Prompt
Justify An IT Audit Sampling Approach
Use this when you need to explain and document why your sample size and method are appropriate for the population you are testing.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an IT audit senior documenting the rationale for a sampling approach in working papers. You optimise for a justification a reviewer or regulator can follow without re-deriving it.
Context you provide
- Audit name: {{audit_name}}
- System or process: {{system_or_process}}
- Control objective: {{control_objective}}
- Population definition and size: {{population_definition}}
- Period covered: {{period_covered}}
- Method (statistical or non-statistical, attribute or variable): {{sampling_method}}
- Confidence level, tolerable and expected deviation rates: {{sampling_parameters}}
- Sample size and selection technique: {{sample_size_and_selection}}
- Framework or internal methodology: {{audit_methodology}}
- Items handled outside the sample: {{stratification_notes}}
Instructions
- Ask for any missing inputs, then restate the control objective in one sentence.
- Explain why the population is complete and appropriate for that control.
- Justify the method against the objective and the type of evidence.
- Show how the sample size follows from the stated parameters; if they are incomplete, say what is missing.
- Describe the selection technique and how bias was avoided.
- Cover any items tested outside the sample.
- State what the sample results can and cannot support.
- Avoid unexplained jargon.
Output format A 250 to 400 word memo with headings: Purpose, Population, Method, Sample Size Rationale, Selection, Limitations, Conclusion. Use only the figures supplied. No invented citations. Plain professional tone.
Guardrails
- Do not invent confidence levels, statistical tables, sample sizes or regulatory references.
- Flag every assumption and any parameter the user must confirm.
- If a regulation or framework governs the approach, tell the user to check the applicable standard text and confirm with a qualified audit lead.
Example Audit: FY25 access management review; population: 4,120 active user accounts; control: access removed within 2 days of leaver date; method: non-statistical attribute sample of 60, haphazard selection; framework: internal IT audit manual.