Domain 1: The IS Audit Process8 min · 3 questions

Choosing a Sampling Approach

Statistical or judgemental, attribute or variable. The choice determines what you are allowed to say about the population when you are finished.

What this makes you able to do

Select a sampling approach appropriate to the audit objective and the conclusion required.

By the end you can

  • Distinguish statistical from non-statistical sampling by what each permits you to conclude.
  • Select attribute or variable sampling according to whether the question is about rate or amount.
  • Identify when stop-or-go and discovery sampling are appropriate.

Transcript

Choosing a sampling approach. The approach you pick decides what you are allowed to say about the population when you are finished, and the exam cares about this more than almost any other part of sampling.

Here is why it matters. You test thirty changes. All thirty had approvals. Your report says change management is operating effectively across the four thousand changes in the period. Whether that sentence is defensible depends entirely on how those thirty were chosen.

So the first choice is statistical or non-statistical. Statistical sampling uses random selection, so every item in the population has a known, non-zero chance of being selected. That is what permits projection: you can state a conclusion about the whole population with a measurable confidence level. Non-statistical, or judgemental, sampling selects items by auditor judgement, the largest, the riskiest, the ones from the month the new team took over. It is legitimate, often efficient, and frequently finds more than a random sample would. What it cannot do is support a projected conclusion.

The exam test of this is blunt. If a question describes a judgemental selection and an option projects the result to the population, that option is wrong. Sample size does not fix it. A thousand judgementally selected items still describe only the items tested, never the four thousand you did not look at.

The second choice is attribute or variable. Attribute sampling answers questions of rate: how often does this condition occur? Deviation rates, exception rates, compliance rates. Almost all controls testing is attribute sampling, because did the control operate is a yes or no property of each item. Variable sampling answers questions of amount: what is the total value, or the average, or the misstatement? It estimates a quantity rather than a frequency, and it belongs to substantive testing.

There is a reliable shortcut here. Compliance testing tends toward attribute sampling, and substantive testing tends toward variable sampling. If you are asking whether a control operated, that is a rate. If you are asking whether an amount is correct, that is a quantity.

Beyond those two axes, there are specialised approaches the exam expects you to recognise, and it names them by what they are for rather than only how they work. Each is the right tool for a specific objective, and picking the wrong tool is a common trap.

Stop-or-go sampling is used when you expect very few errors. It lets you stop early once enough clean items support the conclusion, which minimises the sample size. It reduces effort when the controls are believed to be working.

Discovery sampling is used when the condition is rare and critical, typically fraud, and the objective is to find at least one instance if any exist. It does not estimate a rate. If the expected rate is near zero and any single instance matters, attribute sampling is the wrong tool and discovery is the right one.

Stratified sampling divides the population into sub-populations of similar characteristics, usually value bands, and samples each. It reduces the sample size needed for a given precision when the population contains items of widely varying value. And systematic, or cell, sampling selects every nth item after a random start. It stays statistical provided the start is random and the population has no periodic pattern that lines up with the interval.

Now, where people actually go wrong, and it is the quiet projection. An auditor selects the twenty five most significant items, finds two exceptions, and writes that eight per cent of changes lacked approval. That sentence is not supported, because the selection was not random, and on the exam it is the trap in nearly every judgemental sampling question.

The second error is choosing variable sampling for a controls question because money is involved. The presence of a monetary amount in the scenario does not make the question about amount. If you are asking how often a control failed, that is a rate, and it is attribute sampling regardless of what the transactions are worth. So carry both away: judgemental means no projection, and money does not turn a rate question into an amount question.

Knowledge check
0 / 3
  1. 1.An IS auditor wants to conclude on the rate at which change approvals were missing across the whole population of changes. Which sampling approach is MOST appropriate?

  2. 2.An IS auditor suspects that a small number of fraudulent payment records may exist in a large population and wants to find at least one if any exist. Which approach is MOST appropriate?

  3. 3.An IS auditor selects 30 records by choosing those with the largest transaction values. What is the PRIMARY limitation of the results?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.