Tool

Size a sample, then evaluate the result

Zero-deviation size: n = ln(1 − confidence) / ln(1 − tolerable rate)

This is a statistical illustration of attribute sampling. Your audit or testing methodology, and applicable standards, define the sample sizes and evaluation rules you must use.

Sample sizes

Size by expected deviations

Expected deviationsSample size needed

Evaluation

Upper limit by deviations found

Instructions

How to use this app

  1. Set the confidence level and the tolerable deviation rate before you look at any results.
  2. Enter the number of deviations you expect (usually zero) to size the sample.
  3. Test the sample, then enter the sample size actually tested and the deviations found.
  4. Read the upper limit, not just the sample rate. If it is above the tolerable rate, the result does not support reliance as tested.
  5. Investigate every deviation for cause before deciding on next steps, and follow your testing methodology.

What This Control Test Sample Size Calculator Helps You Decide

This calculator sizes an attribute sample for testing an internal control and evaluates the result. Given a confidence level, a tolerable deviation rate, and the number of deviations you expect, it gives the sample size. After testing, you enter the deviations found and it gives the upper limit of the deviation rate at your confidence level, and whether it is within tolerance.

Use it to explain why a small sample with one deviation may not support reliance, and to see how much larger a sample would need to be.

How It Works

MeasureMethodMeaning
Sample sizeSmallest n where the chance of at most the expected deviations, if the true rate equals the tolerable rate, is at most 1 − confidenceFor zero expected deviations, n = ln(1 − conf) / ln(1 − tolerable rate).
Upper limitOne-sided binomial (Clopper-Pearson) upper confidence limit for the deviation rateThe highest true rate consistent with the sample at the chosen confidence.
ConclusionUpper limit compared with the tolerable rateWhether the evidence supports reliance as tested.
Population adjustmentn / (1 + (n − 1) / N)A reduction for small populations; not used by every methodology.

Worked Example: An Approval Control

The pre-loaded values are 95% confidence, a 5% tolerable rate, and no expected deviations, which gives a sample of 59. If 59 items are tested and one deviation is found, the sample rate is 1.69%, but the 95% upper limit is 7.79%, above 5%, so the result does not support reliance as tested. The tool also shows that about 93 items in total would be needed for one deviation to fit within tolerance, and that finding no deviations in 59 gives an upper limit of 4.95%.

Change the tolerable rate to 10% and the sample falls to 29, and change confidence to 90% and it falls further. The trade-off between confidence, tolerance, and sample size is the point of the exercise.

Limits and Good Practice

Control Test Sample Size Calculator Frequently Asked Questions

How is the sample size calculated?

For zero expected deviations it is the natural log of one minus the confidence level divided by the natural log of one minus the tolerable rate, rounded up, which gives 59 at 95% confidence and a 5% tolerable rate. With expected deviations the calculator finds the smallest sample in which that many or fewer deviations would be unlikely if the true rate equaled the tolerable rate.

Why does one deviation fail a sample of 59?

Because the evaluation uses an upper confidence limit, not the sample rate. One deviation in 59 is a 1.7% sample rate, but at 95% confidence the true rate could be as high as about 7.8%, which exceeds a 5% tolerable rate, so the evidence does not support reliance at that tolerance.

Can I use this instead of my audit methodology?

No. It illustrates the statistics behind attribute sampling. Your organization's methodology and the standards that apply to you define the sample sizes, selection methods, and evaluation rules you must follow, and your auditors may have their own requirements.

Is my data stored anywhere?

No. The calculator runs in your browser and nothing is sent to a server. It does not save your entries between visits.