What counts as a related party under the accounting standards?
The controlling definition for US financial statements is the one set out in FASB Statement of Financial Accounting Standards No. 57, Related Party Disclosures (March 1982), in its Appendix B glossary at paragraph 24(f); the same requirements are carried in the FASB Accounting Standards Codification at Topic 850, Related Party Disclosures. It is a list plus a catch-all. The list names affiliates; entities whose equity securities would be accounted for by the equity method; “trusts for the benefit of employees, such as pension and profit-sharing trusts that are managed by or under the trusteeship of management”; principal owners; management; and “members of the immediate families of principal owners of the enterprise and its management.”
The catch-all is where most contested matters live. Statement No. 57 extends the definition to “other parties with which the enterprise may deal if one party controls or can significantly influence the management or operating policies of the other to an extent that one of the transacting parties might be prevented from fully pursuing its own separate interests,” and adds that a party is also related if it can significantly influence the management or operating policies of the transacting parties, or holds an ownership interest in one and can significantly influence the other to that same extent. Significant influence, not ownership, is the operative concept.
Two consequences follow for anyone reading a set of financial statements. The population is fixed by relationships rather than by transaction size, so there is no dollar threshold that removes a counterparty from the definition. And because the definition can only be applied by someone who knows who is related to whom, the completeness of a disclosure depends on facts held by management. That is the structural reason related-party disclosure is tested rather than relied on.
What has to be disclosed, and why are the disclosures so often incomplete?
Statement No. 57 ¶2 — the requirement carried into ASC Topic 850 — provides that financial statements “shall include disclosures of material related party transactions, other than compensation arrangements, expense allowances, and other similar items in the ordinary course of business,” and that the disclosures must include “[t]he nature of the relationship(s) involved,” a description of the transactions “including transactions to which no amounts or nominal amounts were ascribed,” the dollar amounts of transactions for each period presented, and amounts due to or from related parties with the terms and manner of settlement if not otherwise apparent. Statement No. 57 ¶4 goes further: where common ownership or management control could make the reporting entity’s results significantly different from those of an autonomous entity, the control relationship is disclosed “even though there are no transactions between the enterprises.”
The arm’s-length paragraph is the one most often overstepped. Statement No. 57 ¶3 provides that “[t]ransactions involving related parties cannot be presumed to be carried out on an arm’s-length basis, as the requisite conditions of competitive, free-market dealings may not exist,” and that representations about such transactions “shall not imply that the related party transactions were consummated on terms equivalent to those that prevail in arm’s-length transactions unless such representations can be substantiated.” The burden runs toward substantiation, and a note asserting equivalence without support is itself a testable item.
For SEC registrants two more regimes apply and they do not line up with ASC 850. Item 404 of Regulation S-K, 17 C.F.R. § 229.404, sets a bright-line trigger — transactions exceeding $120,000 in which a related person had a direct or indirect material interest — and Item 404(b) requires a description of the registrant’s review and approval policies plus identification of any reportable transaction where those policies “did not require review, approval or ratification or where such policies and procedures were not followed.” Regulation S-X Rule 4-08(k)(1), 17 C.F.R. § 210.4-08(k)(1), separately provides that “[a]mounts of related party transactions should be stated on the face of the balance sheet, statement of comprehensive income, or statement of cash flows.” Incompleteness usually comes from the seams: a relationship that is real but not named, a party outside the Item 404 categories, or a counterparty nobody at the company knew was connected.
What in the records surfaces a relationship nobody disclosed?
Identity data first, because it is the cheapest and it is recorded for operational reasons rather than reporting ones. Address, telephone and bank fields in the vendor and payee master compared against the same fields for employees, officers and directors; taxpayer identification numbers; names appearing in more than one master file; the endorsement and deposit detail on the back of cleared items, which shows where a payment actually landed rather than where it was addressed. PCAOB Auditing Standard 2410, Related Parties, treats this kind of information as squarely relevant: ¶.05 requires the auditor to inquire of management about “[b]ackground information concerning the related parties (for example, physical location, industry, size, and extent of operations).”
Then the control record. AS 2410 ¶.05 requires inquiry about “related party transactions that have not been authorized and approved in accordance with the company’s established policies or procedures” and about transactions “for which exceptions to the company’s established policies or procedures were granted,” and ¶.12 requires the auditor to determine, for each transaction required to be disclosed or determined to be a significant risk, whether it was authorized and approved under those policies and whether exceptions were granted. Against a written approval matrix, that makes two things testable in the transaction file: invoices and payments sitting just below an approval limit, and repeated activity with one counterparty at amounts that never require the next level of sign-off. Round-dollar amounts and payments on a regular cadence with no supporting delivery record are screening heuristics rather than requirements of any standard, and they earn their place only by directing attention to a document that either exists or does not.
Finally the narrative record, which AS 2410 ¶.14 makes mandatory reading for the auditor: minutes of the meetings of stockholders, directors and committees of directors, or summaries of actions for meetings whose minutes are not yet prepared. Appendix A to AS 2410, at ¶.A3, lists further sources that may indicate previously undisclosed related parties, among them “[c]onflicts-of-interest statements from management and others,” “[s]hareholder registers that identify the company’s principal shareholders,” “[e]xpense reimbursement documentation for executive officers,” “[c]ontracts or other agreements (including, for example, partnership agreements and side agreements or other arrangements) with management,” and records from a whistleblower program. Where the counterparty is an entity rather than a person, the ownership question has its own methods and its own limits, covered in Who really owns the LLC that got the money?
What do the auditing standards require of auditors on related parties?
More than reading the disclosure. For audits of SEC issuers, PCAOB Auditing Standard 2410 sets the objective at ¶.02 as obtaining sufficient appropriate audit evidence “to determine whether related parties and relationships and transactions with related parties have been properly identified, accounted for, and disclosed in the financial statements.” Paragraph .14 states that evaluating whether the company has properly identified its related parties “involves more than assessing the process used by the company” and “requires the auditor to perform procedures to test the accuracy and completeness” of what the company identified. For audits of US entities other than SEC issuers, the parallel standard is AU-C section 550, Related Parties, issued by the AICPA’s Auditing Standards Board, and its paragraph numbering does not transfer.
Two AS 2410 requirements decide most audit disputes in this area. Paragraph .15 provides that where the auditor identifies information indicating that previously undisclosed related parties or transactions might exist, the auditor should perform the procedures necessary to determine whether they do, and that “[t]hese procedures should extend beyond inquiry of management.” Paragraph .16 then requires the auditor, on finding one, to evaluate why it was previously undisclosed and to “[e]valuate the implications for the audit if management’s nondisclosure… indicates that fraud or an illegal act may have occurred,” including the auditor’s obligations under Section 10A of the Securities Exchange Act of 1934, 15 U.S.C. § 78j-1.
The arm’s-length assertion carries its own consequence. Under AS 2410 ¶.18, if the financial statements include a statement by management that related party transactions were conducted on terms equivalent to an arm’s-length transaction, the auditor must determine whether the evidence supports or contradicts it, and if the auditor cannot obtain sufficient appropriate evidence and management will not modify the disclosure, the auditor “should express a qualified or adverse opinion.” The standard adds that a preface such as “management believes that” does not change the auditor’s responsibilities. Under ¶.19 the auditor must communicate to the audit committee, among other things, previously undisclosed related parties and significant related party transactions “that appear to the auditor to lack a business purpose.” Whether an engagement met those requirements is a question about one audit file, and it is the subject of Why didn’t our auditors catch the fraud?
What can a related-party analysis establish on its own, and what can it not?
It can establish that a relationship existed, that transactions ran across it, that the relationship was or was not disclosed where a standard required disclosure, and whether the company’s own approval policy was applied. Those are findings about records and about compliance with a written requirement. They are not findings about conduct, and the distance between the two is the whole discipline. An undisclosed relationship has ordinary explanations — nobody asked, the connection arose after onboarding, the counterparty was outside the categories on the questionnaire — and the analysis does not choose among them.
What it cannot establish is anyone’s intent, knowledge or motive, and it cannot convert a pattern into a conclusion. A shared address, a common bank account or a payment sequence under an approval limit is a reason to obtain a document, not a substitute for one. Statistical screens work the same way and are frequently overstated: a digit-distribution test such as Benford’s Law measures how a population of numbers is distributed and can say nothing about any individual transaction, so it never detects, proves or identifies a fraud. Nor is any of this an opinion that fraud occurred, which is reserved to the trier of fact and which an AICPA member performing forensic services is prohibited from offering under the AICPA’s Statement on Standards for Forensic Services No. 1 — explained at length in Can a forensic accountant say it was fraud?
Scale is worth keeping in view without being read as evidence of anything. In the Association of Certified Fraud Examiners’ Occupational Fraud 2026: A Report to the Nations, built from 2,402 cases in 143 countries and territories, corruption schemes — the category that includes conflicts of interest — appeared in 45% of cases, and the median scheme ran 12 months before detection. That says something about how often counterparty relationships matter in these matters and nothing about any particular one. What a transaction or a relationship was worth, and what the difference is between its terms and a market alternative, is a damages question that belongs to our Economic Damages Institute; the records work behind it, including reconstruction where the vendor file itself is incomplete, is covered in Records & Reconstruction.