Audit sampling has a birthday. It was born the day populations outgrew ledger-paper arithmetic, and it was never a method. It was a concession. Examining everything was impossible, so the profession built a rigorous discipline around examining a defensible fraction. The rigour was real. But it was rigour about a constraint, and somewhere across the decades the constraint became invisible and the concession got promoted to a method.
The constraint is now dead. Transactions, approvals, master-data changes and access grants are all events a machine can test against a control rule, continuously, at population scale. The habit survived, and the habit has started to need defending.
What a sample cannot see
Be fair to sampling first. Against systematic failure, a designed sample works, because a control that fails everywhere fails in any 25 items you pick. But mature control environments rarely fail systematically. They fail episodically (e.g. an override used eleven times in one bad week, or an automated control that silently regressed in March and was fixed in May). A sample's odds of catching an episode are roughly the episode's share of the population, which is to say close to zero. The workpapers will still say "no exceptions noted". That sentence is true and unhelpful at the same time, and it is all a sample can leave behind.
Test the population. Explain the sample.
The mechanics of testing everything
Population testing is not a bigger sample. It is a different thing. The control is written as a rule the data must always obey. Every payment matches an approved order, within tolerance, and no one both requested and approved it. Every access grant has an owner and an expiry. The rule runs against every event as it happens. Exceptions surface as they occur, each with an owner and a clock, while the millions of conforming events route to nobody, by design.
The evidence changes shape with it. Instead of "we tested 25 and found nothing", the file says "we tested the population; here are the eleven exceptions, their dispositions and the dates". One is an inference about what probably holds. The other is a record of what did.
What auditors do when machines test everything
Population testing does not shrink audit judgement; it relocates it. Someone must write the rules, and writing them is control design, the discipline's actual centre. Someone must judge the exceptions, which is where experience earns its keep. And someone must decide where sampling still belongs, because it does, wherever the question cannot be written as a rule (e.g. estimates and fraud hypotheses). The inversion is only this. The sample becomes the justified exception, not the default described as rigour.
Prophesee runs continuous assurance the way the argument implies. Controls live as always-on rules over one shared stream of events, exceptions arrive with owners and deadlines, and the audit trail is generated by the testing itself rather than assembled for the visit. Assurance as a by-product of operating is the part periodic tooling cannot imitate, whatever its testing calendar says. Start here.