Exemplar Global Certified Courses from USD 99. Ending Soon!

Audit Sampling Strategies: Choosing What to Look At

AW

Team @ Audit Workshop

13 min read
Audit Sampling Strategies: Choosing What to Look At

Why Sampling Decisions Define the Quality of Your Audit

Every auditor faces the same fundamental constraint: you cannot look at everything. A manufacturing site might process thousands of work orders each month. A logistics company might have hundreds of supplier records. A hospital might generate thousands of documented procedures across dozens of departments. You have a fixed number of hours on site, and the decisions you make about what to examine will determine whether your audit conclusions are credible or hollow.

Audit sampling strategies are not just a technical topic buried in ISO 19011. They are one of the most important judgement skills an auditor develops over time. Choose poorly and you miss real problems. Choose well and you build a picture of the system that stands up to scrutiny.

This article covers how to think about sampling, the main approaches available to you, how to apply them in practice, and the common mistakes that undermine audit credibility.

What Audit Sampling Actually Means

Sampling in auditing means selecting a subset of available evidence to draw reasonable conclusions about the whole. You are not trying to prove that every single record is correct. You are trying to gather enough evidence, from a wide enough range of sources, to form a justified opinion about whether the system is operating as intended.

ISO 19011 describes audit evidence as records, statements of fact, and other information that is relevant to the audit criteria and verifiable. Sampling is the process of deciding which pieces of that evidence to examine. It applies to documents, records, interviews, observations, and physical outputs.

The key word in any sampling discussion is representative. Your sample needs to reflect the population it is drawn from. A sample of five purchase orders all from the same supplier, all from the same week, all approved by the same person, tells you very little about the broader purchasing process. A sample drawn from different suppliers, different time periods, different order types, and different approvers tells you much more.

The Two Broad Approaches: Statistical and Judgement Based Sampling

Statistical Sampling

Statistical sampling uses probability theory to select items from a population in a way that allows you to make mathematically defensible conclusions. Every item in the population has a known chance of being selected. The results can be expressed with a measurable level of confidence.

In practice, statistical sampling is rarely used in ISO management system audits. It requires large populations, a defined sampling frame, and time to calculate appropriate sample sizes. Certification audits and internal audits simply do not have the time or data infrastructure to support it in most cases. Where you will encounter it is in financial auditing, regulatory compliance auditing, and some specialised quality audits in pharmaceutical or aerospace environments where statistical acceptance sampling is built into the process itself.

Judgement Based Sampling

Judgement based sampling, sometimes called non-statistical or purposive sampling, is what most ISO auditors use. You draw on your knowledge of the organisation, the process under review, the audit objectives, and your professional experience to select items that are most likely to reveal meaningful information.

This is not guesswork. Judgement based sampling is disciplined and deliberate. It requires you to think carefully about where the risks are, where the system is most likely to break down, and where the evidence will be most informative. The skill lies in making those decisions systematically rather than randomly or conveniently.

For a deeper look at the mechanics of sample sizes in audit practice, the related article on audit sample sizes covers how many records are typically enough for different population sizes.

Sampling Strategies You Should Know

Random Sampling

Random sampling means selecting items without any particular pattern, giving all items an equal chance of being chosen. In an audit context, you might pick every fifth record from a register, or use a random number generator to select from a numbered list.

Random sampling works well when the population is homogeneous and you have no reason to suspect particular items are more likely to reveal problems than others. It is useful for checking whether a process is being applied consistently across the board.

The limitation is that randomness can miss concentrations of risk. If problems cluster in a particular time period, product type, or work area, a purely random sample might skip right over them.

Stratified Sampling

Stratified sampling divides the population into subgroups and samples from each. For example, if you are auditing calibration records across a manufacturing site, you might stratify by equipment type: measuring instruments, pressure gauges, temperature probes, and so on. You then draw a sample from each stratum.

This approach ensures coverage across different categories and prevents your sample from being dominated by the most common type. It is particularly useful when different subgroups carry different levels of risk or complexity.

Risk Based Sampling

Risk based sampling directs your attention toward areas where failures are most likely or most consequential. You are deliberately choosing to look harder at the high-risk parts of the system.

In practice, this means looking at processes with a history of nonconformities, areas that have undergone recent changes, activities performed by new or temporary staff, outsourced functions with limited oversight, and processes where the consequences of failure are significant.

Risk based sampling aligns directly with the risk based thinking that underpins modern ISO standards. It is the approach most consistent with how a professional auditor thinks. Rather than treating all processes as equally worthy of attention, you apply more scrutiny where the stakes are higher.

This connects naturally to the broader topic of risk based audit scheduling, which addresses how to prioritise what to audit across an entire programme, not just within a single audit.

Attribute Sampling

Attribute sampling looks for the presence or absence of a particular characteristic. Either the record has the required signature or it does not. Either the calibration label is within date or it is not. Either the training record exists or it does not.

This is the most common form of sampling in ISO audits because most audit criteria are binary in nature. The process either conforms or it does not. Attribute sampling is simple to apply and easy to document.

Block Sampling

Block sampling selects a contiguous group of items, such as all records from a particular month, all jobs completed by a particular team, or all products from a particular production run. It is useful when you want to examine a specific period or operational unit in depth.

The risk with block sampling is that it may not represent the full range of conditions the system operates under. A month with no significant changes or incidents may look very different from a period when staffing was disrupted or new procedures were introduced. Use block sampling deliberately, not as a default.

Judgement Sampling Based on Audit Trails

One of the most powerful sampling approaches for ISO auditors is to follow a process from end to end and sample at each stage. You start with a customer order and trace it through to delivery. You start with a hazard identification and follow it through to risk control and monitoring. You start with a nonconformity and follow it through to root cause analysis, corrective action, and verification of effectiveness.

This approach, sometimes called process tracing or vertical sampling, tests whether the system actually works as a connected whole rather than as a collection of independent procedures. It often reveals gaps that clause-by-clause sampling would miss entirely.

Applying Sampling in Practice: Three Scenarios

Scenario One: Internal Audit of a Purchasing Process

You are auditing the purchasing process under ISO 9001 Clause 8.4. The organisation has approximately 200 active suppliers and processes around 150 purchase orders per month. You have two hours allocated to this process area.

A purely random sample of purchase orders might give you 10 to 15 records. That is a reasonable starting point, but you should stratify by supplier criticality. Pull records for at least two or three critical suppliers, a couple of routine suppliers, and at least one new supplier added in the past six months. Check whether the supplier evaluation records align with the approved supplier list. Follow one or two orders through from requisition to receipt and inspection, checking that the process steps were actually completed.

If the organisation recently changed its procurement software or updated its supplier approval procedure, that is where you focus additional attention. Change is where systems are most vulnerable.

Scenario Two: Certification Audit of an OH&S Management System

You are conducting a Stage 2 certification audit under ISO 45001. The site employs 80 people across three work areas: manufacturing, warehouse, and administration. You have one full day on site.

Allocate your sampling time in proportion to risk. Manufacturing and warehouse carry significantly higher hazard profiles than administration. Within manufacturing, identify the highest-risk tasks from the hazard register and make sure your sample includes records related to those tasks. Look at recent incident reports and check whether the corrective actions were completed. Interview workers in the high-risk areas, not just supervisors. Observe actual work practices, not just documented procedures.

For documented information, sample across time periods. Pull a training record from six months ago and one from last month. Check whether the hazard identification process has been updated to reflect any changes in work methods or equipment.

Scenario Three: Supplier Audit Under a Second Party Programme

You are auditing a critical subcontractor who provides fabrication services. You have four hours on site. The supplier has 12 staff and processes around 30 jobs per month for your organisation.

Start by reviewing the quality records for jobs supplied to your organisation in the past three months. Do not just take the most recent ones. Ask to see records for any jobs that had issues, whether or not formal complaints were raised. Walk the production floor and observe the process in action. Check calibration records for the measuring equipment used on your jobs. Interview the person who signs off on inspection records and ask them to walk you through what they actually do, not what the procedure says they do.

This is where judgement sampling really earns its keep. You are not trying to audit the entire supplier system. You are trying to understand whether the specific work they do for you is under control.

How Many Items Should You Sample?

There is no universal rule, but there are useful conventions. Many auditors use a rough guide based on population size:

  • Population of 1 to 5 items: examine all of them
  • Population of 6 to 50 items: examine 5 to 10 items
  • Population of 51 to 200 items: examine 10 to 20 items
  • Population over 200 items: examine 20 to 30 items, with additional samples if initial findings suggest problems

These are starting points, not rules. The appropriate sample size depends on the risk level, the homogeneity of the population, the time available, and what you find as you go. If your first five records all show the same problem, you do not need to examine 20 more to confirm the finding. If your first ten records are all clean, you might stop there or shift your attention to a different area.

The principle is that your sample size should be large enough to give you reasonable confidence in your conclusion, but not so large that you are spending time on diminishing returns when you could be examining other parts of the system.

Documenting Your Sampling Decisions

A common weakness in audit working papers is that the auditor records what they examined but not why they chose those particular items. This matters because your sampling rationale is part of the evidence that supports your conclusions.

In your working papers, note the population size, the sampling approach you used, the basis for your selection, and the items actually examined. If you made a deliberate decision to focus on high-risk items or recent records, say so. If a finding prompted you to expand your sample, document that too.

This is especially important for lead auditors managing a team. If different team members are sampling different process areas, the team leader needs to be confident that the sampling across the whole audit is coherent and appropriately risk focused, not just whatever was convenient for each individual auditor.

Common Sampling Mistakes That Undermine Audit Credibility

The most common mistake is convenience sampling: examining whatever is easiest to access. This often means the most recent records, the ones already on the desk, or the ones the auditee volunteers. Convenient samples are rarely representative samples.

A second mistake is sampling only the good performers. Auditors who are not confident in their role sometimes unconsciously select records that are most likely to be in order. This produces clean audit findings that do not reflect the real state of the system.

A third mistake is failing to adjust the sample when initial findings are concerning. If the first three records you examine all show the same deficiency, that is a signal to expand your sample and investigate further, not to note the finding and move on.

A fourth mistake is ignoring outliers. If one record looks significantly different from the others, that is worth investigating. Outliers often point to process breakdowns, workarounds, or exceptions that the formal procedure does not account for.

Understanding how to gather evidence that stands up to scrutiny is closely connected to sampling discipline. The article on how to gather audit evidence that stands up to scrutiny covers the broader evidence gathering process in detail.

Sampling Across Different Audit Types

Your sampling strategy should adapt to the type of audit you are conducting. Internal audits, where you have ongoing access to the organisation and can follow up over time, allow for more targeted sampling. You might deliberately focus on areas that were problematic in the previous audit cycle.

Certification and surveillance audits by external auditors tend to use broader sampling to get a representative picture of the whole system. The auditor is meeting the organisation for the first time or returning after a year, so they need to sample widely enough to form a credible overall conclusion.

Supplier audits are typically narrower in scope and can afford to go deeper in specific areas. You are not trying to certify the supplier. You are trying to understand whether the work they do for you is reliable.

For auditors working toward lead auditor credentials, developing a deliberate and documented sampling methodology is one of the markers of professional maturity that assessors look for. If you are building your audit skills and considering formal training, the courses at Audit Workshop cover practical sampling techniques as part of the lead auditor and internal auditor programmes, with real-world exercises that develop the judgement skills you cannot get from theory alone.

Frequently Asked Questions

Statistical sampling uses probability theory to select items so that results can be expressed with a measurable level of confidence. Every item has a known chance of selection and the sample size is calculated mathematically. Judgement based sampling relies on the auditor's professional knowledge to select items that are most likely to reveal meaningful information about the system. Most ISO management system audits use judgement based sampling because the populations are too varied and audit time is too limited for statistical approaches to be practical.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.