Compliance

Audit Sample Size Calculator

Calculate the sample size needed to test a control at a chosen confidence level and tolerable deviation rate, using exact binomial bounds rather than a lookup table, with the achieved upper deviation limit shown.

Last reviewed by the Radiatus Cloud team

Results appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Sample size follows from the conclusion you need to reach

Attribute sampling in a controls audit is not about estimating a rate; it is about being able to say, at a stated confidence, that the true deviation rate is below a threshold you can live with. That threshold is the tolerable deviation rate. The sample size is whatever number makes the upper confidence bound fall below it, given the number of deviations you expect to find. Choosing a round number like 25 because it appears in a table is doing the arithmetic backwards.

Expected deviations drive the size more than confidence does

Moving from 90 to 95 percent confidence increases the sample modestly. Expecting even one deviation instead of zero increases it sharply, because a single failure has to be outweighed by many more successes before the upper bound comes back down. This is why a control believed to be clean can be tested with a small sample while one with a known occasional failure needs a much larger one, and why discovering an unexpected deviation mid-test usually invalidates the planned size.

The upper deviation limit is the actual output

The number that belongs in the working papers is not the sample size but the upper deviation limit achieved: given the sample tested and the deviations found, the highest true rate consistent with the evidence at your confidence level. This tool computes it from the exact binomial distribution rather than the Poisson approximation used by the printed AICPA tables, so it stays correct for small populations and high deviation rates where the approximation drifts.

Related tools

Frequently Asked Questions

What is a tolerable deviation rate?

The highest rate of control failure you could accept and still rely on the control. It is a judgement about the control, not a statistical parameter, and it drives the sample size more than anything else you choose.

Why does expecting one deviation increase the sample so much?

Because a single failure has to be outweighed by many more successes before the upper confidence bound falls back below your tolerable rate. Going from zero to one expected deviation often more than doubles the sample.

Does this use the AICPA tables?

No. It computes exact binomial confidence bounds, which is what those tables approximate. The results agree closely with the published tables and stay correct in the small-population and high-rate corners where the Poisson approximation drifts.

What is the finite population correction?

When the sample is a large fraction of the population, sampling without replacement makes each item more informative. The correction reduces the required sample accordingly, and it only matters when the population is small relative to the sample.

What happens if I find more deviations than expected?

The planned sample no longer supports the intended conclusion. Recompute the upper deviation limit from what you actually found, and if it exceeds your tolerable rate the control cannot be relied on at that confidence.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter your confidence level, tolerable deviation rate and population size.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.