Exemplar Global Certified Courses from USD 99. Ending Soon!

Audit Sample Sizes: How Many Records Are Enough

AW

Team @ Audit Workshop

13 min read
Audit Sample Sizes: How Many Records Are Enough

Why Sample Size Is One of the Most Misunderstood Parts of Auditing

Ask ten auditors how many records they pull for a given process and you will get ten different answers. Some follow a formula. Some go with gut feel. Some pull whatever the auditee hands them and call it a day. The truth is that audit sampling is a judgement call, but it is not a random one. It should be grounded in risk, population size, process maturity, and what you already know about the organisation.

There is no ISO standard that tells you to pull exactly five purchase orders or ten training records. What ISO 19011:2018 does say is that sampling should be planned, that the sample should be representative of the population, and that the method should be appropriate to the audit objectives. That leaves a lot of room for auditor judgement, which is both the freedom and the challenge of the role.

This article breaks down how experienced auditors actually think about sample sizes, what factors drive the decision, and how to avoid the two most common errors: sampling too little and missing real problems, or sampling so much that you run out of time before you finish the audit.

The Purpose of Sampling in an Audit

You are rarely able to review every record a process generates. A manufacturing site might produce thousands of inspection records a year. A logistics company might have hundreds of supplier invoices every month. Reviewing all of them is not practical in a one day or two day audit. Sampling lets you draw reasonable conclusions about a population by examining a subset of it.

The key word is reasonable. Your sample needs to be large enough that if a systemic problem exists, there is a realistic chance you will find it. A sample of two records from a population of five hundred is almost certainly not going to surface a pattern of nonconformance unless you happen to pick the two worst examples.

Equally, pulling fifty records when the process only runs quarterly and the total population for the year is twenty records is not sampling. That is just reviewing everything, which is fine if time allows, but it is not a strategic use of your audit hours.

What ISO 19011 Actually Says About Sampling

ISO 19011:2018 addresses sampling in Annex B, which covers audit sampling. It describes two broad approaches: statistical sampling and non-statistical sampling.

Statistical Sampling

Statistical sampling uses probability theory to select and evaluate a sample. It allows you to make quantified statements about confidence levels and error rates. For example, you might be able to say with 95% confidence that no more than 5% of records in the population are nonconforming. This approach is rigorous but requires a defined population, random selection, and some mathematical groundwork. It is most commonly used in product audits or compliance audits where the population is large and well defined.

Non-Statistical Sampling

Non-statistical sampling is what most ISO management system auditors use in practice. It relies on auditor judgement to select records that are representative of the population. This includes approaches like:

  • Judgement sampling: You select records based on your knowledge of risk areas, process variations, or past findings.
  • Stratified sampling: You divide the population into subgroups (for example, by shift, by product type, or by supplier) and sample from each group.
  • Block sampling: You select a specific time period and review all records from that period.
  • Systematic sampling: You select every nth record from a list.

In practice, most auditors combine these approaches. You might use stratified sampling to ensure you cover different shifts, then use judgement within each stratum to focus on higher risk records.

For a deeper look at the different sampling techniques available to auditors, the article on audit sampling techniques explained covers each method in more detail.

Factors That Should Drive Your Sample Size Decision

Rather than picking a number out of habit, experienced auditors think through several factors before deciding how many records to pull.

Population Size

The larger the population, the larger the sample you generally need to draw meaningful conclusions. But the relationship is not linear. Moving from a population of 100 to 1000 does not mean you need ten times as many records. In statistical terms, the required sample size grows much more slowly than the population once you get past a certain point.

A rough rule of thumb that many experienced auditors use for non-statistical sampling:

  • Population under 50: review 5 to 10 records, or the entire population if small enough
  • Population 50 to 250: review 10 to 25 records
  • Population over 250: review 25 to 40 records, with more if risk warrants it

These are starting points, not fixed rules. Risk and context will push you above or below these numbers.

Risk Level

Higher risk processes warrant larger samples. If you are auditing a safety critical process, a process with a history of nonconformance, or a process that is new or recently changed, you should pull more records than you would for a stable, low risk process with a clean history.

For example, if you are auditing a chemical handling procedure under ISO 45001 and the organisation had an incident last year related to that process, pulling three records is not sufficient. You need enough records to understand whether the corrective action has actually been embedded in practice.

Process Maturity and History

A process that has been running for five years with no nonconformities and consistent management review data behind it can be sampled more lightly than a process that was only implemented six months ago or one that raised findings in the last audit cycle. Past audit history is a legitimate input to your sampling decision.

Confidence in the Auditee

This one is less discussed in training courses but is very real in practice. If you arrive at an organisation and the records are well organised, staff can explain the process clearly, and the documented information is current and controlled, you might be comfortable with a moderate sample. If records are hard to locate, staff seem uncertain about what they are supposed to do, or there are gaps in the documented information, you should pull more records. The early signals you pick up in an audit matter.

Audit Objectives and Scope

If your audit objective is specifically to verify the effectiveness of corrective actions from a previous audit, your sampling strategy will be targeted and focused. If you are conducting a full system audit across all clauses, your sampling will be spread more broadly and each individual area may get a smaller slice of your attention. Scope shapes sample size at the process level.

Practical Sample Sizes by Record Type

Here is how this plays out in real audit situations across ISO 9001, ISO 14001, and ISO 45001.

Training Records

For a site with 80 staff, you would not review all 80 training records. A reasonable approach is to select a cross section: pick a few roles that are safety or quality critical, a few that are general, and include at least one or two recent starters. Aim for 10 to 15 records, and verify that each one links back to a competency requirement. If you find gaps in three or four of those records, that is a strong signal of a systemic issue.

Calibration Records

If the organisation has 40 pieces of measuring equipment, reviewing 8 to 12 calibration records is reasonable. Focus on equipment that is used in critical measurements, equipment that is due for calibration soon, and any that have had issues noted in previous audits.

Nonconforming Product or Output Records

Pull a sample that spans the audit period, not just the most recent month. If you are auditing a full year, try to get records from at least three or four different time periods. This helps you spot trends rather than just snapshots. For an active manufacturing process, 15 to 20 nonconformance records across the year is a reasonable sample.

Supplier Evaluation Records

If the organisation has 30 active suppliers, reviewing 8 to 10 supplier evaluation records is workable. Prioritise critical suppliers, suppliers that have caused problems in the past, and any new suppliers added in the audit period. This is consistent with the risk based approach that ISO 9001 Clause 8.4 requires.

Incident and Hazard Records

For an ISO 45001 audit, incident records are high priority. If there were 25 incidents in the audit period, reviewing 8 to 12 of them is reasonable. Include any that resulted in corrective actions, any that were classified as near misses, and at least one or two that were closed out quickly to verify that closure was genuine rather than administrative.

Common Sampling Mistakes Auditors Make

Accepting the First Records the Auditee Hands Over

This is probably the most common sampling error in practice. An auditee who knows an audit is coming will often have their best records ready. If you only review what is placed in front of you, you are not sampling the population. You are reviewing a curated selection. Always ask to select your own records, or at minimum ask to see the full register and choose from it yourself.

Sampling Only Recent Records

Auditors often default to the most recent records because they are easiest to find. But recent records may not reflect the period under audit, and they may not reveal problems that occurred earlier in the year and were quietly corrected. Spread your sample across the full audit period.

Not Adjusting When Problems Appear

If your first five records reveal two nonconformities, that is a signal to expand your sample, not to stop. A finding in a sample is not just a finding about those specific records. It raises a question about the broader population. Pull more records to understand whether the problem is isolated or systemic. This is one of the most important judgement calls an auditor makes during fieldwork.

Sampling the Same Records Every Audit

If you are an internal auditor who runs the same audit year after year, resist the temptation to pull the same records each time. Rotate your sample. Look at different time periods, different staff members, different product lines or sites. A static sampling approach gives you a static picture.

Documenting Your Sampling Decisions

Whatever sample size you choose, document your rationale. Your working papers should record what population you were sampling from, how many records you selected, how you selected them, and why. This matters for two reasons.

First, it demonstrates that your audit was planned and systematic, not arbitrary. Second, if someone challenges your findings, you can show that your conclusions were based on a representative sample rather than a handful of convenient records.

A simple note in your working papers is sufficient. Something like:

Population of 45 calibration records for the period January to December. Selected 10 records using judgement sampling, prioritising critical measurement equipment and items due for recalibration. Selection included records from Q1, Q2, Q3 and Q4 to ensure coverage across the full audit period.
That level of documentation is professional and defensible.

For guidance on gathering and recording evidence more broadly, the article on how to gather audit evidence that stands up to scrutiny is worth reading alongside this one.

Sample Size in Internal vs External Audits

Internal auditors and external auditors face different constraints. An external auditor from a certification body is working to a fixed audit duration that has been calculated based on the organisation's size and complexity. Every hour counts. Their sampling decisions are constrained by time, which means they tend to be more targeted and risk focused.

An internal auditor, by contrast, often has more flexibility. You may be able to spend an entire day on a single process. That does not mean you should review every record, but it does mean you can afford to go deeper when something looks wrong. Internal auditors should use that flexibility to their advantage, particularly when following up on previous findings or investigating a process that management has flagged as a concern.

The article on internal audit vs certification audit: key differences explained covers how the two types of audit differ in scope, purpose, and approach.

When to Stop Sampling

There is no single answer to when you have sampled enough, but there are two useful signals.

The first is saturation. If you have pulled 15 records and the last five have all been consistent with the first ten, with no new patterns or problems emerging, you are probably at a reasonable stopping point for that area. You are not finding anything new.

The second is a clear finding. If your sample reveals a systemic nonconformity, you do not need to keep sampling to prove it further. Document what you have found, note the sample size, and move on. Expanding the sample at that point is often a poor use of audit time unless you are trying to understand the full extent of the problem.

What you should not do is stop sampling because you have not found anything yet and you are running short on time. If you are pressed for time and have only reviewed two records in a high risk area, that is a planning problem, not a sampling conclusion.

Building Sampling Judgement Over Time

Sampling is a skill that develops with experience. The more audits you conduct, the better your instincts become about when a small sample is sufficient and when something warrants a deeper look. You start to recognise the signals that indicate a process is genuinely under control versus one that looks compliant on paper but has cracks underneath.

New auditors often err on the side of pulling too few records because they are not sure what they are looking for. With experience, you learn to read the early evidence more quickly and adjust your sampling strategy in real time as the audit unfolds.

Formal training accelerates this development significantly. At Audit Workshop, our internal auditor and lead auditor courses cover audit sampling as a practical skill, not just a theoretical concept. Trainees work through real scenarios and learn how to make and document sampling decisions in the context of actual audit situations. If you are building your auditing skills and want to develop confident, defensible sampling judgement, our courses are designed for practitioners who want to do the job properly.

Frequently Asked Questions

No ISO management system standard prescribes a fixed formula for sample sizes. ISO 19011 provides guidance on sampling approaches in its annex but leaves the specific sample size to auditor judgement. The decision should be based on population size, risk level, process maturity, audit objectives, and available time. Experienced auditors develop their own calibrated approach over time, informed by these factors rather than a fixed rule.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.