Sampling
Sampling is the practice of selecting a subset of items from a larger group so that conclusions can be drawn about the whole without examining every single item. In a compliance audit, an assessor typically reviews a representative selection of records or events, rather than the entire population, to evaluate whether controls are working as intended.
Sampling is the process of selecting a subset of individuals or items from a defined population in order to estimate characteristics of, or draw conclusions about, that whole population. In the context of SOC 2 Type II examinations and ISO/IEC 27001 audits, sampling is applied to test the operating effectiveness of controls over a review period: an auditor selects items from a control's population of occurrences (for example, access reviews, change tickets, or onboarding events) and inspects them for evidence of consistent control execution. The specific sample size, selection method, and acceptance thresholds vary by engagement and are determined by the auditor's or certification body's professional judgment, the frequency and nature of the control, the assessed level of risk, and the scope of the review. Sampling supports an inference about the population but does not constitute examination of every item; conclusions are therefore subject to sampling risk and cover only the population and period addressed.
Why it matters
Sampling is what makes control testing practical at scale. Over a SOC 2 Type II review period or an ISO/IEC 27001 audit, many controls generate large populations of occurrences, access reviews, change tickets, onboarding and offboarding events, and examining every single item would rarely be feasible within the time and resources of an engagement. By selecting a representative subset, an assessor can form a reasoned conclusion about whether a control operated consistently across the population without inspecting each event individually.
Because conclusions rest on a subset rather than the whole, sampling carries inherent limitations that compliance professionals need to understand. The results support an inference about the population but do not guarantee that every item was executed correctly, and they are subject to sampling risk, the possibility that the sample does not fully reflect the population. Any conclusion drawn covers only the population and the period addressed, which reinforces a broader point about compliance outcomes: a SOC 2 report attests only to the controls and period examined, and it does not certify that no exceptions or breaches occurred outside what the sampling reached.
Understanding sampling also helps organizations prepare. Knowing that an auditor will typically request a selection of records rather than an exhaustive review shapes how teams maintain evidence, since gaps or inconsistencies surfaced in even a small sample can lead to findings that reflect on the wider population.
Who it's relevant to
Inside Sampling
Common questions
Answers to the questions practitioners most commonly ask about Sampling.