Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161
Audit sampling techniques form the operational backbone of every public company engagement. Testing every transaction in a large population is rarely feasible under real-world time and resource constraints. Consequently, auditors must select samples that provide a reasonable basis for drawing defensible conclusions about the full population — and do so in a way that satisfies PCAOB standards.
Audit sampling is the application of an audit procedure to less than 100 percent of the items within an account balance or class of transactions for the purpose of evaluating some characteristic of the balance or class. Furthermore, there are two general approaches to audit sampling: nonstatistical and statistical. Both approaches require that the auditor use professional judgment in planning, performing, and evaluating a sample. Either approach can provide sufficient evidential matter when properly applied.
In 2026, technology is reshaping how auditors apply these techniques. However, the foundational requirements of PCAOB AS 2315 remain unchanged. At Shah Teelani & Associates, we apply risk-based sampling discipline on every engagement. This blog explains the key audit sampling techniques, how to design samples that satisfy PCAOB requirements, and where modern tools are changing the landscape.
When Audit Sampling Applies
Not every audit procedure involves sampling. Inquiry, observation, analytical procedures, and 100 percent testing of small populations all fall outside the sampling definition. Sampling applies specifically when the auditor draws conclusions about an entire population from a tested subset.
A well-designed sample lets auditors form defensible conclusions about a full population without exhaustive review. PCAOB AS 2315 establishes requirements for planning, performing, and evaluating audit samples. It recognizes both statistical and non-statistical sampling as valid approaches.
Therefore, the first decision every auditor must make is whether sampling applies to a given procedure at all. Applying sampling logic where 100 percent testing is appropriate — or testing a sample where the entire population is small enough to test completely — represents a planning failure before any sample is selected.
Statistical vs Non-Statistical Sampling
The choice between statistical and non-statistical sampling is one of the most consequential decisions in audit planning. Both approaches satisfy PCAOB requirements when properly applied. However, each suits different circumstances.
Statistical sampling uses random selection methods and probability theory. It allows auditors to quantify sampling risk — the risk that the sample conclusion differs from the conclusion the auditor would reach by testing the entire population. Consequently, statistical approaches work best for large, relatively homogeneous populations where the auditor needs to demonstrate sampling risk quantitatively.
Non-statistical sampling relies on professional judgment rather than probability theory for item selection and evaluation. Non-statistical sampling fits smaller populations, highly stratified populations, or situations where risk-focused selection provides better coverage than random methods. The tradeoff is that sampling risk cannot be quantified in the same way.
The Critical Requirement Both Approaches Share
The choice of nonstatistical or statistical sampling does not directly affect the auditor’s decisions about the auditing procedures to be applied, the appropriateness of the evidential matter obtained with respect to individual items in the sample, or the actions that might be taken in light of the nature and cause of particular misstatements.
Therefore, selecting statistical sampling does not automatically produce higher-quality evidence than non-statistical sampling. What matters is whether the sample design responds to the risks identified, the items selected are representative of the population, and the auditor evaluates results with appropriate professional judgment.
Designing the Sample: Three Key Factors
Designing an effective sample under AS 2315 requires the auditor to consider three interconnected factors before selecting a single item.
Factor 1 — Tolerable Misstatement
Tolerable misstatement defines the maximum monetary error the auditor will accept in the population while still concluding that the financial statement assertion is fairly stated. Smaller tolerable misstatement thresholds require larger sample sizes. Consequently, the materiality decisions made during planning directly drive sample design.
Factor 2 — Risk of Incorrect Acceptance
The allowable risk of incorrect acceptance reflects the assessments of inherent risk, control risk, and the detection risk related to substantive analytical procedures or other relevant substantive tests. Higher assessed risks require lower allowable risk of incorrect acceptance — which in turn requires larger, more extensive samples. Where strong internal controls exist and the auditor plans to rely on them, the allowable risk of incorrect acceptance increases and sample size decreases accordingly.
Factor 3 — Population Characteristics
Population characteristics — including the expected size and frequency of misstatements — directly affect sample size determinations. A population with a high expected error rate requires a larger sample to achieve the same level of assurance. Moreover, populations with high variability in item values require stratification to ensure the sample adequately covers both high-value and low-value items.
Sample Selection Methods
After determining sample size, the auditor must select the actual items tested. AS 2315 requires that sample items should be selected in such a way that the sample can be expected to be representative of the population. Therefore, all items in the population should have an opportunity to be selected.
Four primary selection methods satisfy this requirement under different circumstances.
Random selection uses random number generators or similar tools to select items without bias. Every item in the population carries an equal probability of selection. Consequently, random selection produces the most statistically defensible samples for large homogeneous populations.
Systematic selection selects every nth item after a random starting point. Where the starting point is genuinely random, systematic selection produces representative results. However, auditors must confirm that no systematic pattern in the population aligns with the selection interval — which could bias the sample.
Stratified selection divides the population into subgroups — or strata — before selecting items from each. High-value items may receive 100 percent coverage. Lower-value items may receive proportional coverage based on risk. Furthermore, stratification is particularly effective in populations with high variability because it ensures coverage of items most likely to contain material misstatements.
Haphazard selection involves selecting items without conscious bias — but without using a formal randomization tool. AS 2315 recognizes haphazard selection as a valid approach for non-statistical sampling. However, auditors must genuinely avoid patterns in selection. Repeatedly selecting items from the same time period, location, or source defeats the representativeness requirement.
Evaluating Sample Results
Selecting and testing the sample is only part of the process. AS 2315 requires auditors to evaluate results carefully before drawing conclusions about the population.
Evaluating results for a substantive test of details involves two distinct steps. First, the auditor evaluates whether the misstatements found in the sample — projected to the full population — exceed tolerable misstatement. Second, the auditor considers the qualitative nature of misstatements found — their cause, pattern, and whether they indicate a systematic problem or isolated occurrences.
Statistical approaches work well when a population is large and relatively homogeneous, and when the auditor needs to demonstrate sampling risk quantitatively. Where statistical methods apply, the auditor projects misstatements mathematically using the sample results and the known population size. Where non-statistical methods apply, the auditor projects misstatements using professional judgment — which must be documented and defensible.
Responding to Exceptions
Finding exceptions within a sample does not automatically produce a conclusion that the population contains a material misstatement. However, exceptions always require investigation. The auditor must understand the nature and cause of each exception, evaluate whether it represents a pattern or an isolated event, consider whether it indicates a control deficiency, and determine whether additional procedures are necessary.
Furthermore, the auditor must project exceptions to the population as part of the evaluation. A single exception in a 25-item sample implies a potentially significant population error rate — which the auditor must evaluate against tolerable misstatement before concluding.
Controls Testing Sampling: A Different Standard
Sampling for tests of controls operates differently from sampling for substantive procedures. The objective shifts from detecting monetary misstatements to evaluating whether controls operated effectively throughout the period.
To determine the number of items to select for a test of controls, the auditor should consider the tolerable rate of deviation from the controls being tested, the likely rate of deviations, and the allowable risk of assessing control risk too low.
Tolerable deviation rate — the maximum rate of control failures the auditor will accept while still concluding the control is effective — drives controls testing sample sizes the same way tolerable misstatement drives substantive testing sizes. Moreover, where the expected deviation rate approaches the tolerable rate, sample sizes increase significantly to provide adequate assurance.
Dual-purpose sampling applies a single sample to both a controls test and a substantive test simultaneously. This approach improves efficiency. However, the auditor must evaluate the sample results separately against the objectives of each test — a sample that satisfies the controls testing objective may not satisfy the substantive testing objective.
Full Population Testing: When Sampling Ends
Technology has introduced a powerful alternative to traditional sampling. Data analytics tools now allow auditors to analyze entire populations of transactions rather than selecting subsets.
Full population testing using AI challenges traditional concepts of audit procedure design. Rather than selecting samples and extrapolating results, auditors can analyze entire transaction populations to identify exceptions requiring investigation. This approach reduces reliance on traditional sampling while introducing additional considerations around data completeness, analytical design, and professional judgment.
Importantly, AS 2315’s sampling requirements do not apply when the auditor tests 100 percent of a population. However, the evidence quality requirements of AS 1105 still apply fully. PCAOB emphasizes that auditors should understand the nature of technology-assisted analysis, including relevant data inputs and analytic processes, to ensure the reliability of evidence obtained.
Therefore, full population testing only produces reliable evidence when the underlying data is complete, accurate, and has been evaluated for reliability under AS 1105.10A. A data-driven analysis of an incomplete or unreliable population produces unreliable conclusions regardless of how sophisticated the analytical tool.
Common Sampling Failures in PCAOB Inspections
PCAOB inspections consistently identify specific audit sampling failures across both statistical and non-statistical approaches. Understanding these patterns helps engagement teams avoid them.
Common failures include designing samples that do not respond to the actual risk level — using the same sample size for high-risk and low-risk areas alike. Additionally, selecting items in ways that do not give all population items an opportunity for inclusion represents a representativeness failure. Projecting exceptions incorrectly — or failing to project them to the population at all — is another recurring finding. Furthermore, failing to investigate exceptions or treating them as immaterial without documented analysis produces conclusions that cannot withstand scrutiny. Finally, using non-statistical sampling without appropriate professional judgment documentation — simply selecting convenient items and calling it a sample — fails the standard regardless of how many items are tested.
What Issuers and Finance Teams Should Know
Audit sampling affects issuers directly through the evidence requests auditors make during fieldwork. Finance teams that maintain organized, complete, and readily accessible transaction records enable auditors to design and execute samples more efficiently. Consequently, the quality of the population the auditor draws from shapes the quality of the conclusions the sample can support.
Specifically, finance teams strengthen the sampling process by maintaining complete transaction populations with consistent attributes, ensuring system-generated transaction listings are complete and accurate before providing them to auditors, providing clear documentation of population parameters and any exclusions, and flagging unusual transactions or population changes proactively.
The Bottom Line
Audit sampling techniques under PCAOB AS 2315 require professional judgment at every stage — from sample design through selection, testing, and evaluation. Statistical and non-statistical approaches both satisfy the standard when properly applied. Technology now enables full population testing as an alternative. However, the foundational requirement never changes: the sample or analysis must provide sufficient appropriate evidence responsive to the risks identified.
In 2026, with amended AS 2315 taking effect December 15 and technology-assisted analysis receiving increasing PCAOB inspection attention, every registered firm must treat sampling design as a risk-based discipline — not a default procedure applied uniformly across engagements.
Shah Teelani & Associates (PCAOB Reg. No. 7161) applies rigorous, risk-responsive sampling discipline on every public company engagement. We work with US-listed and OTC public companies that understand what defensible audit conclusions require.
If your organization requires a PCAOB-registered auditor with strong sampling methodology, we welcome the conversation.
Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States