Skip to content
VARIABLE CAPITAL
COMPANIES ACT
Let’s talk

Singapore VCC insights

Test VCC AML Controls With Independent Assurance

Independent Singapore VCC guidance

By Variable Capital Companies Actchecklist

Direct answer

Scope independent AML assurance around the VCC's actual risks and delegated control chain, then test evidence from selected investors, beneficial owners, transactions, alerts, sanctions results and escalations. The reviewer should be free from designing or operating the controls being tested and have access to the VCC, eligible financial institution and provider records needed to reproduce outcomes. Grade findings by exposure and control failure, assign accountable owners, preserve disagreements, and close remediation only after an independent retest proves the revised control works.

At a glance

  • Test how controls operated on real cases, not only whether policies exist.
  • Include the VCC, eligible financial institution and material provider handoffs in scope.
  • Select samples from risk and exception populations, then preserve reproducible evidence.
  • Keep finding ownership, due action, validation and risk acceptance visibly separate.
  • Close findings through retesting rather than management assertion alone.

Who this is for

  • VCC boards and AML control owners commissioning internal audit, external assurance or an independent compliance test.

Important exclusions

  • A legal conclusion about whether a particular review frequency, reviewer or scope satisfies every applicable obligation.

Set scope from the VCC risk map

Begin with the VCC structure, sub-funds, investor populations, beneficial owners, jurisdictions, distribution routes, strategies, transaction patterns and service-provider chain. Identify where VCC-N01 controls are performed, where evidence is held and who decides exceptions. Compare the documented risk assessment with actual investor and transaction data so stale assumptions become visible. The scope should explain why higher-risk populations, manual processes, new products, past incidents and unresolved findings receive attention. A generic annual checklist can miss the places where the VCC's real exposure and operational dependency have changed.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance

Assurance scope record

  • Named VCC, sub-funds, investor groups, review period and relevant activity.
  • Current risk assessment tied to real investor, jurisdiction and transaction data.
  • Control owners across the VCC, eligible financial institution and providers.
  • Systems, repositories and handoffs where evidence is created or retained.
  • Prior findings, incidents, overrides and material changes requiring targeted work.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance

Protect reviewer independence and access

Document who designed, operated, supervised and previously reviewed each control. A reviewer should not validate their own decisions or depend on the control owner to choose only favourable samples. Define direct access to governing documents, investor files, beneficial-owner evidence, screening results, monitoring cases, escalation records, system configuration, provider reports and staff. Set a route for unresolved access restrictions and management disagreement. Confidentiality should be protected through controlled access and redaction where appropriate, but it should not prevent the reviewer from reproducing material decisions.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority
Independence and access test
QuestionGood evidenceWarning sign
Who operated the control?Named owner and decision chronologyReviewer approved the same case
Who selected the sample?Risk-based population and documented methodControl owner supplied only clean files
Can outcomes be reproduced?Direct records and system evidenceReliance on a summary presentation
Can findings reach governance?Unfiltered reporting and escalation routeManagement can remove conclusions silently
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Select samples that can expose failure

Build the population before choosing samples. Include successful and rejected onboarding, high-risk and ordinary investors, beneficial-owner changes, periodic reviews, sanctions or screening alerts, unusual transactions, closed monitoring cases, escalations, late evidence and provider exceptions. Select across sub-funds, channels, risk levels and control owners. Add targeted samples for known weak points and a small unpredictable element to reduce preparation bias. Record why each sample was chosen. The aim is not statistical decoration; it is a defensible test of whether important controls operate when facts are difficult or inconvenient.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance
Risk-based sample design
PopulationWhy sample itEvidence trail
New and rejected investorsTests acceptance, escalation and stop controlsCDD file, decision, restriction and communication
Beneficial-owner changesTests ongoing accuracy and event responseTrigger, verification, screening and approval
Closed monitoring alertsTests investigation quality and closure rationaleData, analysis, conclusion and reviewer challenge
Provider exceptionsTests handoff visibility and accountabilityService record, escalation, remediation and VCC oversight
Sanctions or adverse-information hitsTests matching, containment and dispositionSearch inputs, result, evidence and decision
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance

Test design and operation separately

For each control, first ask whether the documented design can address the relevant risk: clear trigger, required evidence, decision criteria, owner, escalation and retained record. Then test whether it actually operated on the selected sample. Compare timestamps, source data, screening configuration, reviewer actions and downstream restrictions. A well-written procedure fails operating-effectiveness testing when staff skipped a step, accepted stale evidence, closed an alert without analysis or allowed dealing before approval. Conversely, a sensible one-off action does not repair a missing repeatable design. Record design and operation conclusions separately.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Case testing sequence

  1. ReconstructTrace the case from trigger and source data through every control action, decision and downstream consequence.
  2. ChallengeCompare the evidence with policy, risk facts and the rationale recorded at the time.
  3. ReperformRepeat key screening, calculation or decision steps using controlled inputs where practicable.
  4. ExpandWhen a failure appears, test the wider population and connected providers to determine scope.
  5. ConcludeState design and operating-effectiveness results separately, with evidence and unresolved limitations.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Follow provider handoffs end to end

Delegation does not make the handoff disappear. Select cases that cross the administrator, fund manager, eligible financial institution, screening vendor, corporate secretary or other provider. Verify who received the trigger, what information moved, whether fields and documents remained complete, who investigated exceptions, and what the VCC board could see. Compare service descriptions with actual responsibility and access. Where one provider relies on another's assurance, identify the evidence supporting that reliance. A case that is complete inside each provider can still fail if the handoff loses context or no one owns the final decision.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Handoff evidence

  • The trigger reached the correct control owner with complete investor and transaction context.
  • Provider systems retained consistent identifiers for the VCC, sub-fund and investor.
  • Exceptions moved through a named escalation route without informal side channels.
  • The final decision and any restriction reached every downstream system promptly.
  • VCC oversight received proportionate information about significant failures and remediation.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Grade findings by consequence and reach

A finding should state the expected control, evidence observed, failure, affected population, root cause, consequence and immediate containment. Grade it using potential exposure, recurrence, duration, control dependency, data integrity and whether management detected it. Do not reduce severity merely because the sampled case ended without loss or because a provider promises improvement. Distinguish a single execution error from a design gap that could affect every investor. Record management response and any disagreement without allowing negotiation to erase the reviewer's evidence-based conclusion.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance
Finding record
FieldQuestionClosure use
ConditionWhat happened and on which evidence?Defines the verified failure
ScopeWhich cases, sub-funds and providers may be affected?Drives expansion and containment
Root causeWhy did design or operation fail?Shapes effective remediation
ConsequenceWhat risk or decision was exposed?Supports severity and governance response
Owner and actionWho will change what control?Creates accountable remediation
Retest methodWhat proof will demonstrate effectiveness?Prevents assertion-only closure
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance

Close remediation only after retesting

Separate action completion from finding closure. A revised policy, new system rule or completed training may show that management acted, but it does not prove the control works. Verify that the change was approved, implemented in production, communicated to every affected provider and applied to the full population requiring correction. Then select fresh evidence and reperform the relevant control. If the retest fails or coverage is incomplete, keep the finding open and reassess severity. Any accepted residual risk should name the authorised decision-maker, rationale, limits and future review trigger.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Closure decision tree

  1. Action incompleteKeep the finding open, maintain containment and report the revised accountable plan to governance.
  2. Action complete, not testedRecord implementation but withhold closure until fresh operating evidence can be reproduced.
  3. Retest failsReassess root cause and scope, strengthen containment and escalate the repeated control failure.
  4. Retest passesClose with the sample, evidence, reviewer conclusion and any continuing monitoring condition attached.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Frequently asked questions

Is an AML policy review the same as independent assurance?

No. Policy review asks whether the documented design is suitable. Operating-effectiveness work traces actual cases, data, decisions, provider handoffs and downstream actions. A mature assurance review does both and records separate conclusions, because a good procedure can still be ignored or implemented poorly.

Can the eligible financial institution perform the review?

Independence depends on the exact work and reporting line. A person should not test controls they designed, operated or approved. The VCC should assess conflicts, competence, sample control and access, and may need another internal function or external reviewer for a credible conclusion.

How should samples be selected?

Start with the full population and risk map. Include high-risk, routine, rejected, changed, alerted and exception cases across relevant sub-funds and providers. Add targeted and unpredictable selections, explain the method, and expand testing when a failure suggests a wider population may be affected.

Can management close a finding after updating the procedure?

A procedure update is implementation evidence, not proof of operation. Closure should follow production deployment, population correction where needed and independent retesting on fresh cases. If the revised control cannot yet be tested, report the action status while leaving the finding open.

What should the VCC board receive?

Directors need a clear scope, independence assessment, limitations, findings, affected population, severity, containment, accountable actions, overdue items and retest results. Sensitive investor details can be restricted, but reporting should remain specific enough for the board to challenge control owners and providers.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

Your next step.

Let’s talk about your plans.

A fund, a family office or a trust structure. We coordinate corporate work alongside experienced law firms for legal and tax advice.

Talk to our team