Internal controls are only useful if they work, and to know whether they work, teams test them, usually on a sample. The sample size and how deviations are evaluated determine how much confidence the result really gives.
This guide explains control types and attributes, how the zero-deviation sample size follows from confidence and a tolerable rate, and why a low sample deviation rate can still fail a test. A worked example tests a journal-entry approval control. Statistical illustrations here do not replace your organization's testing methodology or applicable standards.
Before You Start
Why Control Testing Needs Statistical Thinking
You Cannot Test Everything
A control that operates thousands of times a year is tested on a sample. The sample size decides how much confidence the result gives.
"We Tested 25 and Found Nothing" Is Weak
A small sample that finds no deviations can still hide a deviation rate that is too high to rely on.
Samples Should Be Sized on Purpose
Confidence, the tolerable deviation rate, and expected deviations all determine the sample size. Choosing a number by habit skips that reasoning.
Good Testing Frees Effort
Sound sampling lets teams test enough to be confident, and no more.
Controls and Attributes
An internal control is a process, policy, or activity designed to reduce a risk, such as an approval before a payment or a reconciliation before a close. The COSO Internal Control – Integrated Framework is a widely used reference. Controls are commonly grouped as:
| Type | What it does | Example |
|---|---|---|
| Preventive | Stops an error or misstatement before it happens | Segregation of duties, system-enforced approval limits |
| Detective | Finds an error after it happens so it can be corrected | Bank reconciliation, exception reports, variance review |
Testing a control usually means checking, for each item in a sample, an attribute: was the approval present, was it timely, was it by an authorized person? An item that fails the attribute is a deviation. The result is a deviation rate for the sample, which is used to judge whether the control operates effectively.
Sizing an Attribute Sample
For attribute testing where you expect zero deviations, the sample size n satisfies the binomial relationship n = ln(1 − confidence) / ln(1 − tolerable rate), rounded up. It is the smallest sample in which finding no deviations would allow you to conclude, at the chosen confidence, that the true deviation rate is no higher than the tolerable rate.
| Tolerable deviation rate | 90% confidence | 95% confidence | 99% confidence |
|---|---|---|---|
| 10% | 22 | 29 | 44 |
| 5% | 45 | 59 | 90 |
| 3% | 76 | 99 | 152 |
| 2% | 114 | 149 | 228 |
| 1% | 230 | 299 | 459 |
These are statistical illustrations for zero expected deviations. Your audit or testing methodology, and applicable standards, define the sample sizes and evaluation rules you must use. Follow those.
Worked Example: Testing an Approval Control
A company tests a control that requires manager approval of manual journal entries. The population is 4,000 entries for the year. It sets a 95% confidence level and a 5% tolerable deviation rate, so the zero-deviation sample size is 59. The figures are illustrative.
- Result 1: no deviations in 59. The one-sided 95% upper limit is 4.95%, so the test supports reliance on the control at the stated tolerance.
- Result 2: one deviation in 59. The sample deviation rate is 1.7%, which looks small, but the 95% upper limit is 7.8%, above the 5% tolerable rate. The test does not support reliance as designed.
What the tester does next. One deviation is not a conclusion in itself. The tester investigates it first: was the approval missing, late, or by the wrong person, and why? If it is an isolated, explained event, the methodology may allow the sample to be extended; the upper limit for 1 deviation falls below 5% only at a much larger sample (about 93 items). If the deviation reveals a design problem, such as no system block on unapproved entries, then the right response is to fix the control and retest, not to keep sampling.
The lesson is that a small sample deviation rate can be misleading. A rate of 1.7% sounds fine, but with only 59 items the true rate could plausibly be well above 5%. Your organization's testing standards, and where relevant your auditors, determine how deviations are evaluated.
Size your own samples and evaluate results with the Control Test Sample Size Calculator, and log results in the Control Test Sampling Log.
Self-Assessment Questions
- Do we choose sample sizes from confidence, tolerable rate, and expected deviations, not by habit?
- Do we evaluate results using an upper limit, not just the sample rate?
- Do we investigate every deviation for cause before concluding?
- Do we test the design of a control, not only its operation?
- Do we follow the testing methodology and standards that apply to us?
Common Mistakes
Reading the Sample Rate as the Population Rate
A low sample deviation rate can hide a high true rate. Use a confidence limit.
Keeping Sampling Until It Passes
Extending the sample without a documented basis, only because the first result failed, defeats the test.
Ignoring Non-Random Samples
A sample chosen for convenience may not represent the population. Select items randomly or systematically.
Testing Operation But Not Design
A control that operates perfectly but does not address the risk is not effective.
Internal Controls Testing and Sampling: Frequently Asked Questions
How do you calculate a sample size for control testing?
For attribute testing with zero expected deviations, the sample size is the natural logarithm of one minus the confidence level, divided by the natural logarithm of one minus the tolerable deviation rate, rounded up. At 95% confidence and a 5% tolerable rate this gives 59 items. If deviations are expected, larger samples are needed.
What is a tolerable deviation rate?
It is the highest rate of control deviations the tester is willing to accept and still conclude the control is operating effectively. It is set from the risk the control addresses and the reliance placed on it, and it should be defined before testing, not after seeing the results.
Why isn't the sample deviation rate enough?
Because a sample only estimates the population rate. One deviation in 59 items is a 1.7% sample rate, but at 95% confidence the true rate could be as high as about 7.8%, above a 5% tolerance. Evaluating the upper limit tells you whether the evidence supports reliance.
Sources and Further Reading
- Committee of Sponsoring Organizations of the Treadway Commission (COSO), Internal Control – Integrated Framework, 2013.
- AICPA, Audit Guide: Audit Sampling, and the auditing and internal-control testing standards that apply to you.
- Institute of Internal Auditors, International Standards for the Professional Practice of Internal Auditing.
- Douglas C. Montgomery and George C. Runger, Applied Statistics and Probability for Engineers, on binomial confidence limits.