Define the unit and consequential error before sampling. Use ordinary records and exceptions, then state period, population, method, size, and reviewer.
A sample is evidence with limits. A review of 12 records from 400 cannot become a claim about every record. Score missing fields, wrong categories, stale context, unauthorized actions, and unclear escalations separately.
NIST suggests giving more attention to errors with greater consequence or exposure. Review the sample with the contributor and ask where the case became ambiguous.
Document what the sample can show and end with an action such as revising a rule, narrowing permission, or repeating the review.