Sampling in Internal Audit

Sampling in Internal Audit: SIA 5 Guide

Table of Contents:-

Sampling in internal audit enables an internal auditor to examine selected transactions or items from a larger population instead of testing every transaction.

When properly designed and performed, audit sampling helps the internal auditor obtain sufficient appropriate evidence about a population while conducting the audit efficiently.

The Institute of Chartered Accountants of India (ICAI) has issued Standard on Internal Audit (SIA) 5 – Sampling, which provides guidance relating to the design and selection of audit samples, use of statistical and non-statistical sampling, evaluation of sample results and documentation.

Companies looking for professional support with internal audit, controls and risk reviews may also refer to our Internal Audit Services in India.

What Is Sampling in Internal Audit?

Audit sampling means applying internal audit procedures to less than 100% of the items in a population so that the internal auditor can obtain and evaluate evidence about selected characteristics and form a conclusion about the population.

For example, if a company has 20,000 purchase transactions during a financial year, the internal auditor may not need to examine every invoice.

Instead, the auditor may select an appropriate sample considering factors such as:

  • audit objectives;
  • size of the population;
  • risk involved;
  • nature of transactions;
  • expected error or deviation;
  • tolerable error;
  • internal controls; and
  • professional judgement.

The objective is not merely to reduce audit work. The sample must be appropriately designed so that the evidence obtained supports the internal audit conclusion.

The detailed professional framework can be referred to in the ICAI Compendium of Standards on Internal Audit.

SIA 5 – Sampling

SIA 5 provides guidance on the use of sampling in internal audit engagements.

The Standard broadly deals with:

  • meaning and concepts of audit sampling;
  • use of sampling in risk assessment and tests of controls;
  • design of the sample;
  • determination of sample size;
  • statistical and non-statistical approaches;
  • selection of sample items;
  • evaluation of sample results; and
  • documentation.

ICAI currently includes SIA 5 within its Standards on Internal Audit framework. Companies and professionals may refer to the ICAI Internal Audit Standards Board for the latest Standards, technical guides and publications.

Key Terms Used in Audit Sampling

Understanding the terminology is important before designing an audit sample.

Population

Population means the complete set of items from which the auditor intends to select a sample.

Examples include:

  • all purchase invoices during the year;
  • all sales invoices;
  • all employees in the payroll;
  • all fixed asset additions;
  • all journal entries;
  • all vendor payments; or
  • all inventory transactions.

The population must be relevant to the audit objective.

Sampling Unit

A sampling unit is an individual item forming part of the population.

Depending on the audit procedure, this may be:

  • an invoice;
  • payment;
  • purchase order;
  • employee;
  • journal entry;
  • customer balance;
  • vendor balance; or
  • inventory item.

Sampling Risk

Sampling risk is the risk that the conclusion reached from the selected sample may differ from the conclusion that would have been reached if the entire population had been examined.

Because only part of the population is tested, sampling risk cannot normally be eliminated completely. It should instead be reduced to an acceptable level through appropriate sample design and sample size.

Tolerable Error or Deviation

Tolerable error represents the maximum level of error or deviation that the auditor is willing to accept without changing the conclusion relating to the population.

Expected Error

Expected error is the level of error or deviation that the auditor anticipates may exist in the population based on factors such as:

  • previous audits;
  • preliminary testing;
  • understanding of controls;
  • known control deficiencies; and
  • nature of the transactions.

Why Is Sampling Used in Internal Audit?

Sampling is useful where testing every transaction would be impractical, inefficient or unnecessary.

It helps the internal auditor:

  • obtain audit evidence efficiently;
  • focus resources on significant risks;
  • test whether internal controls are functioning;
  • identify exceptions and control failures;
  • evaluate transaction accuracy;
  • draw conclusions about a larger population; and
  • perform broader audit coverage within available time and resources.

However, sampling should not automatically be used for every audit procedure.

Certain high-risk, unusual or individually significant items may warrant 100% examination.

When Is 100% Testing More Appropriate?

Internal auditors may consider examining all items where:

  • the population is small;
  • individual transactions are highly significant;
  • fraud risk is high;
  • regulatory exposure is significant;
  • transactions are unusual or non-routine;
  • management override is suspected;
  • automated testing makes full-population analysis practical; or
  • the audit objective requires examination of all relevant items.

For example, instead of sampling payments made to related parties, the auditor may decide to examine all related-party payments during the period.

Sampling therefore complements rather than replaces professional judgement.

Sampling in Risk Assessment Procedures

Sampling may help internal auditors better understand:

  • the organisation;
  • major business processes;
  • transaction flows;
  • internal controls;
  • compliance risks;
  • financial risks;
  • fraud exposure; and
  • operational weaknesses.

However, the nature and extent of sampling should be aligned with the specific audit objective.

A risk-based approach helps determine where larger or more targeted samples may be appropriate.

Read more about the broader audit framework in our Internal Audit Checklist for Companies in India.

Sampling for Tests of Controls

Internal auditors frequently use sampling to determine whether a control has operated consistently during the period under review.

Examples include testing whether:

  • purchase orders were approved;
  • vendor creation was authorised;
  • bank payments had maker-checker approval;
  • credit notes were approved;
  • bank reconciliations were reviewed;
  • employee reimbursements were authorised; or
  • physical inventory verification controls were performed.

The population selected for testing should correspond to the control being evaluated.

Example of Control Testing

Suppose company policy requires every purchase above a specified value to be approved by the Purchase Head.

The internal auditor may:

  1. obtain the population of applicable purchase transactions;
  2. verify completeness of the population;
  3. select an appropriate sample;
  4. inspect supporting approvals;
  5. identify exceptions;
  6. investigate the reason for each exception; and
  7. evaluate whether the control can be relied upon.

A finding that one sample lacks approval does not automatically mean the entire process has failed. The auditor needs to evaluate the nature, frequency and significance of exceptions.

Designing the Audit Sample

SIA 5 requires the internal auditor to appropriately design the sample having regard to the audit objectives and characteristics of the population.

Important considerations include:

  • purpose of the audit procedure;
  • population being tested;
  • completeness of the population;
  • nature and frequency of the control;
  • risk of material error or control failure;
  • expected error;
  • tolerable error;
  • sample selection methodology; and
  • extent of reliance to be placed on the results.

A poorly defined population can undermine the reliability of the sampling exercise regardless of sample size.

Determine the Audit Objective First

Before selecting transactions, the auditor should clearly determine:

What am I trying to establish through this test?

For example:

Objective: Determine whether vendor payments are made only after appropriate approval.

The relevant population would be vendor payments, not merely purchase invoices.

Similarly:

Objective: Determine whether customer credit limits are properly authorised.

The population may be customer master changes or credit-limit approvals.

The audit objective should therefore drive the population and sampling approach.

Completeness of Population

Before selecting the sample, the auditor should consider whether the data represents the complete population.

This may involve:

  • reconciling system reports with the general ledger;
  • checking opening and closing sequence numbers;
  • comparing transaction counts with accounting records;
  • reconciling totals with financial statements; or
  • obtaining system-generated reports directly.

Sampling from an incomplete population can produce misleading audit conclusions.

Stratification of Population

In some cases, the auditor may divide a population into separate groups based on common characteristics.

This is known as stratification.

For example, purchase transactions may be divided into:

  • transactions above ₹10 lakh;
  • transactions between ₹1 lakh and ₹10 lakh; and
  • transactions below ₹1 lakh.

The auditor may examine all high-value transactions while sampling smaller transactions.

Stratification can improve audit efficiency by allowing different risk levels to receive different levels of testing.

Determining Sample Size

There is no single sample size appropriate for every internal audit.

Sample size depends upon several factors, including:

  • size of population;
  • risk assessment;
  • control frequency;
  • expected deviation;
  • tolerable deviation;
  • nature of the audit procedure;
  • reliance to be placed on the control;
  • previous audit findings; and
  • auditor’s professional judgement.

Generally, where greater assurance is required or higher risk exists, more extensive testing may be necessary.

Sample size should not be selected merely because a fixed number—such as 10 or 20 transactions—has traditionally been used.

The rationale should relate to the audit objective and risks.

Factors That May Increase Sample Size

A larger sample may be appropriate where:

  • control risk is high;
  • expected error is high;
  • tolerable error is low;
  • the auditor requires greater assurance;
  • previous audits identified significant exceptions;
  • processes have recently changed;
  • employees responsible for controls have changed; or
  • the population is heterogeneous.

Factors That May Reduce Sample Size

A smaller sample may sometimes be appropriate where:

  • risk is relatively low;
  • controls are strongly designed;
  • previous testing showed few exceptions;
  • automation reduces the likelihood of manual error;
  • other audit procedures provide additional evidence; or
  • the population is relatively homogeneous.

Any decision should be supported by professional judgement and properly documented.

Statistical and Non-Statistical Sampling

SIA 5 recognises both statistical and non-statistical sampling approaches.

The choice depends upon the audit objective, circumstances and professional judgement.

Statistical Sampling

Statistical sampling uses probability-based techniques for selecting and evaluating samples.

Common characteristics include:

  • random selection;
  • known probability of selection;
  • mathematical evaluation of sampling risk; and
  • ability to project results using statistical principles.

Statistical methods can provide a more objective basis for evaluating sampling risk where properly applied.

Non-Statistical Sampling

Non-statistical sampling relies more extensively on professional judgement.

The auditor determines:

  • sample size;
  • selection criteria;
  • transactions to be examined; and
  • evaluation of results

without necessarily applying formal statistical methods.

Non-statistical sampling can still provide appropriate audit evidence when properly designed and documented.

Methods of Selecting Audit Samples

Different methods may be used depending upon the circumstances.

Random Selection

Every item in the population has an appropriate opportunity of being selected.

Random selection may be performed using:

  • random-number generators;
  • spreadsheet tools;
  • audit software; or
  • computer-assisted audit techniques.

Systematic Selection

The auditor selects items using a fixed interval after choosing an appropriate starting point.

For example, if the population has 1,000 transactions and the auditor intends to select 50:

Sampling interval = 1,000 ÷ 50 = 20

The auditor may then select every twentieth transaction after determining an initial starting point.

The auditor should ensure that the transaction sequence does not contain a pattern that could distort the sample.

Haphazard Selection

Under haphazard selection, transactions are selected without using a structured statistical technique while avoiding conscious bias.

The auditor should take care not to select only items that are:

  • easy to locate;
  • high value;
  • recent;
  • visually unusual; or
  • supplied selectively by management.

Use of Data Analytics and Audit Tools

Modern internal audits may use data analytics and audit software to:

  • generate random samples;
  • identify duplicate transactions;
  • detect unusual entries;
  • analyse full populations;
  • identify transactions on holidays;
  • identify payments below approval limits;
  • analyse vendor concentration; and
  • flag unusual journal entries.

Technology can therefore supplement traditional sampling and, in some cases, make full-population testing possible.

High-Value and High-Risk Items

Purely random sampling may not always adequately address significant risks.

An effective internal audit approach may therefore combine:

100% testing of high-risk/high-value items + sampling of the remaining population.

For example:

A population contains 5,000 vendor payments.

The auditor may examine:

  • all payments above ₹10 lakh;
  • all payments to related parties;
  • all payments to newly created vendors;
  • all unusual manual payments; and
  • a representative sample of remaining transactions.

This approach gives greater attention to transactions carrying higher risk.

Sampling in Purchase Audit

Possible purchase samples may include:

  • purchase requisitions;
  • quotations;
  • purchase orders;
  • vendor invoices;
  • goods receipt notes;
  • payments;
  • vendor master changes; and
  • purchase returns.

The sample may test whether procurement controls described in the company’s policy have been followed.

Sampling in Sales Audit

Samples may cover:

  • sales orders;
  • customer approvals;
  • invoices;
  • dispatch documents;
  • discounts;
  • credit notes;
  • sales returns;
  • customer credit limits; and
  • collections.

The auditor may also separately select high-value and unusual transactions.

Sampling in Payroll Audit

The internal auditor may select employees to verify:

  • appointment letter;
  • salary structure;
  • attendance;
  • payroll computation;
  • deductions;
  • bank payment;
  • PF/ESI;
  • TDS;
  • reimbursement; and
  • full and final settlement.

Separate attention may be given to:

  • newly joined employees;
  • resigned employees;
  • unusually high salary changes; and
  • changes in employee bank accounts.

Sampling in Expense Audit

Expense testing may cover:

  • invoice;
  • business purpose;
  • supporting documents;
  • approval;
  • GST;
  • TDS;
  • accounting classification;
  • payment; and
  • policy compliance.

Risk-based samples may specifically include:

  • weekend/holiday transactions;
  • round-value payments;
  • payments just below approval limits;
  • unusual vendors;
  • cash expenses; and
  • duplicate invoice numbers.

Sampling in Inventory Audit

Samples may be selected for:

  • physical inventory counts;
  • goods receipt;
  • stock issues;
  • valuation;
  • slow-moving items;
  • obsolete inventory;
  • stock adjustments; and
  • high-value items.

Inventory sampling should consider both:

book-to-floor testing – selecting items from records and verifying physical existence; and

floor-to-book testing – selecting physical items and ensuring they are recorded.

This helps address both existence and completeness risks.

Sampling in Fixed Asset Audit

Sample selection may include:

  • additions;
  • disposals;
  • high-value assets;
  • physical verification;
  • depreciation;
  • capitalisation;
  • repairs charged as assets; and
  • assets located at different sites.

High-value or unusual additions may be examined separately rather than included only in a random sample.

Sampling in Bank and Payment Audit

The auditor may examine samples of:

  • vendor payments;
  • employee payments;
  • manual bank transfers;
  • large payments;
  • beneficiary changes;
  • payments made outside normal business hours; and
  • payments immediately after vendor bank-detail changes.

Maker-checker approvals and supporting documents should be verified.

Evaluation of Sample Results

Selecting transactions is only one part of audit sampling.

The auditor must evaluate the results.

This may involve:

  • identifying errors and deviations;
  • understanding their nature;
  • determining their cause;
  • evaluating whether errors are isolated or systematic;
  • considering possible fraud;
  • assessing the impact on other transactions;
  • projecting errors where appropriate;
  • reconsidering risk assessment; and
  • deciding whether additional testing is required.

The purpose is to determine whether the sample provides reasonable support for a conclusion about the population.

Nature and Cause of Errors

Each exception should be analysed.

For example:

Finding: 3 out of 25 purchase samples did not contain required approval.

Possible causes may include:

  • policy not communicated;
  • system allows control override;
  • retrospective approval;
  • inadequate segregation of duties;
  • staff shortage; or
  • deliberate control circumvention.

Understanding the root cause is often more valuable than merely reporting the number of exceptions.

Projecting Sample Errors

Depending upon the type of sampling and audit objective, the auditor may need to consider whether identified errors suggest a wider issue within the population.

Where an error appears systematic rather than isolated, additional procedures may be necessary.

The auditor should avoid assuming that an exception is insignificant merely because only one item was found in the sample.

Reassessing Sampling Risk

If sample results contain more errors or deviations than expected, the auditor may need to:

  • increase the sample;
  • perform alternative procedures;
  • expand testing to other periods;
  • examine additional locations;
  • reconsider reliance on the control;
  • reassess risk; or
  • perform 100% testing of a particular category.

Sampling is therefore an iterative process rather than simply selecting a fixed number of transactions.

Documentation of Audit Sampling

SIA 5 requires appropriate documentation relating to sampling.

Working papers should ordinarily record matters such as:

  • audit objective;
  • population;
  • source of population;
  • completeness checks;
  • sampling unit;
  • risk assessment;
  • sample size;
  • basis for determining sample size;
  • selection method;
  • individual items selected;
  • procedures performed;
  • exceptions identified;
  • evaluation of exceptions;
  • conclusions; and
  • additional procedures performed.

The documentation should enable an experienced reviewer to understand why the sample was selected and how the auditor reached the conclusion.

Example of Audit Sampling

Suppose an organisation has 12,000 purchase invoices during the year.

The internal auditor wants to determine whether purchase transactions have:

  • valid purchase orders;
  • required approvals;
  • goods receipt evidence; and
  • appropriate vendor invoices.

The auditor may first identify:

  • high-value transactions;
  • related-party transactions;
  • new vendors;
  • unusual transactions; and
  • other high-risk transactions.

These may be tested separately.

The remaining population may then be sampled using an appropriate statistical or non-statistical approach.

If several transactions in the sample show missing approvals, the auditor may expand testing and reassess the procurement control environment.

This demonstrates why sample selection should be linked to the audit objective and risk, rather than simply picking transactions randomly.

Common Mistakes in Internal Audit Sampling

Internal auditors should avoid practices such as:

  • selecting the same sample size for every audit;
  • selecting only easily available documents;
  • taking samples supplied by management without validating the population;
  • ignoring high-risk transactions;
  • failing to verify population completeness;
  • using only high-value items and calling them a representative sample;
  • failing to investigate exceptions;
  • failing to document the basis of sample size;
  • treating every exception as isolated; and
  • drawing conclusions unsupported by the sample.

Sampling and Professional Judgement

No sampling technique can eliminate the need for professional judgement.

The internal auditor should consider:

  • audit objectives;
  • risk;
  • materiality/significance;
  • control environment;
  • nature of transactions;
  • expected errors;
  • available data; and
  • reliability of audit evidence.

The sampling methodology should always support the objective of the internal audit engagement.

Sampling and Risk-Based Internal Audit

Sampling becomes particularly effective when incorporated into a risk-based internal audit approach.

Higher-risk areas may receive:

  • larger samples;
  • more targeted samples;
  • greater use of data analytics; or
  • 100% testing.

Lower-risk areas may require comparatively limited testing where adequate evidence is otherwise available.

This enables internal audit resources to focus on matters carrying greater potential impact.

Sampling vs 100% Examination

There is no rule that internal audit must always rely on sampling.

The appropriate approach may be:

  • sampling;
  • 100% examination;
  • analytical review;
  • data analytics;
  • control testing;
  • enquiry and observation; or
  • a combination of techniques.

The method selected should be capable of generating evidence appropriate to the audit objective.

Frequently Asked Questions

What is sampling in internal audit?

Sampling in internal audit means applying audit procedures to less than 100% of a population so that the auditor can evaluate selected items and draw an appropriate conclusion about the population.

Which ICAI Standard covers sampling in internal audit?

ICAI’s Standard on Internal Audit (SIA) 5 – Sampling provides guidance regarding audit sampling in internal audit engagements.

The latest Standards and Compendium can be accessed through the ICAI Internal Audit Standards Board.

Is statistical sampling compulsory?

No. SIA 5 recognises both statistical and non-statistical sampling approaches. The appropriate method depends upon the engagement circumstances and professional judgement.

How is audit sample size determined?

Sample size may depend upon the population, risk, expected error, tolerable error, control frequency, audit objective and the degree of assurance required.

Does a larger population always require a proportionately larger sample?

Not necessarily. Population size is only one of several factors influencing sample size. Risk, expected deviations, tolerable deviations and the audit objective may be more significant considerations.

What are common methods of selecting an audit sample?

Common methods include random selection, systematic selection and haphazard selection. Data analytics and computer-assisted techniques can also assist sample selection.

Can an internal auditor examine 100% of transactions?

Yes. Full-population testing may be appropriate where the population is small, risks are particularly high, transactions are individually significant or technology makes complete testing practical.

What happens if errors are found in the sample?

The auditor should understand the nature and cause of the errors, evaluate their implications, reconsider sampling risk and determine whether further testing or expanded procedures are required.

Is audit sampling useful only for financial transactions?

No. Sampling can also be used for testing operational controls, procurement, payroll, inventory, compliance, IT access, HR records and various other business processes.

Is sampling the same as random selection?

No. Random selection is one method of selecting a sample. Audit sampling is the broader process involving sample design, selection, testing, evaluation and documentation.

Internal Audit Services in India

EzyBiz India Consulting LLP assists Indian and foreign-owned companies with internal audit, risk assessment, internal control reviews, process audits and compliance reviews.

Our approach combines risk-based audit planning, transaction testing, process evaluation and practical recommendations designed to strengthen internal controls.

Learn more about our Internal Audit Services in India or explore our broader Audit and Assurance Services in India.

Related Services

Authoritative References

Prepared By: EzyBiz India Consulting LLP
Reviewed By: Anil Agrawal, Chartered Accountant
Last Updated: August 2026

Disclaimer

The information provided on this page is for general informational and educational purposes only and should not be construed as audit, legal, accounting or regulatory advice. The nature and extent of audit sampling depend upon the objectives, risks, population characteristics, internal controls and professional judgement applicable to each engagement. Audit procedures and sample sizes should therefore be determined based on the specific facts and circumstances and the applicable professional standards. Readers should obtain appropriate professional advice before relying on this information.