Sample size is not theatre

Dashboard charts representing sampled control evidence

A control test that samples five convenient tickets and declares “100% pass” rarely helps anyone fix anything. We size samples against how often the control should operate and how much customer or funds impact a miss would carry.

For high-frequency reconciliations, we look across the test window rather than cherry-picking quiet days. For rare privileged access grants, we often test the full population in that window. The goal is a finding your operations lead can schedule — with sample references they can reopen.

If your last pack only showed a percentage without sample IDs, the next cycle should start by rebuilding the matrix before adding more controls.