Two sampling risks, two consequences
| Test type | Risk affecting EFFICIENCY | Risk affecting EFFECTIVENESS |
|---|---|---|
| Tests of controls | Risk of assessing control risk too high (under-reliance) | Risk of assessing control risk too low (over-reliance) |
| Substantive tests | Risk of incorrect rejection | Risk of incorrect acceptance |
IMPORTANT: Efficiency risks make the auditor do more work than necessary — costly but not dangerous. Effectiveness risks (over-reliance, incorrect acceptance) mean the auditor reaches a wrong conclusion — this is the risk that matters most and drives sample size.
What drives sample size
| Factor | Effect on sample size |
|---|---|
| Higher risk of material misstatement | Increase |
| Higher tolerable misstatement / tolerable rate | Decrease |
| Higher expected misstatement / deviation rate | Increase |
| Larger population | Almost no effect (for large populations) |
| Higher desired confidence (lower acceptable sampling risk) | Increase |
Attribute vs. variables sampling
- Attribute sampling — used in tests of controls; measures a rate of deviation (yes/no: did the control operate?). Compare the computed upper deviation rate to the tolerable rate.
- Variables sampling — used in substantive tests; estimates a dollar amount of misstatement.
- PPS (probability-proportional-to-size) sampling — a hybrid using attribute theory to reach a dollar conclusion. It automatically emphasizes larger items and is efficient when few misstatements are expected — but it is not effective for detecting understatement and struggles with zero or negative balances.
EXAMPLE: The tolerable deviation rate is 6%. The sample of 60 items contains 2 deviations, giving a 3.3% sample deviation rate; the computed upper deviation rate is 7.4%. Because the upper deviation rate exceeds the tolerable rate, the auditor cannot rely on the control as planned — despite the sample rate being below tolerable.
EXAM TIP: The auditor must always project misstatements found in the sample to the whole population, and consider both projected misstatement and any known/specific misstatements when evaluating results.