Independent Singapore VCC guidance
Direct answer
Use a residual-risk acceptance register only when a defined exposure remains after current controls and an authorised person makes a time-bounded decision to tolerate it. Record the affected VCC or sub-fund, scenario, cause, current controls, potential consequence, decision owner, safeguards, prohibited activity, remediation, review date and expiry. Link the entry to the underlying issue and board or manager record. Do not use acceptance to relabel an unresolved breach, bypass a mandatory control or close an action without retesting.
At a glance
- Describe the actual exposure and affected mandate, not a generic risk category.
- Make decision authority, safeguards, review and expiry explicit.
- Keep acceptance separate from breach classification and action closure.
- End the acceptance only after remediation is implemented and independently tested.
Who this is for
- Fund manager and VCC governance teams documenting a temporary, informed decision about residual operational, investment or provider risk.
Important exclusions
- Permission to ignore law, licence conditions, fund documents, investor rights or controls that cannot be waived by the proposed decision-maker.
Distinguish four different records
Keep the risk inventory, incident or breach record, remediation plan and acceptance decision distinct but linked. The inventory describes exposures before an event. The incident file records what happened. The remediation plan changes the weakness. The acceptance register records the authorised decision to tolerate a defined remaining exposure for a stated period. Combining them encourages premature closure because one status field cannot show whether the event is resolved, the control remains weak and the residual exposure is still being tolerated.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Record | Purpose | Closure condition |
|---|---|---|
| Risk inventory | Describe exposures, controls and monitoring across the operating model | Updated when the exposure or control model changes. |
| Incident or breach file | Preserve facts, impact, decisions and required escalation | Facts, consequences and required responses are resolved. |
| Remediation plan | Deliver and test a change to the causal weakness | The changed control has been implemented and retested. |
| Risk acceptance | Authorise temporary tolerance of a defined residual exposure | Exposure ends, remediation succeeds, or authority withdraws acceptance. |
Related guidance: VCC service-provider incident response
Capture a decision-ready minimum record
The entry should identify the affected legal entity, VCC, sub-fund, process and provider; describe the failure scenario and potential consequence; state the current controls and why they are insufficient; and attach objective evidence. Add the accountable business owner, independent challenger, decision authority, safeguards, restricted activities, remediation plan, trigger events, review date and expiry. Use plain language that a later director or reviewer can understand without interviewing the author.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeMinimum register fields
- Unique reference linked to the underlying risk, event, finding and action records.
- Affected VCC, sub-fund, process, provider, systems and investor outputs.
- Specific failure scenario, plausible consequence and evidence supporting the assessment.
- Current controls, identified weakness and interim safeguards with named owners.
- Decision authority, rationale, prohibited activity, review triggers and expiry.
- Remediation milestones, retest method and final closure evidence.
Match authority to the exposure
Set an approval matrix based on the potential consequence, duration, affected mandates, investor impact and whether the exposure crosses provider or entity boundaries. The person who owns the failing process should propose the acceptance but should not be the only challenger. Compliance, risk, operations, investment and technology input should reflect the actual issue. Escalate to the VCC board where the exposure changes vehicle-level governance, investor outcomes or the board ability to oversee the manager and providers.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeAcceptance authority decision tree
- Local and readily reversibleUse authorised management approval with documented safeguards, monitoring and a short decision horizon.
- Crosses mandates or providersRequire broader challenge and confirm each affected owner understands the shared dependency.
- May affect investors or governanceEscalate through the appropriate manager and VCC board route before continued exposure.
- Outside available authorityDo not record acceptance; stop, restrict or obtain the required external decision or advice.
Related guidance: VCC sub-fund risk-appetite thresholds
Design safeguards that can be observed
Interim safeguards should reduce the likelihood or consequence and produce evidence. Examples include lower limits, manual review, restricted counterparties, duplicate reconciliation, additional approval, increased monitoring or suspension of a risky route. State the population and frequency in operational terms. A vague promise to monitor closely is not a control. Also record the burden and new failure modes created by a manual safeguard, particularly where staff capacity or provider timing may make it unreliable during stress.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Question | Weak entry | Useful entry |
|---|---|---|
| What is covered? | All relevant activity | Named VCC, sub-fund, route, instrument or provider population. |
| Who acts? | Operations team | Named role with backup and escalation owner. |
| What evidence appears? | Daily monitoring | Controlled report, review mark, exception and retained decision. |
| What stops activity? | Escalate if needed | Defined trigger, restriction and person authorised to act. |
| When does it end? | After remediation | Expiry or successful retest against stated acceptance criteria. |
Related guidance: critical VCC service outage map
Review, expire and close deliberately
Every acceptance should reach a review or expiry point without depending on the original owner remembering it. At review, reassess the exposure, incidents, control evidence, progress, changes in scale and any new affected parties. Renewal should be a fresh decision, not an automatic date extension. Closure requires evidence that the exposure ended or the remediation works, plus removal of temporary safeguards where appropriate. If the issue persists beyond repeated reviews, challenge whether the operating model, mandate or provider should change instead.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeAcceptance life cycle
- OpenLink the issue, define the residual exposure and identify available decision authority.
- ChallengeTest the consequence, alternatives, safeguards, affected mandates and reason continued activity remains justified.
- Accept or rejectRecord the authorised decision, limitations, monitoring, expiry and any specifically prohibited activity.
- MonitorReview control evidence, incidents, remediation progress and trigger events while the acceptance remains active.
- Close or renewRetest the control or make a fresh documented decision using current facts.
Report the portfolio of accepted risk
Provide governance with a view of active exposure by mandate, process, provider, age, decision authority and remediation status. Highlight repeated renewals, concentrated dependencies, missed reviews, incidents during acceptance and items without viable end states. The aggregate view should not replace the underlying decision records. It should help directors and senior management see whether temporary exceptions are becoming the permanent operating model and whether one provider or team carries several connected weaknesses.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: VCC board management-information pack
Frequently asked questions
Is risk acceptance the same as waiving a control?
No. Acceptance records a decision about a defined residual exposure after current controls and safeguards are understood. It should not be used to remove a mandatory control, override unavailable authority or avoid the separate classification of a breach.
Who should own a residual-risk acceptance?
The process or business owner should own the exposure and remediation, while independent functions should challenge the assessment. Final authority should match the potential consequence and affected mandates, providers, investors and governance bodies.
How long should an acceptance remain open?
Use the shortest practical decision horizon based on the exposure and remediation. The key control is a real review and expiry point with current evidence, not a universal duration. Renewal should require a fresh decision rather than an administrative extension.
Can compliance accept risk for the business?
Compliance can assess and challenge regulatory or conduct implications, but should not silently become the commercial risk owner. The authorised business or governance decision-maker should own acceptance, with compliance disagreement and limitations preserved where relevant.
What evidence is needed to close the register entry?
Show that the exposure ended or the changed control works using a defined retest and fresh activity. Link the result to the remediation, resolve connected incidents or findings, and remove temporary safeguards only when it is safe to do so.
Official sources and further reading
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
- Guideline SFA 04-G05 on Licensing and Conduct of Business for Fund Managers (Monetary Authority of Singapore)
- Technology Risk Management Guidelines (Monetary Authority of Singapore)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.