Why sample
Examining every one of the thousands of records produced in a year is impossible in most organisations. An audit examines enough records to reach a reasonable conclusion about the state of the system. The risk is plain: a badly chosen sample leads to a wrong conclusion.
Two ways to choose
- Random: shows the general level of conformity; answers “does the system generally work?”
- Risk-based: high-risk processes, new workers, new contractors, places with findings last year; answers “where does it break?”
A good audit uses both: part random, part targeted.
What has to be written down
The report states the size of the population (how many records exist), the size of the sample (how many were examined), the selection method and the period. Without those four, “three files were incomplete” is unmeasured — three out of three hundred, or three out of five?
From sample to pattern
A deviation in the sample indicates that it may exist in the population. The right response is not to confine the finding to those three files but to ask the process owner to screen the rest. The auditor does not do the screening; they require it and verify the result.
Zero findings and the sample
No finding in a small sample does not prove the system is sound. “No findings” is therefore read together with the sampling information.