Materiality and Audit Sampling: Setting Thresholds and Defending Sample Sizes

A partner asks why the sample size audit teams landed on came back at 40 items instead of 25. The honest answer traces back through a chain of numbers: materiality, then a threshold derived from it, then a tolerable amount at the account level, then the sample size itself. Miss a link in that chain and the sample size looks arbitrary, even when the math behind it was sound.

PCAOB and AICPA standards describe that chain differently, and the gap between them is exactly where sample sizes get second-guessed. One framework uses a term the other doesn't use at all.

Key takeaways

  • PCAOB standards never use the term performance materiality. AS 2105 goes directly from the materiality level for the financial statements as a whole to tolerable misstatement at the account level, with no intermediate step.
  • AICPA standards do use performance materiality, under AU-C 320, and define tolerable misstatement as the application of that performance materiality to a specific sampling procedure. The two terms aren't interchangeable.
  • Tolerable misstatement and tolerable rate of deviation measure different things: the first is a dollar amount for substantive tests of details. The second is a percentage for tests of controls.
  • Sampling risk isn't one risk. It splits into four, two for substantive tests and two for tests of controls, and only two of the four actually threaten audit effectiveness.
  • "Clearly trivial" is genuinely shared vocabulary: PCAOB's AS 2810 and AICPA's AU-C 450 both use the identical phrase, and both explicitly say it isn't another way of saying "not material."
  • PCAOB's own audit sampling standard includes a four-factor model, audit risk as a function of inherent risk, control risk, analytical procedures risk, and the risk of incorrect acceptance, and the standard itself says this model isn't meant to be a mathematical formula.
  • Sample size moves in predictable directions: it grows with higher risk and a lower tolerable amount, and shrinks with the reverse, regardless of whether the method is statistical or nonstatistical.

From materiality to tolerable misstatement: two different paths

Materiality in auditing starts with one number: a materiality level for the financial statements as a whole. What happens after that number depends entirely on which standard applies.

Under PCAOB's AS 2105, the auditor sets that overall materiality level, considers whether specific accounts need a lower materiality level of their own, and then determines tolerable misstatement directly at the account or disclosure level. Tolerable misstatement has to be less than the materiality level for the financial statements as a whole, and the standard sets no required percentage for how much less. There's no separate defined term sitting between those two numbers.

Under AICPA's AU-C 320 and AU-C 530, there's an extra step. The auditor first determines performance materiality: an amount set below overall materiality specifically to reduce the probability that the combination of uncorrected and undetected misstatements exceeds materiality for the financial statements as a whole. Tolerable misstatement is then defined as the application of that performance materiality to a particular sampling procedure, and it can be the same amount as performance materiality or smaller, depending on how the sampled population relates to the full account balance.

StepPCAOB (AS 2105)AICPA (AU-C 320 and 530)
Overall materialityMateriality level for the financial statements as a wholeMateriality for the financial statements as a whole
Intermediate stepNonePerformance materiality
Account-level thresholdTolerable misstatementTolerable misstatement, derived from performance materiality
Controls thresholdTolerable rate of deviation (see sampling, below)Tolerable rate of deviation

That missing row matters more than it looks. A reviewer trained on AICPA engagements who asks "what's your performance materiality" on a PCAOB engagement is asking a question the standard itself doesn't answer, because the term plays no role there. The right response on an issuer engagement is to walk straight from overall materiality to tolerable misstatement, citing AS 2105, not to manufacture an intermediate figure that has no PCAOB basis.

Clearly trivial: the one shared term

One piece of vocabulary does carry over cleanly. Both AS 2810 and AU-C 450 use the identical phrase "clearly trivial," and both make the same point about it: clearly trivial is not another expression for not material.

A clearly trivial misstatement is smaller in order of magnitude than materiality itself, inconsequential whether taken alone or combined with others. If there's genuine uncertainty about whether something clears that bar, both frameworks land on the same answer: treat it as not clearly trivial, and accumulate it anyway.

Setting that threshold too high defeats its purpose: a pile of individually trivial misstatements that never gets tracked can quietly approach materiality in aggregate, which is exactly the outcome the clearly trivial threshold exists to prevent.

Tolerable misstatement versus tolerable rate of deviation

Audit sampling applies the materiality chain above to a specific test, and the unit of measurement depends entirely on what's being tested.

For a substantive test of details, the relevant figure is tolerable misstatement: the maximum dollar misstatement the auditor can accept in an account balance or class of transactions, combined with other misstatements, without the financial statements becoming materially misstated. When the population being sampled is only part of a larger account or transaction class, tolerable misstatement for that sampled population should generally be set lower than tolerable misstatement for the account as a whole, to leave room for misstatement in the part that wasn't sampled.

For a test of controls, the relevant figure is different in kind, not just in size: it's the tolerable rate of deviation, the maximum rate of deviation from a prescribed control the auditor can accept without changing the planned assessment of control risk. This is a percentage, not a dollar amount, because the thing being measured is how often a control failed to operate as designed, not how much money moved as a result.

Test typeStatistical technique commonly usedWhat's estimatedThreshold term
Test of controlsAttribute samplingA deviation rateTolerable rate of deviation
Substantive test of detailsVariables sampling, often monetary unit samplingA dollar misstatementTolerable misstatement

Neither "attribute sampling" nor "monetary unit sampling" is a term either standard mandates by name. PCAOB's AS 2315 and AICPA's AU-C 530 both describe the audit objective, estimating a deviation rate for controls, estimating a dollar misstatement for substantive tests, without prescribing a specific statistical technique to get there. Attribute sampling and monetary unit sampling are simply the methods the profession settled on for each objective, not requirements written into either standard.

Sampling risk is four risks, not one

"Sampling risk" gets used as if it's a single concept: AS 2315 breaks it into four, and only half of them matter for audit effectiveness.

For a substantive test of details:

  • The risk of incorrect acceptance, which is the risk that the sample supports a conclusion the balance isn't materially misstated when it actually is
  • The risk of incorrect rejection, which is the risk that the sample supports a conclusion the balance is materially misstated when it actually isn't

For a test of controls:

  • The risk of assessing control risk too low, which is the risk that the sample leads to a control risk assessment below the control's true operating effectiveness
  • The risk of assessing control risk too high, which is the risk that the sample leads to a control risk assessment above the control's true operating effectiveness

The risk of incorrect rejection and the risk of assessing control risk too high are efficiency problems, not effectiveness problems. If a sample wrongly suggests a balance is misstated or a control is weaker than it really is, additional procedures ordinarily catch the error, at the cost of extra work. The risk of incorrect acceptance and the risk of assessing control risk too low are the ones that actually threaten the audit, because a sample that wrongly signals everything is fine gives the auditor no reason to dig further.

That asymmetry is why the two dangerous risks get explicit attention in the planning stage, and why they're the risks auditors should be prepared to explain if a reviewer or regulator asks how a sample size was chosen.

The formula that isn't a formula

AS 2315's appendix includes a model many practitioners recognize without knowing where it came from:

AR = IR × CR × AP × TD

Audit risk as a function of inherent risk, control risk, the risk that analytical procedures and other relevant substantive tests fail to catch a misstatement, and the allowable risk of incorrect acceptance for the remaining test of details. Rearranged, it solves for TD, the risk of incorrect acceptance the auditor can accept for a specific substantive test, which in turn drives the sample size.

The standard itself is explicit about what this model is and isn't: it states plainly that the model is not intended to be a mathematical formula capturing every factor that influences risk, and that some auditors simply find it a useful way to think through appropriate risk levels during planning.

That's a more candid disclaimer than most secondary material repeats, and it lines up with how PCAOB's own AS 1101 frames audit risk generally: a function of the risk of material misstatement and detection risk, not a literal equation the standard requires anyone to compute. The four-factor version in AS 2315's appendix is the same idea with one more variable made explicit, offered as a planning aid, not a mandate.

What actually moves a sample size

Every factor that changes a substantive sample size points in a predictable direction, and being able to state that direction, out loud, in front of a reviewer, is most of what it means to defend a sample size.

FactorSmaller sampleLarger sample
Assessed inherent riskLowHigh
Assessed control riskLowHigh
Risk from other relevant substantive testsLowHigh
Tolerable misstatementLargerSmaller
Expected size or frequency of misstatementsSmaller, less frequentLarger, more frequent
Population sizeMinimal effect unless the population is very smallMinimal effect unless the population is very small

That last row surprises people who assume a bigger population automatically needs a bigger sample. Beyond a certain point, it mostly doesn't: what drives sample size is risk and tolerable misstatement, not how many items happen to sit in the population.

For tests of controls, the same logic runs in reverse through a different lens: the tolerable rate of deviation, the expected rate of deviation, and the desired assurance against assessing control risk too low. A lower tolerable rate, a higher expected rate, or a higher desired assurance level all push the required sample size up.

Evaluating what the sample actually found

Planning a sample well doesn't finish the job: the result still has to be projected to the full population it was drawn from, and that projected misstatement gets compared against tolerable misstatement, with explicit consideration of the sampling risk involved.

A projection that lands comfortably below tolerable misstatement supports a reasonable conclusion. A projection that sits close to tolerable misstatement is a signal to think harder about the chance the true population misstatement actually exceeds it, not a result to wave through because the arithmetic cleared the bar.

The same discipline applies to deviation rates in a controls test. A sample with a low estimated deviation rate doesn't automatically clear the tolerable rate; the auditor still has to weigh the risk that the true population rate is higher than what the sample happened to show, particularly with small samples where one additional deviation can swing the estimate meaningfully.

Where this connects

Materiality, tolerable misstatement, and sampling risk all feed the same place: the risk of material misstatement assessment that SAS 145 reshaped, and the evidence gathered in response to it eventually supports, or fails to support, the opinion itself. Bizora's guide to the types of audit opinions covers what happens when that evidence points toward a modified opinion instead of a clean one.

Bizora's Audit Research traces each answer back to the exact standard and paragraph, whether the question is which materiality term applies on an issuer engagement, or how to defend a sample size that came out smaller than a reviewer expected.

Sources

Frequently Asked Questions

What is the difference between materiality and performance materiality?

Materiality is the overall threshold for the financial statements as a whole. Performance materiality, a term used only under AICPA standards, is a lower amount set to reduce the probability that uncorrected and undetected misstatements, combined, exceed overall materiality. PCAOB standards don't use performance materiality at all, moving directly from overall materiality to tolerable misstatement at the account level.

What is tolerable misstatement in auditing?

It's the maximum dollar misstatement the auditor can accept in an account balance or class of transactions, in combination with other misstatements, without the financial statements becoming materially misstated. It applies to substantive tests of details and is always set lower than the overall materiality level.

What's the difference between tolerable misstatement and tolerable rate of deviation?

Tolerable misstatement is a dollar amount used for substantive tests of details. Tolerable rate of deviation is a percentage used for tests of controls, representing the maximum deviation rate from a prescribed control the auditor can accept without changing the planned control risk assessment.

What is attribute sampling used for in an audit?

Attribute sampling is a statistical technique commonly used for tests of controls, to estimate how often a control deviated from how it was supposed to operate. Neither PCAOB nor AICPA standards require this specific technique by name; they describe the objective, estimating a deviation rate, and leave the statistical method to the auditor.

What are the four types of sampling risk?

For substantive tests of details: the risk of incorrect acceptance and the risk of incorrect rejection. For tests of controls: the risk of assessing control risk too low and the risk of assessing control risk too high. Only the risk of incorrect acceptance and the risk of assessing control risk too low threaten audit effectiveness; the other two affect efficiency.

What does "clearly trivial" mean in an audit?

It's a monetary threshold below which an identified misstatement doesn't need to be accumulated, because the auditor doesn't expect such amounts to have a material effect even in combination. Both PCAOB's AS 2810 and AICPA's AU-C 450 use the identical phrase and both specify that clearly trivial is not simply another way of saying "not material": it's a smaller order of magnitude, and any uncertainty about whether an item qualifies means it doesn't.

Is audit risk really calculated as inherent risk times control risk times detection risk?

Not according to the standards themselves. PCAOB's AS 1101 describes audit risk as a function of the risk of material misstatement and detection risk, without prescribing multiplication. AS 2315's appendix offers a four-factor planning model and explicitly states it isn't intended as a mathematical formula covering every factor. The multiplication version is a teaching tool, not a standard's requirement.

Your Next Answer Is One Search Away

Bizora AI turns hours of manual research into seconds, with every answer backed by primary source citations. Start your 7-day free trial. No credit card required.

Start Free Trial