Every compliance audit eventually reveals the same pattern: the auditor does not test every record. They select a portion of the available evidence and use those results to evaluate the broader population. At first, this can look like a shortcut. In reality, audit sampling is a structured audit technique designed to support reliable conclusions about a much larger set of records.
Audit sampling means applying an audit procedure to less than 100% of a population while selecting items that provide a reasonable basis for evaluating the population as a whole. In practice, auditors define the population, determine an appropriate sample, select items independently, and evaluate the results against the relevant control requirements. The quality of that process matters because a poorly selected sample can produce a misleading conclusion about the underlying population.
For compliance audits, sampling plays a central role in testing controls that operate repeatedly throughout an audit period. Access reviews, change approvals, employee offboarding, incident handling, and other recurring activities can generate large volumes of records. Testing every record would rarely be practical. Instead, auditors use appropriate sampling methods to obtain sufficient appropriate evidence while managing sampling risk.
This guide explains what sampling in auditing involves, the methods auditors use, how sample sizes are determined, and how sampling works in SOC 2 and ISO 27001 engagements. It also examines how auditors evaluate deviations when a selected item fails the expected control requirement.
Concern
Teams that misunderstand audit sampling prepare for audits backwards: they polish a handful of favorable examples while the auditor is designing a selection they cannot predict from a population they must provide in full. One broken item in a representative sample projects across the entire population, which is how a single unrevoked account becomes a control finding rather than an isolated miss.
Overview
Auditors sample because full testing is neither feasible nor required; standards such as AS 2315, AU-C 530, and ISA 530 govern how. Two approaches exist, statistical and non-statistical, both valid when applied with professional judgment. Selection techniques include random, systematic, haphazard, and block selection, with stratification for mixed populations. Audit sample size scales with control frequency, risk, and population size, and no governing body mandates fixed sizes for SOC 2 or ISO 27001 engagements.
Solution
Prepare for compliance audit sampling by protecting what sampling depends on: complete populations exported from source systems, evidence that exists for every item rather than a curated subset, and internal self-sampling that finds broken chains before the auditor does. Organizations that run their own sample testing quarterly meet audit selections with records that already exist.
What Is Sampling in Auditing?
What is sampling in auditing? It is the selection and evaluation of less than the full population of audit-relevant items, designed to support a reasonable conclusion about the population. In practice, the auditor selects items, tests the related evidence, evaluates deviations, and considers whether the results support a conclusion about the broader population. This approach allows compliance auditors to assess control performance without examining every record.
Audit sampling exists because exhaustive testing is often impractical and provides limited additional value. A year of operations at a mid-sized organization can produce thousands of access events, change tickets, approvals, incidents, and other control records. As a result, testing every item would consume significant audit resources. Sampling provides a practical basis for obtaining sufficient appropriate evidence while maintaining a defined level of assurance. Standards such as AS 2315, AU-C 530, and ISA 530 establish principles for applying audit sampling within their respective assurance contexts.
The key consideration is sampling risk, which is the possibility that the selected sample does not adequately represent the population and leads the auditor to an incorrect conclusion. Therefore, every element of audit sampling, from population definition and selection method to sample size and deviation evaluation, addresses this risk. Auditors also retain control over sample selection because allowing the organization to choose the items could introduce selection bias. For compliance audits, this independence matters when testing access reviews, change management, employee terminations, incident records, and other control populations. Understanding sampling risk explains why auditors request complete populations, select their own items, and investigate deviations rather than relying on records chosen by the organization.
Audit Sampling Methods: Statistical and Non-Statistical
Statistical sampling in auditing uses random selection and probability theory to evaluate sampling risk and support conclusions at a defined confidence level. By contrast, non-statistical sampling relies primarily on professional judgment when selecting and evaluating items. Both approaches can produce sufficient appropriate evidence when properly designed and applied. The appropriate method depends on the population, audit objective, risk, and available information.
The choice is practical. Statistical selection requires a complete, accurate, and randomizable population, along with additional setup. Therefore, it works well for large, relatively homogeneous populations where measurable sampling risk adds value. Judgment-based selection can suit smaller populations, particularly when testing a substantial portion of the population is practical. However, a well-designed non-statistical sample should generally be comparable in size to an equivalent statistical sample, while the auditor must remain alert to selection bias.
Within these approaches, four selection techniques commonly appear in audit sampling:
- Random Selection
Every population item has an equal chance of selection, typically through a random number generator. It forms the foundation of statistical sampling.
- Systematic Selection
The auditor selects every nth item after establishing a random starting point, such as every twentieth change ticket. However, the population should not contain a pattern that could distort the selection.
- Haphazard Selection
The auditor selects items without a structured technique while avoiding conscious bias. It can support non-statistical sampling but does not provide the randomness required for statistical designs.
- Block Selection
The auditor selects a contiguous group, such as March termination records. Because one block may not represent the full period, auditors generally use this technique selectively.
Stratification can supplement these techniques by dividing a population into meaningful groups, such as privileged and standard accounts or emergency and routine changes. As a result, higher-risk groups can receive focused testing. Regardless of the method, selected items must then be evaluated against the standards for audit evidence, with each item traced to dated, verifiable records.
How Auditors Determine Audit Sample Size
Audit sample size is determined through professional judgment rather than a universal mandated table. For SOC 2 and ISO 27001 engagements, auditors consider the control's frequency, associated risk, population size, tolerable deviation rate, and expected deviation rate. As a result, two controls with the same frequency can require different sample sizes when their risk profiles differ.
Frequency provides a practical starting point. Common audit sampling conventions for control testing often use smaller samples for infrequent controls and larger samples for frequent controls. For example, annual controls may involve one test, quarterly controls around two, monthly controls two to five, weekly controls five to fifteen, and daily or continuous controls roughly twenty to forty. These ranges are conventions, not fixed requirements, and the appropriate sample remains dependent on the audit objective and risk.
Risk then adjusts the baseline. As control risk increases, auditors generally require stronger and more extensive evidence. In audit sampling, that can mean larger samples, stratified selections, or a lower tolerance for deviations. For example, a quarterly access review protecting production data may receive more testing than a quarterly visitor-log review, even though both operate at the same frequency.
Therefore, organizations should avoid treating sample size as a universal compliance formula. Auditors assess the control objective, population, frequency, risk, and expected exceptions before selecting an appropriate approach. Uniform sample sizes across controls with materially different risks can indicate that testing relies on a template rather than professional judgment. In addition, the auditor considers how much sampling risk is acceptable and whether the selected evidence provides a reasonable basis for the conclusion. A larger population does not automatically require a proportionally larger sample. Instead, the relationship between risk, expected deviations, and desired assurance drives the testing decision.
Sample Testing Audit Mechanics in SOC 2 and ISO 27001
Every audit sampling sequence follows three core steps: define the population, determine an appropriate sample, and test selected items against the control. In a SOC 2 Type II examination, this process supports operating effectiveness testing. For each in-scope control, the auditor establishes the relevant population for the review period, selects items, and traces each one through its supporting records.
The population step often creates the biggest challenge. Auditors request populations directly from source systems, such as every account created, every production change, or every employee departure. This approach helps preserve representativeness before selection begins. Auditors also consider timing. SOC 2 auditors review evidence over time, so selections should provide coverage across the examination period. As a result, a control that operated inconsistently during the year can surface through sample testing.
ISO 27001 engagements apply similar sampling principles within the certification process. Auditors may sample applicable controls, personnel, records, and operational activities based on the audit objectives and available evidence. The ISO 27001 internal audit should also use appropriate sampling when testing the effectiveness of the management system. However, a fixed percentage does not automatically determine an appropriate sample. Risk, population characteristics, audit objectives, and auditor judgment all influence the approach.
Deviation handling completes the process. When a selected item fails the control requirement, the auditor considers whether it represents an isolated exception or indicates a broader control issue. Depending on the results, the auditor may expand testing, obtain additional evidence, or reconsider the conclusion. One unrevoked account among 25 sampled departures represents a four percent deviation rate within that sample. The auditor must then evaluate what that result means for the underlying population before reaching a conclusion.
Preparing for Compliance Audit Sampling
Organizations cannot choose an auditor's selections, and they should not try. Audit sampling depends on independent selection, so preparation should focus on the populations and records those selections will test. In practice, that means keeping populations complete, source records reliable, and control processes consistent before the audit begins.
- Protect Population Integrity
Every compliance control should have a defined system of record from which the full population can be retrieved. For example, the HR system can provide employee departures, the ticketing platform can provide production changes, and the identity platform can provide access events. As a result, auditors can trace selected items to an authoritative source rather than a manually prepared list. Automated evidence collection can preserve timestamps, source details, and complete populations throughout the audit period.
- Sample Before the Auditor
Perform internal testing at regular intervals using the same principles applied during audit sampling. For example, select items from the full population, trace each one from initiation through completion, and verify dates, approvals, and supporting records. This approach can reveal broken evidence chains before fieldwork begins and give the organization time to investigate deviations.
- Fix the Process
When testing identifies a deviation, address the process that produced it rather than correcting only the selected item. For instance, if an access review misses a departing employee, investigate why the workflow failed and determine how the next case will be captured. Likewise, document the corrective action and verify that it works. A process-level fix addresses the wider population and gives auditors stronger evidence that the deviation was properly managed.
Conclusion
Audit sampling is the machinery that lets a few dozen selections speak for a year of operations, and it is engineered, through representativeness, risk-scaled sizing, and deviation projection, to make those selections trustworthy. Teams that understand the machinery stop optimizing for the wrong thing. The goal is not favorable samples; it is populations in which every item would pass.
That reframing is the practical takeaway. When controls run consistently, populations export completely, and self-testing runs on the same logic the auditor will use, audit sampling becomes uneventful by design: whatever twenty-five items the selection lands on, the chain holds. Preparation of that kind does not just pass audits. It is the condition the audit was trying to verify in the first place.
At CertPro, sampling is our daily work: as a licensed CPA firm enrolled in the AICPA Peer Review Program, we design and execute samples across SOC 2 attestations and ISO 27001 certification audits worldwide, sizing selections to risk, verifying populations at the source, and documenting deviations with the precision that makes remediation clear. For organizations preparing for their first examination or tightening an existing program, our SOC 2 certification services cover readiness through Type II reporting.


