METHODS / SOURCES / ASSUMPTIONS
Audit sampling methods you can review.
Reviewed 10 October 2026 · engine version 2026-10-10.2
The calculator offers statistical planning methods. Neither ISA 530 nor PCAOB AS 2315 mandates these particular formulas or a universal sample size of 25 or 60. Choosing a standard reference does not change the mathematics. Sample design, selection, performance and evaluation require separate consideration.
What the standards require
ISA 530 paragraphs 6–8 require consideration of the audit objective and population, a sample sufficient to reduce sampling risk, and a chance of selection for each sampling unit. A10–A11 explain the role of risk and statistically based formulas or judgement. Appendix 2 says that the number of units has little effect for large populations. Read the ISA text in XRB’s conforming adoption and FRC’s ISA (UK) 530.
PCAOB AS 2315 paragraph .38 identifies tolerable deviation, likely deviation and allowable risk of overreliance for control tests. Paragraph .23 addresses tolerable misstatement, incorrect acceptance risk and population characteristics for substantive tests. Its .41 example of 60 items with no deviations and 5% tolerance is conditional, not a universal minimum. See AS 2315. The linked page identifies an amendment effective 15 December 2026; apply the edition relevant to your engagement.
Attribute sampling: a fixed-size plan
We choose a sample size and a planned deviation count together. The count is the expected rate multiplied by the sample size, rounded up. The chosen sample must make the probability of observing that count or fewer, at the tolerable population rate, no greater than the allowable risk.
Choose n with P(X ≤ ceil[n × expected rate]) ≤ 1 − confidence, evaluated at the tolerable population rate.
For populations up to 100,000, X follows the hypergeometric distribution for random selection without replacement. The boundary population contains ceil[population × tolerable rate] deviations. This checks a conservative, achievable boundary at or above the tolerance. Larger populations use a binomial approximation. The exact count discretisation can produce steps in the result.
For zero expected deviations in a large population, n = ceil[log(risk) ÷ log(1 − tolerable rate)]. At 95% confidence and 5% tolerance this gives 59. A conservative Poisson approximation gives 60. The binomial approach and upward rounding of expected counts follow the basis described in AICPA Audit Sampling, Appendix A, A.11. The hypergeometric distribution models the finite population directly; a generic mean-variance correction is not applied.
Review the actual deviations and their causes, including qualitative implications. Do not treat the planned count as permission to ignore a serious finding or repeatedly extend a failed sample until it passes. The browser planner reports an error rather than truncating a calculation beyond its search or convergence limits (200,000 selections, 1,000 planning iterations, or 10,000 finite-distribution tail terms).
Variables: precision of a population mean
This is a two-sided, normal-based precision estimate for a mean, not a complete substantive acceptance test. Supply a population standard deviation or a justified prior/pilot estimate for the characteristic being tested. An attribute sample does not provide a numerical standard deviation.
n₀ = (Z × standard deviation ÷ absolute precision)²
n = ceil[N × n₀ ÷ (N − 1 + n₀)], bounded by N.
Standard deviation and precision use the same units. For a desired margin on a population total, divide that margin by N to obtain the margin per item. We use two-sided normal quantiles: 1.645 at 90%, 1.960 at 95%, and 2.576 at 99%. The finite correction assumes a simple random sample without replacement and a population variance defined with denominator N.
The normal precision formula and its assumptions are described by NIST’s sample-size guidance. Unknown variability, rare errors, skewed data or small samples may need a different model, a t-based treatment or stratification. This planner does not calculate separate risks of incorrect acceptance and rejection, anticipated total misstatement, or a substantive audit conclusion.
Monetary unit sampling: selections, not distinct records
The planner uses the Poisson confidence-factor approach in AICPA Audit Sampling, Appendix C. The factor incorporates the ratio of anticipated to tolerable misstatement. It is numerically evaluated and rounded upward to two decimals; the 90% and 95% factors are checked against table C-2. The 99% factors are calculated from the same model, rather than claimed to be published table cells.
e = anticipated misstatement ÷ tolerable misstatement
Solve Q(1 + eF, F) = risk for F, where Q is the upper regularised gamma function.
Selections = ceil[book value × rounded-up F ÷ tolerable misstatement].
Interval = book value ÷ selections.
At 95% confidence and e = 0.20, F rounds to 4.63. A book value of 2,000,000 and tolerance of 100,000 therefore give 93 monetary selections. This method supports anticipated misstatement up to 60% of tolerance, the documented C-2 range. Higher ratios receive an explicit error.
Use positive recorded balances for overstatement testing and value-weighted selection. Several monetary selections may fall within one record; the distinct record count cannot be inferred from the selection count. No correction based on the number of records is applied. If the monetary plan reaches that number, this tool recommends examining every record instead and preserves the original MUS plan in the export. Zero, negative and unrecorded balances need separate audit consideration, as do certainty items and the evaluation of actual taints.
Using your sample plan
- Choose the method that matches your audit objective and population.
- Document the confidence level, tolerable error and expected error or variability.
- Review the population-specific assumptions and the calculated size.
- Select the actual sampling units separately, giving each eligible unit a chance of selection.
- Retain the downloaded plan and evaluate your findings using your firm’s methodology and professional judgement.
The statistical models are checked against published examples and independent probability calculations. This does not validate your engagement inputs, certify standards compliance, select the records or evaluate the audit findings.
Review a calculation ↗