What it means
Any time someone tests a selection of items rather than every item, two separate things can go wrong. The sample might simply be unrepresentative through bad luck, which is sampling risk, or the tester might handle the work badly, which is non-sampling risk.
The second category is the harder of the two to manage because it cannot be reduced by testing more items. Doubling the sample size does nothing if the test being applied does not address the question that actually matters.
Typical causes are familiar to anyone who has managed a team. They include misunderstanding what the control is meant to prevent, accepting a document at face value without checking it is genuine, applying the wrong materiality threshold, or missing an exception because the reviewer was working at speed near a deadline.
It matters commercially because it sits behind most audit failures that make the news. Investors, lenders and boards rely on assurance work as a safety net, and when that net has a hole in it the cost is usually measured in restatements, covenant breaches and lost confidence rather than in audit fees.
The defences are procedural rather than mathematical. Firms manage non-sampling risk through staff training, clear audit programmes, supervision and review by a second person, consultation on technical matters, and quality checks that revisit completed files.
The same idea applies well outside audit. Internal quality teams, compliance reviewers, clinical data checkers and even marketing analysts running experiments all face the risk that a well-drawn sample is undone by a badly designed or badly executed test.
In practice
Real-world examples.
Example
An auditor tests 60 purchase invoices for evidence of authorisation and finds every one signed. The sample was drawn correctly, but the auditor never checked whether the signatories were within their approval limits, so a pattern of over-limit approvals went undetected. That is non-sampling risk, not sampling risk.
Example
A compliance reviewer at an insurance broker examines new client files for identity documents. Under time pressure before a regulatory deadline, she accepts scanned passports without verifying them against the issuing checks, and two forged documents pass through undetected.
Example
A retail chain's internal audit team tests stock counts at eight stores and concludes controls are effective. The team had used last year's audit programme, which did not cover the new self-checkout shrinkage process introduced six months earlier, so the largest loss driver was never in scope at all.
Think of it
“Non-sampling risk is auditor error not from sampling-human mistakes, wrong procedures.
Case study
Seen in the real world.
Cedar Point Assurance is a fictional, illustrative mid-tier accounting firm used here to show how non-sampling risk builds up quietly. Its audit of a wholesale distributor had run smoothly for four years, and the same junior team returned each January with the prior year's file as a template.
In this illustrative scenario the distributor changed its revenue model, moving from outright sales to a consignment arrangement where goods sat in customer warehouses but were not yet sold. The audit programme still tested despatch notes as evidence of revenue, which had been the right test under the old model and was now the wrong one entirely. The sample sizes were correct, the selections were random and the documentation was complete, yet the conclusion was wrong.
A quality review two years later caught the issue and the distributor restated $4,100,000 of revenue across two periods. Cedar Point's response was not to test more invoices but to introduce a mandatory business-change discussion at planning, a rule that no programme could be rolled forward unchanged for more than two years, and a senior review of every revenue test. The illustrative lesson is that non-sampling risk is defeated by thinking and supervision, never by a larger sample.
Watch out
Common mistakes.
- Trying to fix non-sampling risk by increasing the sample size. A larger sample tested the wrong way simply produces more of the wrong evidence.
- Confusing it with sampling risk when writing up findings. Sampling risk is a statistical property of selection, while non-sampling risk is about judgement, design and execution.
- Assuming that experienced staff eliminate the risk. Experience helps, but familiarity with a client is itself a common cause of overlooked changes.
Questions
People also ask.
Can non-sampling risk ever be measured?
Not directly, because it has no statistical distribution; it is managed through training, supervision and quality review rather than quantified.
Does it apply if the whole population is tested?
Yes, testing every item removes sampling risk entirely but leaves the risk of a poorly designed or carelessly executed test untouched.
Who is responsible for controlling it in a business?
The engagement leader or review manager owns it in practice, supported by firm-wide quality systems, clear methodology and honest supervision.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%