"A sample of twenty items was reviewed" is a standard sentence in an audit report. That number does not come from a statistical calculation; it comes from the cost of gathering evidence. This article is about what really sets the sample size and how an audit changes once that constraint is removed.

Why It Is Always Twenty Items

Ask an auditor and the answer is honest: the sample is as large as can be reviewed in the time allotted. An audit plan allocates a fixed amount of time per item, and gathering the evidence eats most of it.

Where does the time go? Not into review but into collection. Evidence is requested from the relevant team; the team searches, finds, takes screenshots, prints emails, prepares a spreadsheet. The auditor reads what arrives, asks about gaps, waits for a second round. Three or four days can pass for one item, and perhaps half a day of that is actual review.

So sample size is really a budget decision. And it is a fact neither side likes: the auditor wants to look wider, and the audited team does not want to spend weeks assembling evidence.

The Evidence Cost per Item

This cost is easy to measure, and measuring it changes the tone of the discussion. In your last audit, how many items were reviewed and how many person days went into gathering evidence? The division gives you the cost per item.

In most organisations that number lands between half and one person day per item. A sample of twenty then means ten to twenty person days of evidence gathering, a cost budgeted nowhere. It does not appear as an audit cost because it is the team's time, not the auditor's.

That cost has a second consequence: the person gathering the evidence is also the person who works in the process under review. Because the audited party selects the evidence, independence is compromised. The auditor knows this and treats what arrives with caution, which again produces more questions.

Whoever selects the evidence

What is missing from an evidence pack matters as much as what is in it. Even acting in good faith, a team that has to make a selection tends to produce a pack that does not surface exceptions. Yet exceptions are exactly what the auditor is looking for: what shows a control operates is the refusals and blocks it produces.

A Small Sample Means Narrow Assurance

In an organisation making a thousand changes a year, twenty items is two percent. Finding nothing in that sample does not mean the other ninety eight percent is clean, and the auditor does not write that it does. What they write is that no finding was identified in the sample reviewed.

The assurance that sentence gives a board is limited, and most organisations do not notice. When the next incident happens the question is why last year's audit did not catch it. The answer is simple: that item was not in the sample.

Choosing the sample is itself a problem. Random selection looks fair but misses the risky items. Risk based selection is better, but it requires knowing where the risk is, which requires already knowing something about every item. That loop cannot be broken while evidence is expensive.

What Changes When the Cost Approaches Zero

When evidence is produced by the work itself, preparing it for one item takes seconds. That single change rewrites the economics of an audit.

  • The sample grows. Two hundred items can be reviewed instead of twenty, because the constraint has moved from collection to reading.
  • Selection moves to the auditor. Since the audited team no longer assembles the evidence, the independence problem disappears.
  • The team gets its weeks back. This is the most easily measured return on a governance investment and is often sufficient on its own.
  • The quality of the evidence rises. A sealed, verifiable file replaces a screenshot, and the auditor no longer asks for extra samples to compensate for weak evidence.

From Sampling to Exceptions

The real shift is not a larger sample. If evidence is ready for every item, the auditor may not need to sample at all: they can scan the whole population and look only at what deviates from normal.

This approach has been discussed in the audit profession for years, and the obstacle has always been the same: the data is either missing or unreliable. A governance record removes that obstacle because every item is recorded in the same shape with the same fields.

In practice the exception list an auditor works from is short and covers: requests opened as emergencies, requests matching no approval policy, skipped approval steps, people who approved or executed their own request, unmasked data requests and blocked segregation of duties attempts. Across a thousand item year that list usually runs to ten or thirty rows, and the audit starts there.

SQL Change Guard provides that list as a built in report, with the roles allowed to run it defined. It is usually the first place an auditor opens, because what shows a control operates is not the approvals but the visibility of the exceptions.

Frequently Asked Questions

Is scanning the whole population instead of sampling acceptable under audit standards?

Sampling is a method rather than a requirement; where the data supports it, full population testing is a stronger approach and has long been advocated in professional literature. In practice the two are combined: the whole population is scanned with exception rules, the exceptions are reviewed individually, and a small sample is still drawn from the items that look normal.

If evidence is produced automatically, why is an auditor still needed?

Because evidence is not judgement. The system says a request was approved in line with the policy; whether that policy is the right one, whether the stated reason is reasonable and whether the exceptions are legitimate are human decisions. What automation removes is not judgement but the collection effort spent before reaching it.

Can the same evidence be produced for past periods?

The file contains whatever the record contains. For the period before the model went live, if the rule set was never frozen that section stays empty, and if no text digest was computed at execution time the integrity status appears unverifiable. The file does not invent missing information, it states that it is missing. The adoption date is therefore also the boundary of your evidence quality.

Does a larger sample not make the audit longer?

It usually gets shorter, because the collection time disappears. And when work is driven by an exception list the number of items actually examined goes down rather than up: all thousand are scanned but only the ten to thirty deviating ones are read by a person. The auditor's time moves from searching for evidence to judging it.

Let us measure your cost per item

Let us work out together how many person days your last audit spent gathering evidence.

Book a Demo →