Corporate Risk Mitigation • Related Parties • India • 2026

Related-Party Transaction Risk Audit in India: Promoter Links, Approvals, Pricing, Conflicts, Disclosures & Board Controls 2026

A board-level framework for identifying undisclosed relationships, approval failures, non-arm’s-length terms and governance risk in transactions involving connected persons or entities.

MappingDirectors, promoters, relatives, group entities and connected vendors
ApprovalsBoard, committee, shareholder and internal authority pathways
EconomicsPricing, margin, loans, guarantees, services and asset transfers
EvidenceDeclarations, contracts, benchmarking, minutes and disclosures

Related-party transactions are not inherently improper. Many groups legitimately share premises, personnel, financing, services, intellectual property or supply arrangements. The risk arises when the relationship is undisclosed, approval is bypassed, commercial terms are not supportable, the transaction is structured through an intermediary, or decision-makers participate despite a conflict.

A strong review therefore asks: who is connected to whom, what value moves between them, what approval was required, how were terms determined, what was disclosed, and does the evidence support the company’s stated position?

Governance standard: the legal definition of a related party and the approval requirements depend on the company, transaction and applicable law. Thresholds and listed-entity requirements should be checked against the current framework for the specific case.

1. Start with a relationship map, not an invoice sample

Prepare a relationship map covering directors, key managerial personnel, promoters, relatives where legally relevant, holding/subsidiary/associate entities, entities under common control, partnerships, LLPs, trusts, proprietorships and material vendors or customers with potential personal links.

The company’s statutory related-party register should be compared with operational data. A relationship may exist in procurement or finance systems even if it was never captured in a governance register.

For the wider governance architecture, see Corporate Risk Mitigation in India.

2. Legal framework to review

Key Companies Act provisions commonly relevant include the definition of related party, director disclosure of interest, Audit Committee oversight where applicable, and approval requirements for specified related-party transactions. Listed entities may also be subject to additional securities-law requirements.

The audit should not rely on a single checklist copied from another company. Applicability, thresholds, ordinary-course analysis, arm’s-length considerations and approval requirements should be checked for the relevant transaction and period.

3. Types of transactions that deserve review

Transaction Typical risk Evidence
Purchases/sales Inflated or depressed pricing, concentration, preferential terms Contracts, bids, benchmark prices, invoices
Rent/lease Non-market rent, promoter-owned premises, undocumented escalation Lease, valuation/market comparables, approvals
Loans/advances Unsupported funding, weak repayment, diversion Agreements, board records, bank data, balances
Guarantees/security Company assets supporting connected obligations Sanctions, security documents, board/shareholder records
Services/management fees No evidence of service, vague scope, profit extraction SOW, deliverables, time records, invoices
Asset/IP transfer Value leakage, ownership uncertainty Valuation, title, assignment, approvals

4. Compare declarations with real transaction data

Director and employee conflict declarations should be compared with vendor and customer masters, not stored without verification. Useful tests include common addresses, contact numbers, email domains, bank accounts, directors, GST details or recurring transaction patterns.

Any data match is only a trigger for inquiry. Similar addresses or family names can have innocent explanations. The audit should verify the connection before drawing conclusions.

5. Approval pathway review

For each material transaction, determine what approval was required under law, the articles, board-approved policy, shareholder arrangements, delegation matrix and internal finance/procurement rules. Then compare that requirement with what actually happened.

Red flags include post-facto ratification becoming routine, interested decision-makers participating without appropriate handling, approval documents created after payment, vague resolutions, missing recusal records and repeated emergency exceptions.

6. Arm’s-length and ordinary-course analysis

Where the company relies on an ordinary-course or arm’s-length position, the conclusion should be supported by evidence. Depending on the transaction, useful material can include independent bids, market comparables, valuation reports, historic third-party pricing, cost-plus analysis, transfer-pricing support, published rates or a documented commercial rationale.

Merely describing a transaction as “arm’s length” in a board note does not establish that it was so.

7. Indirect and routed transactions

Connected transactions may be routed through distributors, consultants, subcontractors, group entities or newly incorporated vendors. A review should therefore look beyond the immediate counterparty where transaction structure, timing or ownership indicates an indirect benefit to a connected person.

Common indicators include pass-through margins, back-to-back invoices, unusual advances, common bank accounts, circular flows and a vendor with little operating substance.

For procurement-focused controls, see Vendor & Procurement Fraud Risk in India.

8. Promoter-owned premises and shared services

Private companies frequently use promoter-owned offices, warehouses, vehicles, personnel or group services. These arrangements should be documented with scope, price, tenure, tax treatment, allocation methodology, approvals and termination rights.

Unwritten related-party arrangements become difficult during fundraising, lender diligence, acquisition or promoter disputes because the company may not be able to demonstrate the commercial basis of historic payments.

9. Management override risk

Related-party controls fail where seniority can override vendor onboarding, pricing, approval limits or payment controls. The audit should review whether emergency authority was used disproportionately for connected entities and whether finance or procurement personnel felt able to challenge unsupported instructions.

Repeated override should be separately analysed under a management-control review, even if individual transactions ultimately prove legitimate.

10. Disclosure and record consistency

Compare statutory registers, board minutes, financial-statement disclosures, tax records, internal vendor lists and management representations. Material inconsistencies should be investigated and corrected through the appropriate process.

The objective is a single defensible relationship register that finance, legal, secretarial and management can all reconcile.

11. Related-party risk matrix

Rating Illustrative condition Response
Critical Undisclosed material relationship, suspected diversion, false documentation Independent investigation and board escalation
High Missing approval, unsupported pricing, repeated override Legal review, remediation, re-approval where legally available
Medium Documentation gap or stale declaration Correct record and improve controls
Low Properly disclosed, approved and benchmarked transaction Routine monitoring

12. Board-ready deliverables

  • related-party relationship map;
  • director/promoter/employee declaration reconciliation;
  • transaction register by type and value;
  • approval-exception schedule;
  • pricing and benchmarking evidence index;
  • indirect relationship red-flag list;
  • loans/guarantees/security schedule;
  • connected-vendor concentration analysis;
  • disclosure reconciliation;
  • remediation plan; and
  • quarterly board/Audit Committee dashboard where applicable.

13. 30/60/90-day remediation

0–30 days: update relationship declarations, identify material connected entities, preserve records, stop unsupported new transactions and review urgent approval gaps.

31–60 days: benchmark pricing, document shared services, reconcile disclosures, clean vendor masters and redesign recusal/approval workflows.

61–90 days: implement periodic declaration refresh, automated related-party flags, board dashboards and annual testing of material transactions.

14. Frequently asked questions

Are all related-party transactions prohibited?

No. The issue is whether the transaction complies with applicable approval, disclosure and governance requirements and is commercially supportable.

Is promoter ownership of a vendor automatically improper?

No, but it should be disclosed and governed appropriately. Pricing, approval and conflict management become especially important.

Can a transaction be related-party even if the immediate vendor is not formally related?

Potentially, depending on the underlying relationship and applicable definition. Indirect structures should be examined on their facts.

How should pricing be tested?

Use evidence appropriate to the transaction: independent quotes, market comparables, valuation, historic third-party pricing or documented cost methodology.

Who should own the register?

Company secretarial/legal may maintain governance records, but finance, procurement and management data must reconcile with them.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Website: fastracklegalsolutions.com
The particulars above are provided solely for identification and correspondence. They do not constitute an advertisement, solicitation, invitation or inducement to engage legal services.
General corporate-risk information only. Related-party definitions, thresholds and approvals must be checked against current law and the company’s facts.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *