How many samples will an auditor actually pull, and can we influence it?

The number of samples an auditor pulls is not fixed but is determined by the control's frequency, nature, and the auditor's risk assessment. While direct influence over sample size is not possible, organisations can indirectly affect it by demonstrating robust control design, consistent operation, and readily available, high-quality evidence. A well-prepared audit with strong internal controls can lead to more efficient sampling, but the auditor retains ultimate discretion based on professional judgment and applicable standards.

For SOC 2 and CMMC, auditors typically employ a risk-based sampling approach. Controls operating frequently, such as daily access reviews, generally necessitate a larger sample size than those performed less often, like quarterly vulnerability scans. The auditor evaluates the control's inherent risk, the effectiveness of the entity's general IT controls, and the quality and completeness of evidence provided. If evidence is incomplete, inconsistent, or challenging to obtain, auditors may expand their sample size to achieve sufficient assurance, potentially increasing audit effort and associated costs. Conversely, well-documented processes, clear evidence trails, and effective monitoring can significantly streamline the sampling process.

A common misconception is that a fixed percentage or number of samples applies universally across all audits or control types. This is incorrect; auditors exercise professional judgment guided by established auditing standards. Organisations frequently err by not maintaining comprehensive, readily accessible evidence for all control activities throughout the audit period. Attempting to influence sample size by withholding information or presenting curated data is counterproductive and can lead to adverse findings or an expanded audit scope. Instead, practitioners should focus on demonstrating a mature control environment, proactively providing complete and accurate evidence, and engaging transparently with the audit team to facilitate an efficient and effective assessment.

Sources

  • AICPA Professional Standards, AT-C Section 205, Assertion-Based Engagements
  • AICPA Professional Standards, AU-C Section 530, Audit Sampling
  • CMMC Assessment Process (CAP) Guide, Version 2.0

Related