Welcome to Audit Sampling!
Hello there! Today we are diving into one of the most practical parts of auditing: Audit Sampling for Tests of Controls. In an ideal world, an auditor would check every single document, but that would take forever and cost too much! Instead, we "sample." Think of it like tasting a spoonful of soup to see if the whole pot needs more salt. You don't need to drink the whole pot to know if it's good!
In this chapter, we focus on Tests of Controls. We aren't looking for dollar errors yet; we are looking to see if the company's "safety rules" (internal controls) are actually being followed.
1. What is Audit Sampling?
According to HKSA 530, audit sampling is applying audit procedures to less than 100% of items within a population. Every item in that population must have a chance of being selected so that the auditor can reach a conclusion about the whole group.
Prerequisite Concept: What is a "Control"?
Before we sample, remember that a control is a procedure the company uses to prevent or catch errors. For example: "Every purchase invoice over $5,000 must be signed by a manager." When we test this control, we are looking for that signature.
Key Takeaway
Sampling allows us to get reasonable assurance without checking every single transaction, making the audit efficient and effective.
2. Sampling Risk vs. Non-Sampling Risk
When we don't check everything, there is always a risk we might be wrong. We break this down into two types:
A. Sampling Risk
This is the risk that the sample we picked isn't representative of the whole population. You might accidentally pick the only 5 invoices that were signed correctly, even if the other 995 were not!
In Tests of Controls, we worry about two specific sampling risks:
1. Risk of Over-reliance: We think the controls are working great, but they actually aren't. This is dangerous because we will do less work later, even though the risk is high.
2. Risk of Under-reliance: We think the controls are failing, but they are actually fine. This is inefficient because we will end up doing way more work than we needed to.
B. Non-Sampling Risk
This happens when the auditor makes a mistake that has nothing to do with the sample size. For example, the auditor looks at a signature but doesn't realize it's a forgery, or they use the wrong audit procedure. Human error is the best way to remember this!
Quick Review:
Sampling Risk = The sample was "unlucky."
Non-sampling Risk = The auditor "messed up."
3. Statistical vs. Non-Statistical Sampling
There are two ways to choose your "spoonful of soup":
1. Statistical Sampling: This uses random selection and probability theory (math!) to evaluate results. It allows us to measure sampling risk mathematically.
2. Non-statistical Sampling: Also known as "Judgmental Sampling." The auditor uses their professional judgment to pick items and evaluate them. It’s perfectly acceptable under HKSA 530, but you can't measure the risk with a math formula.
Analogy: Statistical sampling is like using a precise kitchen scale to measure ingredients. Non-statistical sampling is like a chef adding a "pinch" of salt based on years of experience.
4. Designing the Sample: Step-by-Step
When planning our test, we need to define a few things first:
Step 1: Define the Objective
What are we testing? Example: Are all sales backed by a shipping document?
Step 2: Define "Deviation"
A deviation (or error) in control testing is when the control is NOT performed. If the rule says "manager must sign" and there is no signature, that is a deviation. Even if the dollar amount on the invoice is correct, the control has failed.
Step 3: Define the Population
This is the whole set of data. If we are auditing the year 2023, our population is all invoices from Jan 1 to Dec 31. If we leave out December, our conclusion won't be valid for the whole year!
Key Takeaway
Always ensure your population is complete and appropriate for your audit objective.
5. Determining Sample Size
How many items do we need to check? This depends on a few factors. Don't worry, you don't need complex calculus, just understand the relationships!
1. Reliance on Controls: If you want to rely heavily on controls, you need a larger sample size.
2. Tolerable Deviation Rate (TDR): This is the maximum "fail rate" the auditor is willing to accept. If you are very strict (low TDR), you need a larger sample.
3. Expected Deviation Rate (EDR): This is how many errors you expect to find. If you expect a lot of errors, you need a larger sample to see if it's really that bad.
Memory Aid: "The Size Logic"
- Want more Confidence? -> Bigger Sample.
- Less Tolerant of mistakes? -> Bigger Sample.
- Expect more trouble? -> Bigger Sample.
6. Selection Methods: How to Pick the Items
Here are the ways we can physically pick our items:
1. Random Selection: Every item has an equal chance. Usually done with computer software (like Excel). Best for statistical sampling.
2. Systematic Selection: Picking every \( n^{th} \) item. For example, every 50th invoice. You calculate the "interval" by: \( \text{Interval} = \frac{\text{Population Size}}{\text{Sample Size}} \).
3. Haphazard Selection: The auditor picks items without following a structured technique but tries to avoid bias. Note: This is not allowed for Statistical Sampling because it's not truly mathematical!
4. Block Selection: Picking a "block" of items (e.g., all invoices in the first week of May). This is generally not recommended because transactions in one week might not represent the whole year.
Common Mistake to Avoid: Don't confuse "Haphazard" with "Random." Random uses a math-based system (like a generator); Haphazard is just a human picking things "randomly" by hand.
7. Evaluating the Results
After you've checked your sample, you calculate the Sample Deviation Rate:
\( \text{Sample Deviation Rate} = \frac{\text{Number of Deviations Found}}{\text{Number of Items in Sample}} \)
Comparing to Tolerable Rate
- If Sample Rate < Tolerable Rate: The control is working effectively. We can rely on it!
- If Sample Rate > Tolerable Rate: The control is NOT working. We cannot rely on it. We must do more substantive testing (check more actual dollar amounts) to make up for the weak controls.
Did you know? If you find a deviation, you shouldn't just count it and move on. You must investigate why it happened. Was it a one-time computer glitch, or was it a staff member intentionally skipping the rule? This matters!
Key Takeaway
If the results are "marginal" (close to the tolerable rate), the auditor must use professional skepticism and decide if more testing is needed.
Summary: The Big Picture
Audit sampling for controls is about getting a representative look at how well a company follows its own rules. By understanding sampling risk and picking the right sample size and method, you can draw a conclusion about thousands of transactions by only looking at a small handful. This makes you a more efficient and effective auditor!
Keep practicing those "Reliance vs. Sample Size" relationships—they are a favorite for exam questions! You've got this!