ISA 550 Related Parties: Risk, Audit Procedures, and Reporting

ISA 550 is the International Standard on Auditing that governs how auditors deal with related parties and related party transactions during a financial statement audit. It requires the auditor to identify who the entity’s related parties are, understand the transactions between them, assess the risks those transactions create (including fraud risk), respond with targeted procedures, and evaluate whether the financial statements disclose the relationships and dealings adequately under the applicable reporting framework. The standard applies the broader risk and fraud requirements of ISA 315, ISA 330, and ISA 240 to the specific problem that arises when the parties to a transaction are not independent of each other.1IAASB. Related Parties – ISA 550

Who Counts as a Related Party

ISA 550 does not write its own definition. It defers to the applicable financial reporting framework, which under IFRS is IAS 24. A related party, in broad terms, is any person or entity that can exercise control, joint control, or significant influence over the reporting company. Control usually flows from ownership, as with a parent and its subsidiary. Significant influence means enough power to shape financial and operating decisions without outright control.2ICJCE. International Standard on Auditing 550 Related Parties

The net is wide. Parents, subsidiaries, fellow subsidiaries, joint ventures, and associates all sit inside it. So do key management personnel and their close family members, along with any entities those individuals control. ISA 550 also flags the concept of dominant influence, where a party has the practical power to dictate decisions even without formal control on paper. Dominant influence is one of the harder relationships to detect because it often lives in informal arrangements rather than in a shareholder register.1IAASB. Related Parties – ISA 550

What Makes a Transaction a Related Party Transaction

A related party transaction is any transfer of resources, services, or obligations between related parties, whether or not money changes hands.2ICJCE. International Standard on Auditing 550 Related Parties A subsidiary licensing intellectual property from its parent for no fee is as much a related party transaction as one where the parent charges for it.

The question the auditor keeps coming back to is whether the transaction happened on arm’s-length terms, meaning the terms two independent parties would have agreed to when each was looking out for its own interests. A company selling inventory to a subsidiary at a 1% margin while outside buyers pay 15% is the textbook non–arm’s-length case. That kind of gap does not appear in open markets, and it raises an immediate question about whether the deal is designed to shift profits, absorb losses, or obscure the company’s real financial picture.

Why Related Party Transactions Create Audit Risk

Independent parties negotiate against each other, and that pressure tends to pull prices toward economic reality. Between related parties, the relationship can set the terms, and those terms may bear no resemblance to fair value. ISA 550 ties this directly to fraud: the standard states that fraud may be more easily committed through related parties, and it requires the auditor to factor related party arrangements into the fraud risk assessment carried out under ISA 240.3PASAI. International Standard on Auditing 550 Related Parties

A company might sell assets to a related entity at an inflated price to manufacture a gain. It might guarantee a related party’s debt without disclosing it, hiding a significant liability. Even without any intent to deceive, non-monetary exchanges, intercompany financing, and layered guarantees produce accounting errors because the substance of the deal is hard to pin down. There is often no independent market rate to benchmark against, so the auditor loses the objective evidence that makes other testing straightforward.

The presence of a related party with dominant influence is called out in ISA 550 as a specific circumstance the auditor must weigh in the fraud risk assessment.3PASAI. International Standard on Auditing 550 Related Parties When one party can effectively dictate both sides of a deal, the room for manipulation grows.

Red Flags to Watch For

Transactions priced well above or below market. Deals struck just before period-end that lift reported results. Counterparties that seem to lack the financial substance to fulfill their obligations. Arrangements with entities in jurisdictions where independent verification is difficult. A transaction that does not make commercial sense on its face is often the clearest signal that something is wrong.

What the Auditor Actually Does

Work begins in the planning phase. The auditor performs risk assessment procedures aimed at understanding the entity’s network of related parties and the controls management has built to identify and account for them. That starts with inquiries of management about who the related parties are, the nature of each relationship, and whether any transactions occurred during the period.1IAASB. Related Parties – ISA 550 Those inquiries reach beyond finance to other people in the organization who might know something relevant.

The auditor also inspects documents that tend to surface relationships management may not have volunteered: bank and legal confirmations, shareholder and board meeting minutes, and records of the entity’s investments.1IAASB. Related Parties – ISA 550 Shareholder records point to principal owners. Board minutes can reveal approved transactions or discussions of business relationships that never made it onto a disclosure list.

Testing Identified Transactions

Once a transaction is on the auditor’s radar, the work moves into the underlying documentation: contracts, agreements, invoices, and settlement records. The auditor is looking for the business rationale, proper authorization, and whether the accounting reflects the economic substance of the deal. Terms and amounts may be confirmed directly with the related party, and the auditor may inspect records held by that party as well.

Where a related party transaction is significant and falls outside the entity’s normal course of business, ISA 550 treats it as a significant risk and demands a more rigorous response.1IAASB. Related Parties – ISA 550 The auditor evaluates whether the deal has a legitimate business purpose or whether its absence suggests the transaction was structured to manipulate the numbers.

Evaluating Arm’s-Length Claims

When management asserts that a related party transaction was conducted on arm’s-length terms, the auditor cannot take the claim at face value. There has to be enough evidence to support it: pricing, payment terms, and conditions benchmarked against what unrelated parties would have agreed to under similar circumstances. If sufficient evidence is not available and management refuses to modify the disclosure, the audit opinion has to reflect the limitation.

When Undisclosed Related Parties Turn Up

One of the more distinctive features of ISA 550 is that it keeps the auditor alert throughout the entire engagement, not just during planning. If a previously unknown related party surfaces mid-audit, the standard requires several steps: telling the engagement team, asking management why the existing controls missed the relationship, performing additional procedures to see whether other undisclosed relationships or transactions exist, and reconsidering the risk that management withheld the information deliberately.

That last point matters. An undisclosed related party is not just a gap in the notes to the financial statements. It raises a question about whether the omission was intentional, which then colors the reliability of management’s other representations and the fraud risk assessment as a whole.3PASAI. International Standard on Auditing 550 Related Parties

What Management Has to Do

Primary responsibility for identifying related parties, accounting for the transactions correctly, and disclosing them properly sits with management and those charged with governance. That means putting controls in place to track who has control or significant influence over the entity and to monitor transactions with those parties across the reporting period.1IAASB. Related Parties – ISA 550

ISA 550 also requires the auditor to obtain a written representation from management on two specific points: that all related parties have been disclosed to the auditor, and that the related party disclosures in the financial statements are adequate.2ICJCE. International Standard on Auditing 550 Related Parties The representation letter fixes accountability. If a related party later comes to light that management failed to identify, the letter becomes evidence about where the failure sat.

Reporting, Documentation, and Opinion Consequences

Significant findings go to those charged with governance. That includes significant or unusual related party transactions identified during the audit, concerns about the adequacy of management’s controls, and any transactions that were not properly authorized or approved.1IAASB. Related Parties – ISA 550

The final step is a judgment on whether the financial statements, as affected by related party relationships and transactions, are fairly presented under the applicable framework. If the auditor cannot obtain sufficient evidence about whether the transactions are properly accounted for, or if disclosures fall short of what the framework requires, the opinion must be modified. Depending on the severity, that means a qualified opinion or an adverse opinion.1IAASB. Related Parties – ISA 550

On documentation, ISA 550 requires the auditor to record the names of all identified related parties and the nature of each relationship in the audit file.3PASAI. International Standard on Auditing 550 Related Parties That record supports the auditor’s conclusions and is available to quality inspectors and regulators later.

A Note on U.S. Audits

ISA 550 does not apply to audits performed under U.S. Public Company Accounting Oversight Board standards. Companies listed on a U.S. exchange follow PCAOB Auditing Standard 2410 regardless of where they are headquartered, and AS 2410 has its own requirements around independent testing of management’s related party identification, direct inquiries of the audit committee, and review of SEC filings and proxy statements.4PCAOB Public Company Accounting Oversight Board. AS 2410: Related Parties For groups audited across both regimes, both standards need to be understood on their own terms.