Skip to main content
Category: Audit Process

Sampling

Also known as: Audit Sampling, Sample Testing
Simply put

Sampling is the practice of selecting a subset of items from a larger group so that conclusions can be drawn about the whole without examining every single item. In a compliance audit, an assessor typically reviews a representative selection of records or events, rather than the entire population, to evaluate whether controls are working as intended.

Formal definition

Sampling is the process of selecting a subset of individuals or items from a defined population in order to estimate characteristics of, or draw conclusions about, that whole population. In the context of SOC 2 Type II examinations and ISO/IEC 27001 audits, sampling is applied to test the operating effectiveness of controls over a review period: an auditor selects items from a control's population of occurrences (for example, access reviews, change tickets, or onboarding events) and inspects them for evidence of consistent control execution. The specific sample size, selection method, and acceptance thresholds vary by engagement and are determined by the auditor's or certification body's professional judgment, the frequency and nature of the control, the assessed level of risk, and the scope of the review. Sampling supports an inference about the population but does not constitute examination of every item; conclusions are therefore subject to sampling risk and cover only the population and period addressed.

Why it matters

Sampling is what makes control testing practical at scale. Over a SOC 2 Type II review period or an ISO/IEC 27001 audit, many controls generate large populations of occurrences, access reviews, change tickets, onboarding and offboarding events, and examining every single item would rarely be feasible within the time and resources of an engagement. By selecting a representative subset, an assessor can form a reasoned conclusion about whether a control operated consistently across the population without inspecting each event individually.

Because conclusions rest on a subset rather than the whole, sampling carries inherent limitations that compliance professionals need to understand. The results support an inference about the population but do not guarantee that every item was executed correctly, and they are subject to sampling risk, the possibility that the sample does not fully reflect the population. Any conclusion drawn covers only the population and the period addressed, which reinforces a broader point about compliance outcomes: a SOC 2 report attests only to the controls and period examined, and it does not certify that no exceptions or breaches occurred outside what the sampling reached.

Understanding sampling also helps organizations prepare. Knowing that an auditor will typically request a selection of records rather than an exhaustive review shapes how teams maintain evidence, since gaps or inconsistencies surfaced in even a small sample can lead to findings that reflect on the wider population.

Who it's relevant to

Compliance and GRC Managers
These professionals coordinate evidence collection and need to understand that assessors typically review a representative selection of records rather than every item. Anticipating what may be sampled helps them ensure evidence is complete and consistent across the population, since inconsistencies exposed in a sample can produce findings that reflect on the whole.
Auditors and Assessors
Auditors performing SOC 2 Type II examinations or ISO/IEC 27001 audits apply professional judgment to determine sample size, selection method, and acceptance thresholds based on the control's frequency and nature, the assessed risk, and the review scope. They must also communicate the limitations of sampling, including sampling risk and the fact that conclusions cover only the population and period addressed.
Security Engineers and Control Owners
Those responsible for operating controls, such as access reviews, change management, and onboarding processes, benefit from knowing that any occurrence could be selected for testing. This encourages consistent, well-documented execution across every event rather than only for anticipated review items.
Report and Certificate Consumers
Customers and stakeholders relying on a SOC 2 report or an ISO 27001 certificate should understand that sampling underpins the conclusions. The results attest to controls based on a tested subset over a defined period and scope, and do not guarantee that every item in the population was executed without exception.

Inside Sampling

Sampling
A testing technique in which an auditor examines a subset of a population of transactions, events, or control instances to draw conclusions about the operating effectiveness of a control across the full population, rather than examining every occurrence.
Population
The complete set of items from which a sample is drawn (for example, all instances of a control's operation during the review period). Defining the population accurately is a prerequisite to selecting a representative sample.
Sample Size
The number of items selected for testing. Sizes typically vary with the frequency of the control's operation, the level of assurance sought, and the auditor's professional judgment rather than following a single fixed number.
Selection Method
The approach used to choose sample items, which may be statistical (random or systematic) or judgmental (targeted selection based on risk). The method chosen depends on the engagement, the auditor, and the nature of the control.
Relevance to SOC 2 Type II
Sampling is most associated with SOC 2 Type II examinations, where the CPA firm tests operating effectiveness of controls over a defined review period. It is generally less central to Type I engagements, which assess suitability of design at a point in time.
Relevance to ISO 27001 Auditing
Certification body auditors assessing an ISMS may also use sampling when evaluating evidence of control operation and conformance to the clause 4-10 requirements and applicable Annex A controls, depending on audit scope and methodology.
Deviations and Exceptions
Instances where a sampled item does not demonstrate the control operating as intended. How deviations are evaluated and whether they affect the overall conclusion depends on the auditor's judgment and the nature of the exception.

Common questions

Answers to the questions practitioners most commonly ask about Sampling.

Does sampling mean the auditor tests every instance of a control?
No. Sampling involves selecting a subset of items from a population rather than examining every instance. In a SOC 2 Type II examination, the auditor typically tests a sample of control occurrences over the review period to form a conclusion about operating effectiveness, rather than inspecting the entire population. The extent of testing depends on factors such as control frequency, the auditor's judgment, and scoping decisions.
If a sample passes without exceptions, does that guarantee the control operated effectively at all times?
No. A sample provides a basis for the auditor's conclusion but does not guarantee that a control functioned without exception across every instance in the population. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches or that no deviations occurred outside the tested items. Sampling inherently involves a degree of risk that is accepted as part of the examination approach.
How does sampling differ between a SOC 2 Type I and a Type II examination?
In a Type I engagement, the auditor assesses the suitability of the design of controls at a point in time, so testing typically focuses on whether controls are designed and in place rather than on sampling occurrences over time. In a Type II engagement, the auditor assesses both design and operating effectiveness over a defined review period, which generally involves sampling instances of control operation across that period. The period length varies and is set by scoping decisions.
How is sample size typically determined for control testing?
Sample size is generally influenced by the frequency with which a control operates, the population size, and the auditor's professional judgment about risk. Controls that operate more frequently may involve larger samples, while controls that occur only a few times in a period may be examined in full. There is no single fixed number that applies universally; the approach depends on the auditor and the specifics of the engagement.
What should an organization prepare to support the auditor's sampling process?
Organizations should typically maintain complete and reliable populations of control-related evidence, such as records showing each occurrence of a control activity over the review period. Clear, well-organized documentation helps the auditor select samples and verify that the population is complete. In most engagements, gaps or incomplete populations can complicate testing, so retaining consistent evidence throughout the period is advisable.
What happens if an exception is found within a sample?
When an auditor identifies an exception in a sampled item, the treatment depends on the auditor's evaluation of the deviation's nature and cause. Depending on the circumstances, the auditor may expand testing, investigate further, or reflect the deviation in the report. Whether an exception affects the overall conclusion is a matter of auditor judgment and the significance of the finding relative to the control objective.

Common misconceptions

A sample tested without exceptions proves the control worked for every instance in the population.
Sampling supports a conclusion about the population based on a subset; it does not examine every occurrence. A clean sample provides reasonable assurance over the tested controls and period but does not guarantee that no deviation occurred outside the sample, nor does it guarantee freedom from breaches.
There is a fixed, mandatory sample size that applies to all controls in a SOC 2 or ISO 27001 engagement.
Sample sizes typically vary based on control frequency, desired assurance, and the auditor's professional judgment. There is no single universal number that applies across all controls, auditors, or engagements.
Sampling is used the same way in a SOC 2 Type I and a Type II examination.
Sampling of operating effectiveness over a period is characteristic of SOC 2 Type II, which assesses both design and operating effectiveness across a defined review period. A Type I assesses suitability of design at a point in time and does not test operating effectiveness over a period in the same manner.

Best practices

Define the population precisely before sampling, ensuring it captures the full set of relevant control instances for the defined review period or point in time.
Align the selection method (statistical or judgmental) and sample size with the control's frequency, the level of assurance sought, and documented professional judgment rather than a fixed rule.
Retain clear documentation of how samples were selected, what was tested, and the basis for the sample size to support the auditor's conclusions and reproducibility.
Evaluate any deviations or exceptions carefully, considering their nature and cause before concluding on the control, rather than treating any single result as automatically pass or fail.
Coordinate with your CPA firm (for SOC 2) or certification body (for ISO 27001) early to understand their sampling expectations, since methodology varies by auditor and scope.
Communicate the limitations of sampling to stakeholders, clarifying that tested results attest only to the controls and period examined and do not guarantee that every uncovered instance operated as intended.