The mechanics are stricter than teams expect. The auditor first requests the complete population for the observation period — every ticket, every deploy, every offboarded employee — usually as a system-generated export whose completeness they verify before anything else. Then they select items, without you choosing, at sizes scaled to frequency: a control that runs daily draws a larger sample than a quarterly one. Each selected item must produce its artifact — the approval, the review record, the revoked account. One item with nothing behind it becomes an audit exception, recorded in the testing section.
Teams sometimes bet that a skipped month will hide inside a big population. The math runs the other way: selections spread across the period, so a control that lapsed in June stands a strong chance of being drawn — and a population list that mysteriously omits June is itself a finding, because completeness gets tested before items do. Access reviews are the classic casualty: run them every quarter and sampling is a formality; skip one and the gap is permanent, because the evidence cannot be created after the fact.
The practical takeaway: every single occurrence of a control is potentially the one on the auditor’s list, so consistency beats intensity. Programs that automate evidence capture make sampling a non-event — the artifact exists the moment the control runs, and audit week becomes retrieval instead of archaeology.