Sampling
Selecting a subset of a population to test, using the result to infer a conclusion about the whole — a workaround for human throughput that automation makes largely unnecessary.
Sampling is a well-developed discipline: attribute sampling, monetary-unit sampling, defined confidence levels and tolerable rates. Applied properly it produces defensible conclusions from limited effort, and for genuinely manual controls — a signature on a paper form, an observation of a physical count — it remains the right method.
What deserves scrutiny is how often the sample size reflects statistics at all. In practice many teams use conventional sizes (25, 40, 60) inherited from guidance and habit, without a stated confidence level or tolerable deviation rate. That is not statistical sampling; it is a customary quantity of work.
Where the underlying records are digital and reachable, the honest position is that sampling is now a choice to test less than you could. Sometimes that choice is correct — the data is inaccessible, the control is manual, the cost of extraction exceeds the value. It is worth making the choice explicitly rather than by default, because “we tested 25” is increasingly a question an audit committee will ask about rather than accept.
Related