Related-Party Transaction Risk Audit in India: Promoter Links, Approvals, Pricing, Conflicts, Disclosures & Board Controls 2026
A board-level framework for identifying undisclosed relationships, approval failures, non-arm’s-length terms and governance risk in transactions involving connected persons or entities.
Related-party transactions are not inherently improper. Many groups legitimately share premises, personnel, financing, services, intellectual property or supply arrangements. The risk arises when the relationship is undisclosed, approval is bypassed, commercial terms are not supportable, the transaction is structured through an intermediary, or decision-makers participate despite a conflict.
A strong review therefore asks: who is connected to whom, what value moves between them, what approval was required, how were terms determined, what was disclosed, and does the evidence support the company’s stated position?
1. Start with a relationship map, not an invoice sample
Prepare a relationship map covering directors, key managerial personnel, promoters, relatives where legally relevant, holding/subsidiary/associate entities, entities under common control, partnerships, LLPs, trusts, proprietorships and material vendors or customers with potential personal links.
The company’s statutory related-party register should be compared with operational data. A relationship may exist in procurement or finance systems even if it was never captured in a governance register.
For the wider governance architecture, see Corporate Risk Mitigation in India.
2. Legal framework to review
Key Companies Act provisions commonly relevant include the definition of related party, director disclosure of interest, Audit Committee oversight where applicable, and approval requirements for specified related-party transactions. Listed entities may also be subject to additional securities-law requirements.
The audit should not rely on a single checklist copied from another company. Applicability, thresholds, ordinary-course analysis, arm’s-length considerations and approval requirements should be checked for the relevant transaction and period.
3. Types of transactions that deserve review
| Transaction | Typical risk | Evidence |
|---|---|---|
| Purchases/sales | Inflated or depressed pricing, concentration, preferential terms | Contracts, bids, benchmark prices, invoices |
| Rent/lease | Non-market rent, promoter-owned premises, undocumented escalation | Lease, valuation/market comparables, approvals |
| Loans/advances | Unsupported funding, weak repayment, diversion | Agreements, board records, bank data, balances |
| Guarantees/security | Company assets supporting connected obligations | Sanctions, security documents, board/shareholder records |
| Services/management fees | No evidence of service, vague scope, profit extraction | SOW, deliverables, time records, invoices |
| Asset/IP transfer | Value leakage, ownership uncertainty | Valuation, title, assignment, approvals |
4. Compare declarations with real transaction data
Director and employee conflict declarations should be compared with vendor and customer masters, not stored without verification. Useful tests include common addresses, contact numbers, email domains, bank accounts, directors, GST details or recurring transaction patterns.
Any data match is only a trigger for inquiry. Similar addresses or family names can have innocent explanations. The audit should verify the connection before drawing conclusions.
5. Approval pathway review
For each material transaction, determine what approval was required under law, the articles, board-approved policy, shareholder arrangements, delegation matrix and internal finance/procurement rules. Then compare that requirement with what actually happened.
Red flags include post-facto ratification becoming routine, interested decision-makers participating without appropriate handling, approval documents created after payment, vague resolutions, missing recusal records and repeated emergency exceptions.
6. Arm’s-length and ordinary-course analysis
Where the company relies on an ordinary-course or arm’s-length position, the conclusion should be supported by evidence. Depending on the transaction, useful material can include independent bids, market comparables, valuation reports, historic third-party pricing, cost-plus analysis, transfer-pricing support, published rates or a documented commercial rationale.
Merely describing a transaction as “arm’s length” in a board note does not establish that it was so.
7. Indirect and routed transactions
Connected transactions may be routed through distributors, consultants, subcontractors, group entities or newly incorporated vendors. A review should therefore look beyond the immediate counterparty where transaction structure, timing or ownership indicates an indirect benefit to a connected person.
Common indicators include pass-through margins, back-to-back invoices, unusual advances, common bank accounts, circular flows and a vendor with little operating substance.
For procurement-focused controls, see Vendor & Procurement Fraud Risk in India.
8. Promoter-owned premises and shared services
Private companies frequently use promoter-owned offices, warehouses, vehicles, personnel or group services. These arrangements should be documented with scope, price, tenure, tax treatment, allocation methodology, approvals and termination rights.
Unwritten related-party arrangements become difficult during fundraising, lender diligence, acquisition or promoter disputes because the company may not be able to demonstrate the commercial basis of historic payments.
9. Management override risk
Related-party controls fail where seniority can override vendor onboarding, pricing, approval limits or payment controls. The audit should review whether emergency authority was used disproportionately for connected entities and whether finance or procurement personnel felt able to challenge unsupported instructions.
Repeated override should be separately analysed under a management-control review, even if individual transactions ultimately prove legitimate.
10. Disclosure and record consistency
Compare statutory registers, board minutes, financial-statement disclosures, tax records, internal vendor lists and management representations. Material inconsistencies should be investigated and corrected through the appropriate process.
The objective is a single defensible relationship register that finance, legal, secretarial and management can all reconcile.
11. Related-party risk matrix
| Rating | Illustrative condition | Response |
|---|---|---|
| Critical | Undisclosed material relationship, suspected diversion, false documentation | Independent investigation and board escalation |
| High | Missing approval, unsupported pricing, repeated override | Legal review, remediation, re-approval where legally available |
| Medium | Documentation gap or stale declaration | Correct record and improve controls |
| Low | Properly disclosed, approved and benchmarked transaction | Routine monitoring |
12. Board-ready deliverables
- related-party relationship map;
- director/promoter/employee declaration reconciliation;
- transaction register by type and value;
- approval-exception schedule;
- pricing and benchmarking evidence index;
- indirect relationship red-flag list;
- loans/guarantees/security schedule;
- connected-vendor concentration analysis;
- disclosure reconciliation;
- remediation plan; and
- quarterly board/Audit Committee dashboard where applicable.
13. 30/60/90-day remediation
0–30 days: update relationship declarations, identify material connected entities, preserve records, stop unsupported new transactions and review urgent approval gaps.
31–60 days: benchmark pricing, document shared services, reconcile disclosures, clean vendor masters and redesign recusal/approval workflows.
61–90 days: implement periodic declaration refresh, automated related-party flags, board dashboards and annual testing of material transactions.
14. Frequently asked questions
Are all related-party transactions prohibited?
No. The issue is whether the transaction complies with applicable approval, disclosure and governance requirements and is commercially supportable.
Is promoter ownership of a vendor automatically improper?
No, but it should be disclosed and governed appropriately. Pricing, approval and conflict management become especially important.
Can a transaction be related-party even if the immediate vendor is not formally related?
Potentially, depending on the underlying relationship and applicable definition. Indirect structures should be examined on their facts.
How should pricing be tested?
Use evidence appropriate to the transaction: independent quotes, market comparables, valuation, historic third-party pricing or documented cost methodology.
Who should own the register?
Company secretarial/legal may maintain governance records, but finance, procurement and management data must reconcile with them.
Authoritative references
- Companies Act, 2013 — India Code
- Securities and Exchange Board of India
- Ministry of Corporate Affairs
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.