensible. PCAOB standards require that items for a statistical sample be selected randomly from the population.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2315 – Audit Sampling
Systematic selection picks a random starting point, then takes every nth item until the sample is complete. If 600 items are needed from 60,000 transactions, the interval is every 100th record. It works well for sequentially organized records, but it can introduce bias if the population has a hidden pattern that lines up with the interval.
Whichever method is used, document how it was applied. A reviewer or regulator has to be able to confirm the sample was unbiased and representative. A poorly documented selection process can undermine an otherwise sound conclusion.
Interpreting the Results
The outcome is binary. Either zero deviations show up, or at least one does.
Zero Deviations
If the entire sample comes back clean, the auditor can state with the predefined confidence level that the true deviation rate in the population sits below the tolerable rate. At 95% confidence with a 0.5% tolerable rate, the conclusion reads: there is no more than a 5% chance that deviations occur in more than 0.5% of the population. The control is operating effectively for the purposes of the test.
One or More Deviations
A single deviation invalidates the statistical conclusion. The auditor can no longer assert that the deviation rate is below the threshold. One exception out of 600 items may look small as a percentage, but the design assumed zero, and one is enough to break it.
The practical consequences move quickly. The auditor typically shifts to substantive testing or expands the investigation to determine the scope and cause of the failure. The control is reported as ineffective, which can lead to classification as a significant deficiency or a material weakness. Under PCAOB standards, a material weakness exists when there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis, and fraud by senior management is specifically listed as an indicator.2Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2201 – An Audit of Internal Control Over Financial Reporting
How It Differs From Attribute Sampling
Discovery sampling is technically a special case of attribute sampling, not a separate method. Attribute sampling tests whether a control attribute is present or absent across a population and estimates the actual deviation rate. It is the tool when the auditor expects some level of error and wants to quantify it.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2315 – Audit Sampling
Discovery sampling narrows the framework to a specific case: the expected rate is zero, the tolerable rate is set very low, and the only question is whether any deviation exists. Where attribute sampling might use a tolerable rate of 5% or higher, discovery sampling uses rates well below 1%.
The choice depends on what the auditor believes before testing starts. If a control sometimes fails and the question is how often, attribute sampling quantifies the answer. If the control should never fail and the question is whether it ever has, discovery sampling fits. Using discovery sampling when failures are actually common wastes effort, because the first deviation ends the analysis before any useful rate estimate is possible.
What Discovery Sampling Cannot Do
Discovery sampling does not estimate how widespread a problem is. If the first tested item reveals a deviation, the auditor knows the problem exists but has no statistical basis for saying whether it affects 0.1% or 50% of the population. Scoping the problem requires a different approach.
The method also assumes the tested attribute is the right one. A control requiring dual signatures might be followed on every transaction, yet if both signatures come from people who never actually review the underlying documentation, discovery sampling will show zero deviations while the real risk goes undetected. Statistical rigor in the sample does not compensate for a poorly designed test.
Then there is nonsampling risk, which covers everything that can go wrong outside the math. An auditor might select the wrong procedure entirely, or examine a document and fail to recognize the problem in it. The PCAOB notes that an auditor can apply a procedure to every single item in a population and still miss a material misstatement.3Public Company Accounting Oversight Board. AU 350 – Audit Sampling Nonsampling risk can be reduced through planning, supervision, and well-designed audit programs, but statistical methods alone will not eliminate it.
Documentation That Supports the Conclusion
The audit opinion rests on the paper trail. Record each statistical input (confidence level, tolerable deviation rate, and expected deviation rate), the selection method, the specific items tested, and the results of each examination. The PCAOB expects auditors to have considered the tolerable rate, the likely rate of deviation, and the allowable risk of assessing control risk too low when determining sample size.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2315 – Audit Sampling
State the final conclusion clearly and tie it back to the statistical evidence. If deviations were found, document the response: what additional testing was performed, what the root cause analysis revealed, and how the finding affected the overall assessment of internal controls. Reviewers and regulators will trace the logic from the initial design through to the reported conclusion, and gaps in that chain undermine the credibility of the test.