Skip to content
VARIABLE CAPITAL
COMPANIES ACT
Let’s talk

Singapore VCC insights

Build a Compliance Monitoring Plan for a VCC Mandate

Risk & compliance illustration for Build a Compliance Monitoring Plan for a VCC Mandate
Illustration: Build a Compliance Monitoring Plan for a VCC Mandate.

Independent Singapore VCC guidance

By Variable Capital Companies Actreference

Direct answer

Build a VCC compliance monitoring plan from the obligations and risks that apply to the actual vehicle, sub-funds, manager and providers. For each control, define the owner, complete population, test method, sample basis, evidence, reviewer, frequency and escalation. Separate routine monitoring from event-driven tests. Grade findings by impact and recurrence, assign remediation with clear closure evidence, and retest independently. A calendar of review dates alone is not a monitoring plan.

At a glance

  • Use one control universe spanning VCC, manager and provider responsibilities.
  • Test population completeness before selecting samples.
  • Design event-driven tests for changes, incidents and breaches.
  • Close findings through evidence and retesting, not status updates.

Who this is for

  • Compliance, risk and governance teams building or refreshing monitoring for a live VCC mandate

Important exclusions

  • A generic regulatory calendar, legal opinion or replacement for the manager and VCC risk assessments

Create one control universe and responsibility map

Start with the VCC constitution, offering terms, investment mandate, manager licence scope, policies, service agreements, board decisions, risk assessment, prior findings and regulatory obligations. Break each requirement into an observable control and identify who performs, reviews, approves and receives exceptions. Distinguish the legal vehicle from the fund manager and each provider. A control performed by an administrator still needs a VCC or manager owner who can obtain evidence and challenge the result. Current fund-management rules cover risk management, valuation, safeguarding, customer priority and conflicts, while ACRA describes the VCC's continuing governance and filing framework. The plan should connect those layers without pretending one party owns everything.

Sources: Singapore Statutes Online · Accounting and Corporate Regulatory Authority · Accounting and Corporate Regulatory Authority
Minimum monitoring-plan fields
FieldPurposeFailure signal
Requirement and riskExplains why the control exists and what failure could harmA test with no traceable obligation or risk
Control and ownerNames the activity, performer, reviewer and accountable decision-makerShared ownership with no person able to close an exception
Population and systemDefines every event or record eligible for testingA sample selected before completeness is established
Method and evidenceStates the test steps and documents that support a conclusionReviewer judgement with no reproducible evidence
Frequency and triggerSets routine timing and events that require an extra testAnnual review despite material changes or repeated incidents
Finding and closureLinks severity, action, owner, evidence and retestRemediation marked complete from an email or revised policy alone
Sources: Monetary Authority of Singapore · Singapore Statutes Online · Accounting and Corporate Regulatory Authority

Design tests around populations and control purpose

For every test, first prove the population is complete. Reconcile the source report to an independent total, system sequence, cash ledger, trade book, investor register, approval log or provider attestation. Then choose a method that fits the risk: inspect every high-risk event, select a risk-weighted sample, compare independent records, reperformance, observe a control, or use data analysis to identify outliers. Record why the sample can answer the stated question. A large random sample can still fail if the source population excludes cancelled trades, manual overrides, late entries or cases handled outside the normal system. Preserve the original population and selection logic so another reviewer can reproduce the test.

Sources: Monetary Authority of Singapore · Singapore Statutes Online
  • Reconcile the population to a separate source before selecting any test items.
  • Include overrides, rejected events, cancellations, manual journals and out-of-system cases where relevant.
  • Use risk-based selection for unusual values, connected parties, new providers and prior failures.
  • State the expected control result before examining the sample.
  • Keep the evidence needed to reproduce each pass, exception and conclusion.
  • Escalate a population gap separately from failures found inside the sample.
Sources: Monetary Authority of Singapore · Singapore Statutes Online

Balance routine coverage with event-driven testing

Set routine coverage from inherent risk, control reliance, change rate, transaction volume, investor impact, prior findings and available evidence. Do not spread effort evenly merely to complete a calendar. Some controls deserve continuous or frequent monitoring; others can be tested periodically if the environment is stable. Add event triggers for a new sub-fund, mandate change, manager or provider change, system migration, valuation uncertainty, breach, investor complaint, regulatory update, staff turnover or repeated manual override. An event-driven test should examine the affected control promptly and should not wait for the next scheduled cycle. Record any deferred test with a reason, interim safeguard and approval.

Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority
  1. High impact and weak preventive controlUse frequent detective monitoring, broad coverage and rapid escalation until design and performance improve.
  2. Stable process with reliable evidenceUse periodic testing, but retain event triggers and rotate samples across sub-funds, providers and event types.
  3. Material change or incidentRun a targeted test immediately, reassess the control risk and adjust the future monitoring cycle.
  4. Population cannot be proven completeReport a design or data finding before drawing conclusions from any sample selected from that population.
Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Grade findings, remediate and retest

A finding record should state the failed control objective, affected population, known impact, potential impact, root cause, recurrence, interim containment, accountable owner and target outcome. Severity should reflect investor, asset, regulatory, financial and operational consequences, not the seniority of the control owner. Group related exceptions where they share a cause, but do not hide multiple affected cases in one vague observation. A revised policy is design evidence, not proof that the new control operates. Close remediation only after implementation evidence exists and an independent retest confirms the control works across an appropriate population. Report overdue, repeated and high-impact findings to the governance forum able to change resources or risk acceptance.

Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority · Singapore Statutes Online
  1. ContainProtect investors, assets and records while the cause and full affected population are established.
  2. DiagnoseSeparate isolated execution error from weak design, data failure, unclear ownership or deliberate override.
  3. RemediateDefine the target control outcome, owner, dependencies and evidence that will prove implementation.
  4. RetestUse an independent reviewer and a fresh population that can demonstrate sustained operating effectiveness.
  5. ReportShow themes, repeat findings, overdue actions and accepted residual risks to the correct decision-makers.
Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Frequently asked questions

What belongs in a VCC compliance monitoring plan?

Include the requirement and risk, control, responsible parties, population, system source, test method, sample basis, evidence, frequency, event triggers, reviewer, escalation, finding severity, remediation owner and retest standard for each material control.

Is a compliance calendar the same as a monitoring plan?

No. A calendar shows when an activity is due. A monitoring plan explains what control is being tested, why it matters, which population is in scope, how evidence will be assessed and how failures are escalated and closed.

How large should a compliance sample be?

There is no single useful number for every control. The reviewer should consider population size, risk, frequency, prior failures, control design and the purpose of the test. High-risk or unusual events may deserve complete review rather than sampling.

What if a provider performs the control?

Name the provider as performer but keep an accountable VCC or manager owner. The owner should receive sufficient evidence, challenge exceptions, track remediation and understand any limitation in the provider report or system population.

When can a finding be closed?

Close it after the agreed control is implemented, the required evidence exists and an independent retest demonstrates that it operates effectively. A plan, policy update, meeting note or provider assurance alone does not prove sustained closure.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

Your next step.

Let’s talk about your plans.

A fund, a family office or a trust structure. We coordinate corporate work alongside experienced law firms for legal and tax advice.

Talk to our team