Independent Singapore VCC guidance
Direct answer
Recertify VCC access by building one population of every user, service account, portal, file exchange and approval role that can view data or move work for the fund. Match each entitlement to a current role, legal entity, sub-fund scope and named approver. Remove dormant, duplicate and conflicting access, then obtain system evidence that revocations completed. Keep exceptions time-bound and separately approved. The review is finished only when provider records and the VCC’s own authority map agree.
At a glance
- Review the whole service chain, including external portals and shared accounts.
- Match access to current responsibilities and exact VCC or sub-fund scope.
- Test combinations of rights, not just individual entitlements.
- Require system proof for revocation and changed access.
- Keep exceptions time-bound, owned and visible to the next review.
Who this is for
- VCC directors, managers, operations teams and provider owners coordinating access to fund systems, portals, accounts and data exchanges.
Important exclusions
- A replacement for the manager or provider security policy, incident response plan, contractual duties or technical security assessment.
Create the complete access population
Start from systems and channels, not from the current staff list. Include bank portals, custody platforms, administrator systems, transfer agency tools, accounting repositories, document rooms, regulatory filing portals, secure file exchanges, distribution lists and emergency access. Capture named users, shared identities, service accounts, delegates, approvers and people who can reset credentials. Map each item to its system owner, provider, VCC or sub-fund scope and business purpose. A person absent from human resources records can still retain provider access, while a current employee can hold obsolete rights inherited from an earlier role.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Inland Revenue Authority of Singapore| Field | Control question | Review evidence |
|---|---|---|
| Identity | Who or what uses the access? | Named user or controlled service identity |
| Scope | Which VCC, sub-fund, account or data set is visible? | System entitlement export |
| Capability | Can the identity view, create, approve, release or administer? | Role and permission detail |
| Purpose | Which current responsibility needs the access? | Role description and owner confirmation |
| Status | Was access retained, changed, removed or excepted? | Approver and system completion evidence |
Reconcile the system population with joiner, mover, leaver and provider records. Look for alternate usernames, old email domains, dormant accounts and roles created for implementation projects. Include mobile tokens, hardware authenticators and delegated approval devices where they affect access. If the same provider supports several funds, request evidence at the appropriate VCC and sub-fund level rather than accepting a generic statement. Record gaps in provider data as exceptions. An incomplete entitlement export should not be treated as a completed review merely because the business owner recognises the visible names.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: VCC cyber incident response across providers
Match entitlements to current responsibilities
For every identity, ask what task requires the access now. Compare the entitlement with the authority matrix, provider responsibility schedule, employment or engagement status and actual operating model. A portfolio professional may need view access without payment release. An administrator may prepare a record without approving the manager’s decision. A director may need governance materials without broad system administration. Record the least set of capabilities that supports the role. If the approver cannot explain a right in plain operational terms, route it for removal or a documented exception.
Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority · Monetary Authority of SingaporeRole-to-access checks
- Confirm the user is current and the identity belongs to that person or controlled service.
- Match view, create, amend, approve, release and administrator rights to separate tasks.
- Verify the legal entity, account, portfolio and sub-fund scope of every entitlement.
- Remove access retained only for convenience, historical familiarity or hypothetical cover.
- Record the business owner and independent approver for every retained high-impact right.
Treat temporary cover and emergency access as explicit cases. Record the reason, start condition, permitted action, approver and removal event. Do not solve a succession problem by leaving broad dormant rights active. Where one person holds several roles, review the combined capability and not just each role in isolation. The question is what the user can achieve from start to finish. A set of individually reasonable permissions can create an unreasonable ability to initiate, approve, release and conceal the same transaction or record change.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: VCC bank mandate change controls
Test conflicts and privileged routes
Build conflict tests around important workflows: investor onboarding, dealing, valuation, payments, custody instructions, accounting changes, regulatory filings and user administration. Identify whether one identity can both prepare and approve, change standing data and release a payment, amend a price and finalise NAV, or create users and certify its own access. Include provider administrators and support channels that can bypass the visible workflow. The response may be removal, narrower scope, a compensating review or redesigned responsibility, but the decision should be explicit and supported by evidence.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory AuthorityConflict decision tree
- High-impact capability?If no, retain only when the current role and scope are clear; if yes, continue the conflict review.
- Independent approval preserved?If not, remove or split the access unless a documented exceptional control is approved.
- Privileged or recovery route?Test administrator, reset, emergency and provider-support channels that can bypass normal approvals.
- Exception unavoidable?Set a narrow scope, named monitor, expiry event and evidence requirement before access continues.
Pay special attention to data exports and file exchanges. A user without transaction authority can still expose confidential investor, portfolio or banking information. Check who can create sharing links, change recipients, download bulk data, alter secure transfer destinations or add external collaborators. Review service accounts for ownership, credential rotation and dependency on departed staff. The VCC review should connect operational need with the provider’s technical evidence. A policy statement that access is restricted is not enough when the actual entitlement record shows broad or unexplained capability.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Inland Revenue Authority of SingaporeExecute changes and prove completion
Turn each review decision into a tracked change request with identity, system, current access, required access, approver, provider owner and completion evidence. Sequence changes carefully when a replacement user or new approval chain is needed, but do not leave the old access active after the transition event. For external systems, obtain a fresh export, provider confirmation or direct test showing the final state. An email saying a ticket was raised does not prove revocation. Escalate overdue high-impact changes while the exposure remains open.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Inland Revenue Authority of SingaporeAccess change evidence chain
- DecideThe business and control owners record whether access is retained, narrowed, removed or excepted.
- RequestA controlled ticket identifies the identity, system, exact entitlement change and authorised approver.
- ImplementThe internal or provider administrator completes the change without altering unrelated access.
- VerifyA reviewer checks the final entitlement or direct access result against the approved decision.
- CloseThe evidence is linked to the population and any remaining exception retains an owner and expiry.
Use explicit failure handling. If a portal cannot provide an export, document the alternative evidence and residual limitation. If a former user remains active, consider whether related credentials, devices, distribution groups and downstream provider accounts also need action. If a shared identity cannot yet be removed, narrow its capability and establish named usage evidence while replacement work proceeds. Avoid closing the review with a summary percentage. Decision-makers need the exact unresolved identities, systems, capabilities, owners and next events that still create exposure.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: VCC manager replacement data pack
Maintain the review between cycles
A periodic review is a backstop, not the primary joiner, mover and leaver control. Connect access changes to role changes, provider transitions, new sub-funds, bank mandate updates, system launches and incident findings as they occur. Keep the inventory current enough that the next recertification starts from a reliable population. Compare recurring exceptions by provider and workflow. Repeated delays may indicate unclear ownership, weak contract evidence, poor portal reporting or a manual dependency that needs a structural fix rather than another reminder.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory AuthorityBetween-cycle controls
- Trigger access review when people, roles, providers, accounts or sub-funds change.
- Retest administrator, recovery and shared identities after system or provider changes.
- Track unresolved exceptions to a named expiry event and compensating evidence.
- Compare the authority map, provider records and actual entitlements after each material change.
- Feed access weaknesses found in incidents, audits or handovers back into the inventory.
Report outcomes in operational terms: access removed, access narrowed, conflict remediated, evidence missing or exception approved. Preserve the underlying details securely and limit distribution to those who need them. The board or oversight body should understand material unresolved access without receiving unnecessary credentials or sensitive exports. The final control question is simple: can the VCC show who can see, change, approve, release and administer each important workflow, why they need that capability, and how removal was proved when the need ended?
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory AuthorityRelated guidance: VCC provider exit and handover plan
Frequently asked questions
Should the review include provider staff?
Yes, where provider identities can access VCC data or perform important actions. Request evidence at the relevant system and fund scope, while respecting security and contractual limits on sensitive provider information.
Are shared accounts always unacceptable?
They create accountability and control challenges and should be avoided where named access is available. If a shared identity temporarily remains, document ownership, permitted use, monitoring, credential control and a replacement or expiry route.
What proves that access was revoked?
Use the strongest system evidence available, such as a fresh entitlement export, inactive status, removed role or controlled access test. A submitted ticket or informal email does not by itself prove the final state.
How should emergency access be reviewed?
Define who may activate it, what actions it permits, how usage is logged, who reviews the activity and what event removes the access. Emergency status should not become a permanent broad entitlement.
Does recertification replace cyber incident response?
No. Recertification tests whether planned access remains appropriate. An incident response handles suspected or actual compromise, containment, evidence, notification and recovery, although incident findings should feed back into access design.
Official sources and further reading
- Governance and Management of Variable Capital Companies (Monetary Authority of Singapore)
- Legal Obligations of a VCC Director (Accounting and Corporate Regulatory Authority)
- Overview of Managing a Variable Capital Company (Accounting and Corporate Regulatory Authority)
- Record Keeping Requirements (Inland Revenue Authority of Singapore)
- Frequently Asked Questions on the Notice on Technology Risk Management (Monetary Authority of Singapore)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.