Skip to content
VARIABLE CAPITAL
COMPANIES ACT
Let’s talk

Singapore VCC insights

Build a VCC Residual Risk Acceptance Register

Independent Singapore VCC guidance

By Variable Capital Companies Actreference

Direct answer

Use a residual-risk acceptance register only when a defined exposure remains after current controls and an authorised person makes a time-bounded decision to tolerate it. Record the affected VCC or sub-fund, scenario, cause, current controls, potential consequence, decision owner, safeguards, prohibited activity, remediation, review date and expiry. Link the entry to the underlying issue and board or manager record. Do not use acceptance to relabel an unresolved breach, bypass a mandatory control or close an action without retesting.

At a glance

  • Describe the actual exposure and affected mandate, not a generic risk category.
  • Make decision authority, safeguards, review and expiry explicit.
  • Keep acceptance separate from breach classification and action closure.
  • End the acceptance only after remediation is implemented and independently tested.

Who this is for

  • Fund manager and VCC governance teams documenting a temporary, informed decision about residual operational, investment or provider risk.

Important exclusions

  • Permission to ignore law, licence conditions, fund documents, investor rights or controls that cannot be waived by the proposed decision-maker.

Distinguish four different records

Keep the risk inventory, incident or breach record, remediation plan and acceptance decision distinct but linked. The inventory describes exposures before an event. The incident file records what happened. The remediation plan changes the weakness. The acceptance register records the authorised decision to tolerate a defined remaining exposure for a stated period. Combining them encourages premature closure because one status field cannot show whether the event is resolved, the control remains weak and the residual exposure is still being tolerated.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore
Record boundaries
RecordPurposeClosure condition
Risk inventoryDescribe exposures, controls and monitoring across the operating modelUpdated when the exposure or control model changes.
Incident or breach filePreserve facts, impact, decisions and required escalationFacts, consequences and required responses are resolved.
Remediation planDeliver and test a change to the causal weaknessThe changed control has been implemented and retested.
Risk acceptanceAuthorise temporary tolerance of a defined residual exposureExposure ends, remediation succeeds, or authority withdraws acceptance.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Capture a decision-ready minimum record

The entry should identify the affected legal entity, VCC, sub-fund, process and provider; describe the failure scenario and potential consequence; state the current controls and why they are insufficient; and attach objective evidence. Add the accountable business owner, independent challenger, decision authority, safeguards, restricted activities, remediation plan, trigger events, review date and expiry. Use plain language that a later director or reviewer can understand without interviewing the author.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Minimum register fields

  • Unique reference linked to the underlying risk, event, finding and action records.
  • Affected VCC, sub-fund, process, provider, systems and investor outputs.
  • Specific failure scenario, plausible consequence and evidence supporting the assessment.
  • Current controls, identified weakness and interim safeguards with named owners.
  • Decision authority, rationale, prohibited activity, review triggers and expiry.
  • Remediation milestones, retest method and final closure evidence.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Match authority to the exposure

Set an approval matrix based on the potential consequence, duration, affected mandates, investor impact and whether the exposure crosses provider or entity boundaries. The person who owns the failing process should propose the acceptance but should not be the only challenger. Compliance, risk, operations, investment and technology input should reflect the actual issue. Escalate to the VCC board where the exposure changes vehicle-level governance, investor outcomes or the board ability to oversee the manager and providers.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Acceptance authority decision tree

  1. Local and readily reversibleUse authorised management approval with documented safeguards, monitoring and a short decision horizon.
  2. Crosses mandates or providersRequire broader challenge and confirm each affected owner understands the shared dependency.
  3. May affect investors or governanceEscalate through the appropriate manager and VCC board route before continued exposure.
  4. Outside available authorityDo not record acceptance; stop, restrict or obtain the required external decision or advice.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Design safeguards that can be observed

Interim safeguards should reduce the likelihood or consequence and produce evidence. Examples include lower limits, manual review, restricted counterparties, duplicate reconciliation, additional approval, increased monitoring or suspension of a risky route. State the population and frequency in operational terms. A vague promise to monitor closely is not a control. Also record the burden and new failure modes created by a manual safeguard, particularly where staff capacity or provider timing may make it unreliable during stress.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore
Safeguard design test
QuestionWeak entryUseful entry
What is covered?All relevant activityNamed VCC, sub-fund, route, instrument or provider population.
Who acts?Operations teamNamed role with backup and escalation owner.
What evidence appears?Daily monitoringControlled report, review mark, exception and retained decision.
What stops activity?Escalate if neededDefined trigger, restriction and person authorised to act.
When does it end?After remediationExpiry or successful retest against stated acceptance criteria.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Review, expire and close deliberately

Every acceptance should reach a review or expiry point without depending on the original owner remembering it. At review, reassess the exposure, incidents, control evidence, progress, changes in scale and any new affected parties. Renewal should be a fresh decision, not an automatic date extension. Closure requires evidence that the exposure ended or the remediation works, plus removal of temporary safeguards where appropriate. If the issue persists beyond repeated reviews, challenge whether the operating model, mandate or provider should change instead.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Acceptance life cycle

  1. OpenLink the issue, define the residual exposure and identify available decision authority.
  2. ChallengeTest the consequence, alternatives, safeguards, affected mandates and reason continued activity remains justified.
  3. Accept or rejectRecord the authorised decision, limitations, monitoring, expiry and any specifically prohibited activity.
  4. MonitorReview control evidence, incidents, remediation progress and trigger events while the acceptance remains active.
  5. Close or renewRetest the control or make a fresh documented decision using current facts.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Report the portfolio of accepted risk

Provide governance with a view of active exposure by mandate, process, provider, age, decision authority and remediation status. Highlight repeated renewals, concentrated dependencies, missed reviews, incidents during acceptance and items without viable end states. The aggregate view should not replace the underlying decision records. It should help directors and senior management see whether temporary exceptions are becoming the permanent operating model and whether one provider or team carries several connected weaknesses.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Frequently asked questions

Is risk acceptance the same as waiving a control?

No. Acceptance records a decision about a defined residual exposure after current controls and safeguards are understood. It should not be used to remove a mandatory control, override unavailable authority or avoid the separate classification of a breach.

Who should own a residual-risk acceptance?

The process or business owner should own the exposure and remediation, while independent functions should challenge the assessment. Final authority should match the potential consequence and affected mandates, providers, investors and governance bodies.

How long should an acceptance remain open?

Use the shortest practical decision horizon based on the exposure and remediation. The key control is a real review and expiry point with current evidence, not a universal duration. Renewal should require a fresh decision rather than an administrative extension.

Can compliance accept risk for the business?

Compliance can assess and challenge regulatory or conduct implications, but should not silently become the commercial risk owner. The authorised business or governance decision-maker should own acceptance, with compliance disagreement and limitations preserved where relevant.

What evidence is needed to close the register entry?

Show that the exposure ended or the changed control works using a defined retest and fresh activity. Link the result to the remediation, resolve connected incidents or findings, and remove temporary safeguards only when it is safe to do so.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

Your next step.

Let’s talk about your plans.

A fund, a family office or a trust structure. We coordinate corporate work alongside experienced law firms for legal and tax advice.

Talk to our team