Welcome to Audit Sampling!
Welcome to one of the most practical chapters in your AUD studies! Have you ever tasted a small spoonful of soup to see if the whole pot needs more salt? That is exactly what Audit Sampling is. Auditors can’t look at every single transaction a company makes (it would take forever!), so we look at a representative "spoonful" to reach a conclusion about the "whole pot."
In this chapter, we will learn how to pick that spoonful and how to feel confident that our conclusion is right. Don't worry if this seems a bit "math-heavy" at first—we will break it down into simple steps and focus on what the CPA exam actually tests.
1. The Basics: What is Audit Sampling?
Audit Sampling is the application of an audit procedure to less than 100% of the items within a population. The goal is to evaluate some characteristic of the entire group based on the small piece we tested.
Sampling Risk vs. Non-Sampling Risk
Even if you do everything right, there is always a chance you’ll reach the wrong conclusion. This is called Audit Risk. In sampling, we split this into two categories:
1. Sampling Risk: The risk that the sample you picked isn't representative of the whole group. Maybe you just happened to pick the only five "bad" invoices in a pile of 1,000 "good" ones.
Analogy: You take a sip of soup and get a giant chunk of salt that didn't dissolve yet. You think the whole pot is too salty, but it's actually fine!
2. Non-Sampling Risk: The risk that you reach a wrong conclusion for any reason not related to the sample size. This usually happens because of human error—like using the wrong procedure or misinterpreting the evidence.
Analogy: You taste the soup, but you have a cold and can't taste anything anyway!
Memory Aid: The Two Types of Sampling Mistakes
The CPA exam loves to test these two risks. Think of them in terms of Efficiency (doing too much work) vs. Effectiveness (failing to find a problem).
For Tests of Controls:
- Risk of Assessing Control Risk Too High (Alpha Risk): You think the controls are bad, but they are actually good. Result: You do too much extra work (Low Efficiency).
- Risk of Assessing Control Risk Too Low (Beta Risk): You think the controls are good, but they are actually bad. Result: You don't do enough work and might miss a big error (Low Effectiveness—Dangerous!).
For Substantive Testing:
- Risk of Incorrect Rejection: You think the balance is wrong, but it's right. (Efficiency issue).
- Risk of Incorrect Acceptance: You think the balance is right, but it's wrong. (Effectiveness issue—Dangerous!).
Quick Review: Auditors are most afraid of Risk of Assessing Control Risk Too Low and Risk of Incorrect Acceptance because these lead to a "fail" in the audit's quality.
2. Statistical vs. Non-Statistical Sampling
There are two main "flavors" of sampling. Both are allowed under GAAS (Generally Accepted Auditing Standards).
Statistical Sampling: Uses the laws of probability to measure risk. It helps you calculate an exact sample size and mathematically evaluate the results.
Benefit: It provides an objective way to measure "Sampling Risk."
Non-Statistical Sampling: Uses the auditor’s professional judgment to pick items and evaluate results.
Note: You still need a representative sample, but you aren't using math formulas to justify it.
Common Mistake to Avoid:
Students often think Statistical Sampling is "better." It's not! Both are equally valid under audit standards. The choice depends on the auditor's judgment and the cost-benefit of using complex math.
3. Attribute Sampling (Testing Controls)
We use Attribute Sampling when we are looking for a "Yes/No" characteristic. For example: "Did the manager sign this purchase order?" We aren't looking at the dollar amount; we are looking for the attribute of a signature.
Key Factors that Determine Sample Size:
1. Tolerable Deviation Rate: How many errors are you willing to "tolerate" before you decide the control isn't working? (If you want to be strict, this number is low).
2. Expected Deviation Rate: How many errors do you expect to find?
3. Allowable Risk of Assessing Control Risk Too Low: How much risk are you willing to take of being wrong? (High confidence = lower risk).
Evaluating Results:
After you test your sample, you calculate the Sample Deviation Rate (\(\frac{\text{Number of Errors}}{\text{Sample Size}}\)). Then, you add a "safety margin" called the Allowance for Sampling Risk.
The Golden Rule of Attribute Sampling:
Sample Deviation Rate + Allowance for Sampling Risk = Upper Deviation Rate
Compare your Upper Deviation Rate to your Tolerable Rate:
- If Upper Deviation Rate \(\le\) Tolerable Rate: Rely on the control.
- If Upper Deviation Rate \(>\) Tolerable Rate: Do NOT rely on the control. Expand testing or increase control risk.
4. Variables Sampling (Substantive Testing)
While Attribute Sampling looks for "Yes/No," Variables Sampling looks at Dollar Amounts. We use this when we want to know if an account balance (like Accounts Receivable) is materially misstated.
Three Common Methods:
1. Mean-Per-Unit (MPU) Estimation:
Calculate the average value of the items in your sample and multiply it by the total number of items in the population.
\((\text{Average Sample Value}) \times (\text{Total Number of Items}) = \text{Estimated Total Value}\)
2. Ratio Estimation:
Use the ratio of the audited value to the book value from your sample to estimate the whole.
\((\frac{\text{Audit Value of Sample}}{\text{Book Value of Sample}}) \times \text{Total Book Value} = \text{Estimated Total Value}\)
3. Difference Estimation:
Calculate the average difference between the "true" audited value and the "recorded" book value for your sample, then project that difference to the whole population.
5. Probability-Proportional-to-Size (PPS) Sampling
This is a hybrid method that is very popular on the CPA exam. Instead of picking physical "invoices," PPS treats every individual dollar as a sampling unit.
Why use PPS?
- It automatically picks larger dollar items (because a $10,000 invoice has 10,000 "chances" to be picked, while a $10 invoice only has 10).
- It is usually more efficient than classical variables sampling if you expect few errors.
Calculating the Sample Size in PPS:
You need to know the Sampling Interval.
Formula: \( \text{Sampling Interval} = \frac{\text{Tolerable Misstatement}}{\text{Reliability Factor}} \)
Sample Size: \( \text{Sample Size} = \frac{\text{Total Population Book Value}}{\text{Sampling Interval}} \)
PPS Evaluation:
When you find an error in PPS, you calculate the Projected Error.
- If the item's book value is smaller than the interval, you use a "Tainting %."
- If the item's book value is larger than the interval, the projected error is simply the actual error found.
Key Takeaway for PPS: It's great for finding overstatements (assets that are too high), but it's not good at finding understatements or zero balances (because a zero balance has zero "chances" of being picked!).
Summary Checklist for Success
Before you move on to practice questions, make sure you can answer these:
- Attribute Sampling = Controls (Yes/No).
- Variables Sampling = Substantive ($ Amounts).
- Beta Risk = The "Scary" risk (Effectiveness).
- Alpha Risk = The "Extra work" risk (Efficiency).
- PPS = Focuses on larger dollar amounts; bad for zero/negative balances.
Keep going! You're doing great. Sampling is one of those topics that "clicks" once you start seeing how the formulas interact with the auditor's goal of being both efficient and safe.