A partner asks why the sample size audit teams landed on came back at 40 items instead of 25. The honest answer traces back through a chain of numbers: materiality, then a threshold derived from it, then a tolerable amount at the account level, then the sample size itself. Miss a link in that chain and the sample size looks arbitrary, even when the math behind it was sound.
PCAOB and AICPA standards describe that chain differently, and the gap between them is exactly where sample sizes get second-guessed. One framework uses a term the other doesn't use at all.
Materiality in auditing starts with one number: a materiality level for the financial statements as a whole. What happens after that number depends entirely on which standard applies.
Under PCAOB's AS 2105, the auditor sets that overall materiality level, considers whether specific accounts need a lower materiality level of their own, and then determines tolerable misstatement directly at the account or disclosure level. Tolerable misstatement has to be less than the materiality level for the financial statements as a whole, and the standard sets no required percentage for how much less. There's no separate defined term sitting between those two numbers.
Under AICPA's AU-C 320 and AU-C 530, there's an extra step. The auditor first determines performance materiality: an amount set below overall materiality specifically to reduce the probability that the combination of uncorrected and undetected misstatements exceeds materiality for the financial statements as a whole. Tolerable misstatement is then defined as the application of that performance materiality to a particular sampling procedure, and it can be the same amount as performance materiality or smaller, depending on how the sampled population relates to the full account balance.
| Step | PCAOB (AS 2105) | AICPA (AU-C 320 and 530) |
|---|---|---|
| Overall materiality | Materiality level for the financial statements as a whole | Materiality for the financial statements as a whole |
| Intermediate step | None | Performance materiality |
| Account-level threshold | Tolerable misstatement | Tolerable misstatement, derived from performance materiality |
| Controls threshold | Tolerable rate of deviation (see sampling, below) | Tolerable rate of deviation |
That missing row matters more than it looks. A reviewer trained on AICPA engagements who asks "what's your performance materiality" on a PCAOB engagement is asking a question the standard itself doesn't answer, because the term plays no role there. The right response on an issuer engagement is to walk straight from overall materiality to tolerable misstatement, citing AS 2105, not to manufacture an intermediate figure that has no PCAOB basis.
One piece of vocabulary does carry over cleanly. Both AS 2810 and AU-C 450 use the identical phrase "clearly trivial," and both make the same point about it: clearly trivial is not another expression for not material.
A clearly trivial misstatement is smaller in order of magnitude than materiality itself, inconsequential whether taken alone or combined with others. If there's genuine uncertainty about whether something clears that bar, both frameworks land on the same answer: treat it as not clearly trivial, and accumulate it anyway.
Setting that threshold too high defeats its purpose: a pile of individually trivial misstatements that never gets tracked can quietly approach materiality in aggregate, which is exactly the outcome the clearly trivial threshold exists to prevent.
Audit sampling applies the materiality chain above to a specific test, and the unit of measurement depends entirely on what's being tested.
For a substantive test of details, the relevant figure is tolerable misstatement: the maximum dollar misstatement the auditor can accept in an account balance or class of transactions, combined with other misstatements, without the financial statements becoming materially misstated. When the population being sampled is only part of a larger account or transaction class, tolerable misstatement for that sampled population should generally be set lower than tolerable misstatement for the account as a whole, to leave room for misstatement in the part that wasn't sampled.
For a test of controls, the relevant figure is different in kind, not just in size: it's the tolerable rate of deviation, the maximum rate of deviation from a prescribed control the auditor can accept without changing the planned assessment of control risk. This is a percentage, not a dollar amount, because the thing being measured is how often a control failed to operate as designed, not how much money moved as a result.
| Test type | Statistical technique commonly used | What's estimated | Threshold term |
|---|---|---|---|
| Test of controls | Attribute sampling | A deviation rate | Tolerable rate of deviation |
| Substantive test of details | Variables sampling, often monetary unit sampling | A dollar misstatement | Tolerable misstatement |
Neither "attribute sampling" nor "monetary unit sampling" is a term either standard mandates by name. PCAOB's AS 2315 and AICPA's AU-C 530 both describe the audit objective, estimating a deviation rate for controls, estimating a dollar misstatement for substantive tests, without prescribing a specific statistical technique to get there. Attribute sampling and monetary unit sampling are simply the methods the profession settled on for each objective, not requirements written into either standard.
"Sampling risk" gets used as if it's a single concept: AS 2315 breaks it into four, and only half of them matter for audit effectiveness.
For a substantive test of details:
For a test of controls:
The risk of incorrect rejection and the risk of assessing control risk too high are efficiency problems, not effectiveness problems. If a sample wrongly suggests a balance is misstated or a control is weaker than it really is, additional procedures ordinarily catch the error, at the cost of extra work. The risk of incorrect acceptance and the risk of assessing control risk too low are the ones that actually threaten the audit, because a sample that wrongly signals everything is fine gives the auditor no reason to dig further.
That asymmetry is why the two dangerous risks get explicit attention in the planning stage, and why they're the risks auditors should be prepared to explain if a reviewer or regulator asks how a sample size was chosen.
AS 2315's appendix includes a model many practitioners recognize without knowing where it came from:
AR = IR × CR × AP × TD
Audit risk as a function of inherent risk, control risk, the risk that analytical procedures and other relevant substantive tests fail to catch a misstatement, and the allowable risk of incorrect acceptance for the remaining test of details. Rearranged, it solves for TD, the risk of incorrect acceptance the auditor can accept for a specific substantive test, which in turn drives the sample size.
The standard itself is explicit about what this model is and isn't: it states plainly that the model is not intended to be a mathematical formula capturing every factor that influences risk, and that some auditors simply find it a useful way to think through appropriate risk levels during planning.
That's a more candid disclaimer than most secondary material repeats, and it lines up with how PCAOB's own AS 1101 frames audit risk generally: a function of the risk of material misstatement and detection risk, not a literal equation the standard requires anyone to compute. The four-factor version in AS 2315's appendix is the same idea with one more variable made explicit, offered as a planning aid, not a mandate.
Every factor that changes a substantive sample size points in a predictable direction, and being able to state that direction, out loud, in front of a reviewer, is most of what it means to defend a sample size.
| Factor | Smaller sample | Larger sample |
|---|---|---|
| Assessed inherent risk | Low | High |
| Assessed control risk | Low | High |
| Risk from other relevant substantive tests | Low | High |
| Tolerable misstatement | Larger | Smaller |
| Expected size or frequency of misstatements | Smaller, less frequent | Larger, more frequent |
| Population size | Minimal effect unless the population is very small | Minimal effect unless the population is very small |
That last row surprises people who assume a bigger population automatically needs a bigger sample. Beyond a certain point, it mostly doesn't: what drives sample size is risk and tolerable misstatement, not how many items happen to sit in the population.
For tests of controls, the same logic runs in reverse through a different lens: the tolerable rate of deviation, the expected rate of deviation, and the desired assurance against assessing control risk too low. A lower tolerable rate, a higher expected rate, or a higher desired assurance level all push the required sample size up.
Planning a sample well doesn't finish the job: the result still has to be projected to the full population it was drawn from, and that projected misstatement gets compared against tolerable misstatement, with explicit consideration of the sampling risk involved.
A projection that lands comfortably below tolerable misstatement supports a reasonable conclusion. A projection that sits close to tolerable misstatement is a signal to think harder about the chance the true population misstatement actually exceeds it, not a result to wave through because the arithmetic cleared the bar.
The same discipline applies to deviation rates in a controls test. A sample with a low estimated deviation rate doesn't automatically clear the tolerable rate; the auditor still has to weigh the risk that the true population rate is higher than what the sample happened to show, particularly with small samples where one additional deviation can swing the estimate meaningfully.
Materiality, tolerable misstatement, and sampling risk all feed the same place: the risk of material misstatement assessment that SAS 145 reshaped, and the evidence gathered in response to it eventually supports, or fails to support, the opinion itself. Bizora's guide to the types of audit opinions covers what happens when that evidence points toward a modified opinion instead of a clean one.
Bizora's Audit Research traces each answer back to the exact standard and paragraph, whether the question is which materiality term applies on an issuer engagement, or how to defend a sample size that came out smaller than a reviewer expected.
Materiality is the overall threshold for the financial statements as a whole. Performance materiality, a term used only under AICPA standards, is a lower amount set to reduce the probability that uncorrected and undetected misstatements, combined, exceed overall materiality. PCAOB standards don't use performance materiality at all, moving directly from overall materiality to tolerable misstatement at the account level.
It's the maximum dollar misstatement the auditor can accept in an account balance or class of transactions, in combination with other misstatements, without the financial statements becoming materially misstated. It applies to substantive tests of details and is always set lower than the overall materiality level.
Tolerable misstatement is a dollar amount used for substantive tests of details. Tolerable rate of deviation is a percentage used for tests of controls, representing the maximum deviation rate from a prescribed control the auditor can accept without changing the planned control risk assessment.
Attribute sampling is a statistical technique commonly used for tests of controls, to estimate how often a control deviated from how it was supposed to operate. Neither PCAOB nor AICPA standards require this specific technique by name; they describe the objective, estimating a deviation rate, and leave the statistical method to the auditor.
For substantive tests of details: the risk of incorrect acceptance and the risk of incorrect rejection. For tests of controls: the risk of assessing control risk too low and the risk of assessing control risk too high. Only the risk of incorrect acceptance and the risk of assessing control risk too low threaten audit effectiveness; the other two affect efficiency.
It's a monetary threshold below which an identified misstatement doesn't need to be accumulated, because the auditor doesn't expect such amounts to have a material effect even in combination. Both PCAOB's AS 2810 and AICPA's AU-C 450 use the identical phrase and both specify that clearly trivial is not simply another way of saying "not material": it's a smaller order of magnitude, and any uncertainty about whether an item qualifies means it doesn't.
Not according to the standards themselves. PCAOB's AS 1101 describes audit risk as a function of the risk of material misstatement and detection risk, without prescribing multiplication. AS 2315's appendix offers a four-factor planning model and explicitly states it isn't intended as a mathematical formula covering every factor. The multiplication version is a teaching tool, not a standard's requirement.
Bizora AI turns hours of manual research into seconds, with every answer backed by primary source citations. Start your 7-day free trial. No credit card required.
Start Free Trial