Related party auditing is not just a disclosure checklist. Under ICAI's SA 550, the auditor has to understand related party relationships and transactions, assess the risks they create, remain alert for undisclosed relationships, and design procedures that respond to those risks. The standard matters because related parties are not independent of each other: transactions may be complex, information systems may not identify them completely, and terms may differ from normal market conditions.
What SA 550 is trying to achieve
SA 550 expands the auditor's work under risk assessment, responses to assessed risks and fraud considerations specifically for related parties. ICAI's current Engagement and Quality Control Standards index lists SA 550 within the 500-599 Audit Evidence series, and the official SA 550 text sets out the detailed requirements.
The auditor's objectives include understanding related party relationships sufficiently to recognise relevant fraud risk factors and to judge whether the financial statements achieve a true and fair presentation or are not misleading. Where the applicable financial reporting framework contains related party requirements, the auditor must also obtain sufficient appropriate audit evidence that related parties and transactions have been properly identified, accounted for and disclosed.
Why related parties can create higher audit risk
SA 550 does not say that every related party transaction is suspicious. It expressly recognises that many occur in the normal course of business and may carry no higher risk than similar transactions with unrelated parties. The risk increases where relationships are complex, systems do not capture related party information effectively, or transactions are entered into on unusual terms.
Related party relationships can also create opportunities for collusion, concealment or management manipulation. That is why professional skepticism is especially important. The audit approach should not stop at obtaining management's related party list and matching it to the financial statement note.
A practical SA 550 audit workflow
1. Build the related party universe
The auditor should inquire of management about the identity of related parties, changes from the prior period, the nature of each relationship, and whether transactions occurred during the period. A useful working paper normally starts with the prior-year list and updates it using current governance, ownership and management information.
The team should also understand management's controls for identifying, accounting for and disclosing related party relationships and transactions, approving significant related party transactions, and approving significant transactions outside the normal course of business.
2. Look beyond management's list
SA 550 requires the auditor to remain alert while inspecting records and documents for relationships or transactions that management has not identified or disclosed. The standard specifically points to bank, legal and third-party confirmations and minutes of shareholder and governance meetings as records that should be inspected for such indications.
In practice, useful cross-checks can include director and key-management declarations, ownership records, major vendor and customer masters, unusual journal entries, loan and guarantee records, legal confirmations, board minutes and significant contracts. The objective is not to create an unlimited investigation; it is to test whether management's identification process is credible and complete enough for the audit risk.
3. Focus on significant transactions outside the normal course
SA 550 requires identified significant related party transactions outside the entity's normal course of business to be treated as significant risks. For these transactions, the auditor should inspect the underlying contracts or agreements and evaluate the business rationale, whether the terms agree with management's explanation, whether accounting and disclosure are appropriate, and whether the transaction was properly authorised and approved.
This is an important distinction. A transaction can be correctly recorded mathematically and still deserve deeper audit attention because its commercial rationale, counterparty or terms are unusual.
4. Test arm's-length assertions instead of accepting the label
If management asserts in the financial statements that a related party transaction was conducted on terms equivalent to an arm's-length transaction, SA 550 requires sufficient appropriate audit evidence for that assertion. A signed agreement alone does not prove market equivalence.
Depending on the transaction, evidence might include comparable third-party quotations, independent valuation evidence, market pricing, historical dealings with unrelated parties, external financing terms or another defensible benchmark. The auditor should evaluate whether the comparison is genuinely comparable in volume, timing, credit terms, risk allocation and other economically relevant conditions.
5. Respond properly when an undisclosed related party is found
If the audit identifies a related party or significant related party transaction that management did not previously disclose, SA 550 requires more than adding a name to the checklist. The auditor should communicate the information to the engagement team, ask management to identify transactions with the newly identified party where the reporting framework requires it, investigate why the controls failed, perform appropriate substantive procedures, reconsider whether other undisclosed parties or transactions may exist, and assess fraud implications if the omission appears intentional.
Worked example
Assume a manufacturing company purchases a warehouse near year end from an entity controlled by a close family member of the managing director. The transaction is large, property purchases are unusual for the company, and the related party was not included in management's initial declaration.
A sound SA 550 response would not be limited to verifying the sale deed. The auditor would investigate the relationship, communicate the discovery within the engagement team, ask management why the relationship was omitted, search for other transactions with that party, inspect approval records and the contract, evaluate the business rationale and pricing evidence, test the accounting and disclosure, and consider whether the omission indicates a broader fraud or management-override risk.
Documentation checklist for the audit file
- Names of identified related parties and the nature of each relationship.
- Management inquiries and changes from the prior-year related party universe.
- Understanding and testing of relevant identification and approval controls where applicable.
- Records reviewed for indications of undisclosed related parties.
- Risk assessment for significant related party transactions, especially those outside normal business.
- Contracts, approvals, business rationale and accounting treatment for high-risk transactions.
- Evidence supporting any arm's-length assertion made in the financial statements.
- Follow-up procedures for newly identified or undisclosed parties or transactions.
- Evaluation of financial statement accounting and disclosures.
- Written representations and significant matters communicated to those charged with governance.
Common mistakes to avoid
- Treating the management declaration as complete without corroborative procedures.
- Assuming every related party transaction is automatically high risk, rather than identifying the circumstances that make risk higher.
- Ignoring unusual transactions merely because they were formally approved.
- Accepting an arm's-length statement without evidence supporting market-equivalent terms.
- Finding one undisclosed party but failing to reconsider whether the identification controls have failed more broadly.
- Documenting transaction testing without documenting the relationship, risk assessment and final disclosure conclusion.
Practical takeaway
SA 550 is best applied as a risk-based investigation of relationships, not as a year-end disclosure tick box. Build and challenge the related party universe, understand the controls, stay alert for undisclosed relationships, treat significant non-routine related party transactions as significant risks, test arm's-length claims with evidence, and expand procedures when an undisclosed relationship emerges. A strong audit file shows not only which transactions were checked, but why the auditor was satisfied that related party risks were identified, addressed and appropriately reflected in the financial statements.