Periodic inspection

How is sampling done in an audit?

Examining every record is impossible in most organisations, so audits sample. How the sample is drawn decides the strength of the finding: random selection shows the general state, risk-based selection shows the weak points. The sampling method and size go into the report — without them nobody can tell whether a finding is a single exception or a pattern.

Why sample

Examining every one of the thousands of records produced in a year is impossible in most organisations. An audit examines enough records to reach a reasonable conclusion about the state of the system. The risk is plain: a badly chosen sample leads to a wrong conclusion.

Two ways to choose

  • Random: shows the general level of conformity; answers “does the system generally work?”
  • Risk-based: high-risk processes, new workers, new contractors, places with findings last year; answers “where does it break?”

A good audit uses both: part random, part targeted.

What has to be written down

The report states the size of the population (how many records exist), the size of the sample (how many were examined), the selection method and the period. Without those four, “three files were incomplete” is unmeasured — three out of three hundred, or three out of five?

From sample to pattern

A deviation in the sample indicates that it may exist in the population. The right response is not to confine the finding to those three files but to ask the process owner to screen the rest. The auditor does not do the screening; they require it and verify the result.

Zero findings and the sample

No finding in a small sample does not prove the system is sound. “No findings” is therefore read together with the sampling information.

Manage this in Optifora

Optifora is not a single program but a compliance platform assembled from modules. The catalogue states which module is ready today and which is on the roadmap.

See what Optifora is