CPA Exam · 10 min read Updated

CPA Auditing & Attestation: Statistical vs non-statistical sampling — Complete Study Guide

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

Key Takeaways

  • CPA Exam Section: Auditing & Attestation (AUD)
  • Primary Application: Tests of Controls (Attribute Sampling) & Substantive Tests (Variable Sampling)
  • Statistical Sampling: Quantifies sampling risk; requires random selection.
  • Non-statistical Sampling: Relies on auditor judgment; does not quantify sampling risk.
  • Key Risk (Controls): Risk of Over-reliance (assessing control risk too low).
  • Key Risk (Substantive): Risk of Incorrect Acceptance (concluding no material misstatement when one exists).

You think the hard part of audit sampling is memorizing the formulas for sample size. That assumption is the #1 reason candidates misapply these concepts under pressure, especially in task-based simulations. The real trap isn't the math; it's the judgment call—choosing the wrong tool for the audit objective and being unable to defend why.

Quick answer

Statistical sampling uses random selection and probability theory to objectively measure and control sampling risk, allowing auditors to make quantifiable conclusions about a population. Non-statistical sampling relies on auditor judgment to select and evaluate samples, offering flexibility but no mathematical measurement of sampling risk.

Key facts

  • CPA Exam Section: Auditing & Attestation (AUD)
  • Primary Application: Tests of Controls (Attribute Sampling) & Substantive Tests (Variable Sampling)
  • Statistical Sampling: Quantifies sampling risk; requires random selection.
  • Non-statistical Sampling: Relies on auditor judgment; does not quantify sampling risk.
  • Key Risk (Controls): Risk of Over-reliance (assessing control risk too low).
  • Key Risk (Substantive): Risk of Incorrect Acceptance (concluding no material misstatement when one exists).

What's the Core Difference Between Statistical and Non-Statistical Sampling?

The fundamental difference is that statistical sampling allows you to mathematically measure and control sampling risk, while non-statistical sampling does not. Statistical methods use probability theory to design an efficient sample, measure the sufficiency of evidence, and evaluate results with a specific confidence level (e.g., "we are 95% confident..."). Non-statistical sampling relies entirely on the auditor's professional judgment and experience to perform these same steps, which can be effective but lacks the objective defensibility of a statistical approach.

On the AUD exam, you won't just be asked for definitions. You'll get scenarios where you must decide which method is more appropriate, justify the sample size, and interpret the results. The examiners want to see if you can weigh the trade-offs between the objectivity of statistical methods and the efficiency of judgmental ones. Try VoraPrep's free CPA practice questions to see how these scenarios are tested.

Free 5-Min Diagnostic

Studying for CPA AUD? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

Here’s a clear breakdown of the key distinctions:

FeatureStatistical SamplingNon-Statistical Sampling
Sample SelectionMust be random (e.g., random number generator, systematic selection with a random start).Can be judgmental (e.g., haphazard, block, or targeting specific high-risk items).
Risk MeasurementSampling risk is quantified using probability theory (e.g., 5% risk of incorrect acceptance).Sampling risk is qualitatively assessed based on auditor judgment (e.g., "low," "moderate").
ObjectivityHigh. Conclusions are mathematically defensible and repeatable.Lower. Relies heavily on auditor experience and is more subjective.
Primary Use CaseLarge, homogenous populations where an objective conclusion is needed (e.g., testing revenue transactions).Populations with a few individually significant items, or when a quick, targeted test is sufficient.
DefensibilityStronger basis for defending conclusions to regulators or in litigation.Weaker, as it's harder to prove the sample was representative without mathematical support.

How Do Key Factors Affect Your Sample Size?

Determining the right sample size is a critical skill tested on the AUD exam, and the logic applies to both methods, even if the calculation is only explicit in statistical sampling.

The sample size for a test of controls (attribute sampling) is driven by three key factors. Understanding their relationships is more important than memorizing a formula:

  1. Tolerable Deviation Rate (TDR): The maximum rate of control failures you're willing to accept.
  • Relationship: Inverse. If you can tolerate more errors (a higher TDR), you need a smaller sample. You're less concerned, so you need less evidence.
  1. Expected Population Deviation Rate (EPDR): The rate of errors you actually expect to find.
  • Relationship: Direct. If you expect to find more errors (a higher EPDR), you need a larger sample to confirm your assessment.
  1. Acceptable Risk of Over-reliance (ARO): The risk you're willing to take of concluding a control is effective when it's not. This is the complement of the confidence level (e.g., a 5% ARO corresponds to a 95% confidence level).
  • Relationship: Inverse. If you want to take less risk (a lower ARO), you need more assurance, which requires a larger sample.
The Population Size Trap: A common exam trick involves population size. For attribute sampling, once a population reaches a certain size (e.g., over 2,000 items), its size has a negligible effect on the sample size. However, for some classical variables sampling methods used in substantive testing, population size does directly impact the sample size. Be sure you know which type of sampling the question is asking about.

What Are Sampling Risk and Non-Sampling Risk?

Auditors face two types of risk when sampling, and the exam expects you to know the difference.

✨ Free Interactive Tool

Check Your State’s Exact CPA Exam Requirements

Every state has different credit hour, ethics, and residency rules. Use our 55-jurisdiction checker to verify your eligibility before applying.

Check State Requirements →
Sampling risk is the risk that your conclusion based on a sample might be different from the conclusion you would reach if you tested the entire population. It's the inherent uncertainty of not looking at everything. This risk is present in both statistical and non-statistical sampling, but it can only be measured with statistical methods.

There are two "sides" to sampling risk:

  • For Tests of Controls:
  • Risk of Over-reliance (Assessing Control Risk Too Low): The sample indicates controls are effective, but they're not. This is the more dangerous risk, as it impacts audit effectiveness.
  • Risk of Under-reliance (Assessing Control Risk Too High): The sample indicates controls are ineffective, but they actually are. This impacts audit efficiency, as it leads to more substantive testing than necessary.
  • For Substantive Tests:
  • Risk of Incorrect Acceptance: The sample indicates no material misstatement, but one exists. This is a major audit failure (effectiveness).
  • Risk of Incorrect Rejection: The sample indicates a material misstatement, but one doesn't exist. This impacts efficiency.
Non-sampling risk includes all other aspects of audit risk that are not due to sampling. It's the risk of human error—things like selecting inappropriate audit procedures, misinterpreting evidence, or failing to recognize a misstatement. This risk can be reduced through proper planning, supervision, and review, but it exists whether you sample or test 100% of the population.

Worked Example: Choosing the Right Sampling Method

Let's walk through a realistic AUD scenario. This isn't about formulas; it's about judgment.

Scenario: You are the audit senior for Aero Components, a manufacturing firm. You are planning the substantive testing for accounts receivable, which has a balance of $10 million, composed of 4,000 customer accounts. Your risk assessment reveals the following:
  • Population A: 3,950 accounts, totaling $4 million. These are small, routine balances with customers who have a long history of timely payments. Control risk is assessed as low.
  • Population B: 50 accounts, totaling $6 million. These are large, individually significant balances, including several new international customers with non-standard payment terms.
Question: How would you design your sampling approach for Populations A and B? Justify your choice of statistical or non-statistical sampling for each. Step-by-Step Thought Process:
  1. Analyze the Audit Objective: The goal is substantive testing of accounts receivable, likely focusing on the existence and valuation assertions. This means you're testing for monetary misstatements.
  2. Stratify the Population: The first smart move is to recognize these are two distinct populations. You should not treat them as one. This is called stratification.
  3. Develop a Strategy for Population A (Large, Homogenous, Low-Risk):
  • Method Choice: Statistical Sampling, specifically Monetary Unit Sampling (MUS).
  • Justification: This population is large (3,950 items) and homogenous (small, routine balances). MUS is extremely efficient here because it automatically stratifies by dollar amount, giving larger items within this group a higher chance of selection. It allows you to draw an objective, statistically valid conclusion about the entire $4 million balance without testing an excessive number of items. You can state with, for example, 95% confidence that the misstatement in this population does not exceed a certain amount.
  1. Develop a Strategy for Population B (Small, Heterogeneous, High-Risk):
  • Method Choice: Non-Statistical Sampling (specifically, 100% examination or targeted selection of all high-risk items).
  • Justification: These 50 accounts make up 60% of the total AR balance. The risk of material misstatement is concentrated here. Using a statistical sample would be inefficient and might even miss key items. The most effective and efficient audit procedure is to use judgment to test all, or nearly all, of these individually significant balances. The audit value comes from deep, targeted testing, not from projecting a sample result.
The Tempting Wrong Answer: "Use statistical sampling for both populations to be objective." Why It's Wrong: This answer ignores audit efficiency. Setting up a statistical plan for the 50 large accounts is overkill. The time spent calculating parameters would be better spent simply examining the high-dollar items directly. The CPA exam rewards practical, risk-based thinking, not a dogmatic adherence to one method. An auditor's job is to gather sufficient, appropriate evidence efficiently.

How Do You Evaluate Sample Results in Substantive Testing?

Finding a misstatement in a sample is just the first step. The critical next step, heavily tested on the exam, is to project the misstatement to the entire population and compare it to your tolerable misstatement.

Here’s the process:

  1. Calculate the Projected Misstatement: If you find a $500 misstatement in a sample that represents 10% of the population's dollar value, your initial projected misstatement is $5,000 ($500 / 0.10). The specific calculation method varies (e.g., ratio or difference estimation in classical variables sampling, or the tainting percentage in MUS), but the principle is the same.
  2. Consider Sampling Risk: The projected misstatement is just your best estimate. You must also calculate an "allowance for sampling risk," which creates a range (an upper misstatement limit). This acknowledges that your sample might not have perfectly represented the population.
  3. Compare to Tolerable Misstatement: You then compare this upper misstatement limit to the tolerable misstatement you established during planning.
  • If the upper limit is less than tolerable misstatement, you can conclude the account balance is fairly stated.
  • If the upper limit exceeds tolerable misstatement, you cannot conclude the balance is fairly stated. You must either perform additional audit procedures, ask the client to adjust the balance, or consider modifying your audit opinion.

Understanding this evaluation process is crucial for TBSs, where you might be given sample results and asked to draw a conclusion. Mastering this requires practice, and VoraPrep’s adaptive learning engine can help by drilling you on your weak areas until you’re confident. Explore our course pricing and plans.

Frequently asked questions

How many questions on sampling appear on the AUD exam? You can expect 3-6 multiple-choice questions directly on sampling and potentially a task-based simulation that requires you to apply sampling concepts to a realistic audit scenario, like evaluating control deficiencies or projecting misstatements. What's the best way to study for sampling questions? Focus on the why. Create a decision tree for when to use statistical vs. non-statistical methods. Use flashcards for the direct and inverse relationships affecting sample size (e.g., "Higher Tolerable Rate -> Smaller Sample"). Most importantly, work through scenario-based practice questions. Is sampling tested in simulations (TBS) or only MCQs? It is frequently tested in TBS. A simulation might require you to select sampling parameters from a drop-down menu, calculate a projected misstatement from a set of sample data, or write a memo explaining why an account balance is or is not materially misstated based on sample results. Should I memorize the formulas for sample size? No. The AUD exam focuses on your understanding of the concepts and relationships that drive sample size, not your ability to plug numbers into a complex formula. Know that a lower risk tolerance or higher expected error rate leads to a larger sample, and you'll be well-prepared.

--- Ready to Pass Your CPA Exam? Don't let complex topics like audit sampling hold you back. VoraPrep's comprehensive study materials, with 9,500+ practice questions, an adaptive learning engine, and 24/7 Vory tutor support, are designed to help you master every concept. Visit voraprep.com to get started Start Your Free 14-Day Trial at voraprep.com →

⚡ Instant Knowledge Check · 1-Click Test Drive
AUD-II: Assessing Risk & Developing a Planned Response

Under AICPA AU-C 500 (Audit Evidence) and AU-C 505 (External Confirmations), which of the following forms of audit evidence provides the HIGHEST degree of reliability regarding the existence of accounts receivable?

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CPA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CPA diagnostic + 12-week plan PDF

Start →
CPA 1:1 Prometric Simulator

9,500+ practice questions with instant Socratic feedback