Sampling exists because examining everything was, for most of the history of the profession, impossible. That constraint was practical rather than conceptual — and where the records are held digitally, it has substantially lifted.
What CAATs make possible
Computer Assisted Audit Techniques apply data mining and analysis tools directly to an organisation's own records. Applied to a full transaction population, they allow work that a sample cannot support: identifying every entry above a threshold, every transaction posted outside working hours, every duplicate payment reference, every gap in a sequence.
These are not more efficient versions of sample testing. They answer different questions — questions of the form are there any, which sampling can never fully close.
The prerequisite nobody mentions
The technique depends entirely on the quality and completeness of the data extract. An analysis run against a partial or poorly-understood dataset produces confident output and no assurance whatsoever. Establishing what the extract contains, how it was produced, and whether it reconciles to the ledger is the substantive part of the work.
This is also why risk assessment audits, security reviews and information systems work sit naturally in the same practice. Understanding the system that produced the data is not a separate discipline from analysing it.
A control question, not just an audit one
The same techniques are available to management. An organisation that can run these tests on its own records continuously does not have to wait for an annual audit to learn what they would have shown — which is, in the end, the more valuable position to be in.




