Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161
Related party transactions audit procedures rank among the most scrutinized areas in PCAOB inspections. Nearly every major financial reporting fraud in modern history involved related party transactions that auditors failed to identify or adequately challenge. Enron’s transactions with special purpose entities, Tyco International’s executive loan arrangements, and FTX’s transactions with Alameda Research share one common thread. Each involved related parties operating outside the scrutiny that arm’s-length transactions naturally attract.
Issues with related parties played a prominent role in scandals at Enron, Tyco International, and Refco. Public outrage led Congress to pass the Sarbanes-Oxley Act of 2002 and establish the PCAOB. Similar problems have arisen in more recent financial reporting fraud cases, prompting the PCAOB to enact tougher standards on related-party transactions and financial relationships.
Inspection findings confirm the problem persists. The Board’s inspection program has identified a range of deficiencies in auditing related party transactions, particularly with respect to audits of smaller public companies conducted by smaller domestic audit firms. Deficiencies cited included failures to test for undisclosed related parties and failures to address risks posed by known related party transactions, including failures to obtain an understanding of the business purpose of such transactions.
At Shah Teelani & Associates, we treat related party transactions as a high-risk area on every engagement. This blog explains what PCAOB AS 2410 requires, where audit risk concentrates, and what common deficiencies reveal about where engagement teams fall short.
Related Party Transactions Audit Risk: Why It Exists on Every Engagement
Related party transactions differ fundamentally from arm’s-length transactions. Between unrelated parties, market forces and competing interests naturally constrain every deal. Between related parties, those forces disappear. One party controls or significantly influences both sides.
AS 2410 requires auditors to obtain an in-depth understanding of every related-party financial relationship and transaction, including their nature, terms, and business purpose — or lack thereof.
The absence of business purpose is a critical fraud indicator. Transactions serving no clear economic function — or achieving financial reporting outcomes management desires — warrant heightened skepticism. Moreover, management has both the incentive and the ability to structure these transactions in ways that obscure economic reality.
Auditors should view related party transactions, significant unusual relationships, and financial relationships with executive officers as presenting plausible risks of fraud or erroneous accounting. Approaching these areas from a more adversarial stance than other areas of the audit is appropriate.
The Three-Part Objective of AS 2410
The objective of the auditor under AS 2410 is to obtain sufficient appropriate audit evidence to determine whether related parties and relationships and transactions with related parties have been properly identified, accounted for, and disclosed in the financial statements.
Proper identification requires the auditor to go beyond management’s representations and actively search for undisclosed related parties. Proper accounting requires evaluating whether each transaction reflects economic substance — not just legal form. Proper disclosure requires evaluating whether financial statement disclosures give investors the information they need to assess the nature, terms, and financial effects of each relationship.
Failing any single element constitutes a deficiency — even where the other two are satisfied. Consequently, engagement teams must address all three explicitly in every related party workpaper.
Understanding the Company’s Related Party Process
Before testing individual transactions, auditors must understand the company’s process for identifying, authorizing, accounting for, and disclosing related party transactions.
The auditor should perform procedures to obtain an understanding of the company’s relationships and transactions with its related parties that might reasonably be expected to affect the risks of material misstatement of the financial statements.
This understanding covers three key areas. First, auditors must identify who the company considers related parties — including entities under common control, principal owners, and members of management. Second, existing controls over authorization must be examined — specifically whether transactions require board or audit committee approval before execution. Third, whether management’s identification process is systematic or informal requires explicit evaluation.
An informal process managed entirely by senior management creates inherent limitations. Where the individuals responsible for identifying related parties are themselves related parties — executives with ownership interests in counterparties — the reliability of management’s process requires additional scrutiny.
Searching for Undisclosed Related Parties
The highest-risk aspect of related party testing involves identifying parties and transactions that management did not disclose. Intentional omission conceals self-dealing. Unintentional omission reflects a process that lacks rigor. Both situations require the same auditor response.
If the auditor determines that a related party or relationship previously undisclosed to the auditor exists, the auditor should inquire of management regarding that party and the possible existence of other undisclosed transactions. Evaluating why the relationship was previously undisclosed, communicating relevant information to engagement team members, and reassessing the risk of material misstatement based on the new information are all required steps.
Discovering an undisclosed related party mid-engagement is not an isolated finding. It signals the need to revisit the entire engagement — reassessing fraud risk and expanding procedures.
Where to Search for Undisclosed Relationships
Several specific sources help auditors identify undisclosed relationships. Bank confirmations may reveal transactions with parties absent from management’s list. Board meeting minutes may reference individuals or entities not identified as related parties. Significant unusual transactions — particularly those lacking obvious business purpose — may connect to undisclosed relationships.
Indicators warranting investigation include transactions involving previously undisclosed parties, transactions with parties lacking the financial capability to support the transaction independently, transactions lacking commercial or economic substance, and transactions enabling the company to achieve specific financial targets.
Lawyers’ letters, proxy statements, and SEC filings provide additional search sources. Inquiring of individuals beyond management — audit committee members, internal audit staff, and legal counsel — often surfaces information that management omitted.
Evaluating Business Purpose
Even where management identifies related parties accurately, auditors must independently evaluate the business purpose of every significant related party transaction. Management’s assertion of legitimate purpose is not audit evidence.
Evaluating business purpose requires a specific question: could the same objective be achieved through an arm’s-length transaction with an unrelated party? Where the answer involves financial reporting benefits — smoothing earnings, avoiding covenant violations, achieving specific ratios — significantly heightened scrutiny applies.
Transactions where management emphasizes accounting treatment rather than economic substance, or where management has discussed the nature and accounting for the transaction with the audit committee, are specific fraud risk indicators requiring further investigation.
Each such indicator requires evaluating whether the transaction reflects genuine commercial activity or financial statement manipulation.
Related Party Transactions Audit: Testing Arm’s Length Terms
Where management asserts that related party transactions occurred on arm’s-length terms, AS 2410 requires independent evidence supporting that assertion — not just management’s representation.
Where financial statements include an assertion that transactions with related parties were conducted on terms equivalent to those prevailing in an arm’s-length transaction, auditors must obtain relevant written representations from management confirming there are no side agreements or other arrangements — either written or oral — undisclosed to the auditor.
Written representations are a starting point — never a conclusion. Comparable market transactions, independent appraisals, and industry benchmarks provide the independent corroboration AS 2410 requires. Where no comparable market data exists, the auditor must consider whether that absence itself indicates the transaction lacks economic substance. Transactions with no market equivalent may exist precisely because no unrelated party would accept those terms.
Specific AS 2410 Procedures for Significant Transactions
AS 2410 requires specific procedures for each significant related party transaction. Reviewing management’s documentation alone does not satisfy the standard.
Transaction terms must be read and evaluated for consistency with management’s explanations. Authorization records require examination — verifying approvals occurred before execution, not after. Relevant contracts, invoices, and supporting documentation provide direct evidence of terms and execution.
Inquiring of individuals beyond management is an explicit AS 2410 requirement. AS 2410 requires auditors to perform inquiries of those other than management and the audit committee. The auditor must also communicate any related party findings to the audit committee.
Individuals who processed transactions, legal counsel who documented them, and board members who approved them each provide perspectives that management-only inquiry cannot produce. Conflicting responses require immediate investigation — not documentation and continuation.
Evaluating Financial Statement Disclosure
After identifying and testing related party transactions, auditors must evaluate whether disclosures satisfy the applicable accounting framework.
ASC 850 requires disclosure of the nature of related party relationships, transaction descriptions including amounts, and the effects of any change in terms from prior periods. Disclosures must give investors sufficient information to assess every material related party relationship.
Inadequate disclosure is a financial statement misstatement — even where the underlying transaction accounting is correct. Boilerplate, vague, or incomplete disclosures require the auditor to conclude whether adequate disclosure exists. Additionally, auditors must evaluate whether any transactions require disclosure but do not currently appear in the financial statements — addressing completeness as explicitly as presentation quality.
Common Deficiencies PCAOB Inspectors Identify
Inspection findings in related party testing follow consistent patterns. Recognizing them helps engagement teams avoid replication.
Not searching for undisclosed related parties. Relying entirely on management’s identification — without independent search procedures — is the most fundamental AS 2410 failure. Management cannot reliably identify parties they have an incentive to conceal.
Not understanding business purpose. Documenting that a transaction exists and received approval does not satisfy AS 2410. Auditors must evaluate and document why the transaction served a legitimate purpose that could not be achieved otherwise.
Not testing arm’s-length assertions. Where financial statements assert arm’s-length terms, independent corroborating evidence is required. Accepting management’s representation alone fails both AS 2410 and the professional skepticism standard.
Limiting inquiries to management. AS 2410 explicitly requires inquiries beyond management. Audit committees, legal counsel, and internal auditors all provide information management alone cannot supply.
Not evaluating disclosure completeness. Testing transaction accounting without evaluating disclosures addresses only one of the three AS 2410 objectives. Disclosure completeness requires equal attention.
What Issuers and Audit Committees Should Know
Related party transactions create specific governance obligations for issuers. Audit committees bear primary responsibility for reviewing, approving, and monitoring every transaction between the company and its executives, directors, or their affiliates.
Strong governance practices include maintaining a current, comprehensive related party list — updated whenever executive relationships or ownership interests change. Pre-approving significant transactions before execution, rather than ratifying them afterward, directly supports auditor authorization testing. Organized transaction documentation — all contract terms, supporting analyses, and board approval records — reduces mid-engagement requests.
Proactive communication between audit committees and external auditors throughout the year matters significantly. Early communication enables auditors to design responsive procedures well before fieldwork begins — not after disclosures require finalization.
The Bottom Line
Related party transactions audit procedures require active skepticism, broad inquiry, and independent evaluation of business purpose and transaction terms. Relying on management’s identification, accepting management’s characterization of purpose, and limiting inquiry to management alone each produce a testing approach that fails AS 2410.
In 2026, with related party failures continuing to appear prominently in PCAOB inspection findings and enforcement actions, every registered firm must treat related party identification, evaluation, and disclosure testing as a primary engagement discipline — not a year-end formality.
Shah Teelani & Associates (PCAOB Reg. No. 7161) applies rigorous, skepticism-driven related party procedures on every public company engagement. We work with US-listed and OTC public companies that understand what complete and defensible related party audit conclusions require.
If your organization requires a PCAOB-registered auditor with strong expertise in related party transaction testing, we welcome the conversation.
Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States
I really like what you guys are up too. This kind of clever work and reporting! Keep up the amazing works guys I’ve incorporated you guys to my personal blogroll.