Independent Singapore VCC guidance
Direct answer
Approve a core fund accounting system change only after the team proves what will change, which VCCs and sub-funds are affected, how data and calculations migrate, who can access the new process, how interfaces behave, and how the current state can be restored. Test representative and difficult cases in a controlled environment, reconcile opening and output control totals, obtain independent business approval, and monitor the first production cycles. A successful technical deployment is not enough when investor, NAV or accounting results remain unproven.
At a glance
- Classify the change by business and investor impact, not by the vendor’s technical label.
- Test migrated data, calculations, interfaces, access and reports against independently expected results.
- Define measurable stop, rollback and escalation criteria before the production window begins.
- Keep enhanced monitoring until several real outputs reconcile and exceptions are understood.
Who this is for
- Platform upgrades, migrations, configuration changes, calculation engines, interfaces or material reference-data changes affecting VCC accounting and reporting.
Important exclusions
- Treating vendor certification as VCC acceptance, bypassing security review, or changing governing fund terms through technology configuration.
Define the business change and affected population
Begin with the process and output, not a release number. State which VCCs, sub-funds, share classes, currencies, asset types, accounting policies, valuations, fees, investor transactions, interfaces and reports are affected. Identify upstream sources and downstream consumers, including spreadsheets and provider files that may not appear in the formal architecture. Classify what is unchanged as well as what changes. The approved scope becomes the population for test coverage, migration control totals, access review, communication and first-production monitoring.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Dimension | Scope question | Acceptance evidence |
|---|---|---|
| Entities | Which VCCs, sub-funds and classes are affected? | Complete configured population. |
| Data | Which balances, history and reference fields move? | Mapped source-to-target controls. |
| Logic | Which calculations or rules may differ? | Approved expected-result tests. |
| Interfaces | Which files, APIs and reports change? | End-to-end transmission evidence. |
| People | Which roles, access and procedures change? | Approved entitlements and training. |
Related guidance: critical VCC spreadsheet controls
Set authority and independence before testing
Name the change owner, technology lead, administrator owner, business testers, information-security reviewer, release approver and rollback authority. Separate development from final acceptance for material calculations or records. Define what the vendor certifies and what the VCC or manager must prove independently. Resolve conflicts where one team benefits from the target release date or reduced manual effort. Agree how defects are classified, who can accept residual risk and which unresolved conditions prevent production.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeGovernance prerequisites
- Business and technology owners agree the exact scope, assumptions, dependencies and excluded populations.
- Independent reviewers are assigned for material calculations, migrated balances, access and release approval.
- Defect severity, evidence standards, risk acceptance and escalation authority are documented before testing.
- Production access and emergency change rights are limited to current authorised roles with monitoring.
- Rollback ownership, decision time and communication routes are understood by every affected provider.
Build tests from real failure paths
Use production-like but properly protected cases covering ordinary processing, boundaries, exceptions and historical corrections. Include subscriptions, redemptions, capital activity, fees, corporate actions, income, expenses, multiple currencies, illiquid valuations, manual overrides, reversals and cross-period events where relevant. Calculate selected expected outcomes independently rather than comparing two systems that share the same faulty input. Test each affected sub-fund and class, then add end-to-end scenarios that cross bank, custody, transfer agency, ledger and reporting interfaces.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeTest design sequence
- SelectChoose cases that represent volume, complexity, boundaries, known exceptions and the highest-consequence failure paths.
- PredictDocument the expected accounting, investor and reporting result before executing the test in the changed system.
- ExecuteRun controlled cases with traceable inputs, versions, users, timestamps and interface messages.
- CompareExplain every difference against independent expectations and current production results where appropriate.
- RetestRerun corrected defects and regression cases so one fix does not damage an unrelated calculation or output.
Related guidance: VCC investment-rule testing after a release
Reconcile migration and opening positions
Agree source cut-off, extraction method, transformation rules, target load and reconciliation control totals. Compare cash, positions, cost, accrued income, expenses, capital, investor units, realised and unrealised results, fees, tax attributes and reference data at the level used by the VCC. Trace differences to approved transformations rather than forcing totals to match through unexplained journals. Confirm historical records remain retrievable and that each sub-fund retains separate ownership. Freeze or control source changes during the cutover window.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Control | Comparison | Release requirement |
|---|---|---|
| Population | Source and target record counts by entity | Every missing or extra record explained. |
| Value | Balances and positions by sub-fund and class | Differences resolved or approved explicitly. |
| History | Transactions, prices and audit trail | Required periods remain usable and searchable. |
| Reference data | Identifiers, currencies, rules and mappings | No ambiguous or default mapping remains. |
| Access | Users, roles and privileged rights | Only approved current access is active. |
Prove interfaces, reports and operational readiness
Test file names, schedules, record counts, acknowledgements, rejected messages, duplicates, late delivery and recovery across every inbound and outbound connection. Confirm reports use the intended data cut-off, entity, sub-fund, class, currency and version. Rehearse the daily or periodic run with actual operating roles, including exception handling and provider escalation. Training should cover changed decisions and controls, not only screen navigation. Update procedures, inventories and support contacts before the production gate.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: critical VCC service outage mapping
Make the release and rollback decision
Assemble approved scope, test coverage, defects, reconciliations, access review, operational rehearsal, data protection assessment, cutover tasks, communications and support arrangements. Define stop conditions such as unexplained control-total differences, material calculation defects, failed interfaces, unauthorised access or inability to restore the prior state. The rollback plan must specify data captured after cutover and how it will be preserved or replayed. Obtain accountable business approval rather than treating a vendor go-live recommendation as sufficient.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeProduction gate
- All critical evidence passesApprove the controlled release with named monitoring, escalation and rollback owners for the production window.
- A material defect remainsDelay release unless the authorised risk owner accepts a supported, time-bound and genuinely controllable alternative.
- Control totals do not reconcileStop and investigate rather than using balancing entries or unsupported tolerances to meet the date.
- Production becomes unstableInvoke the approved stop or rollback route while preserving transactions, logs and decisions made after cutover.
Related guidance: VCC manual workaround approval during an outage
Monitor real production outcomes
Use enhanced review for the first production cycles: reconcile key balances, recalculate selected outputs, inspect overrides and access, review interface exceptions and compare reports with authoritative sources. Track workarounds and late defects rather than normalising them as post-launch noise. Exit enhanced monitoring only when the agreed evidence is complete and residual issues have owners and accepted risk. Retain the release pack, production results and lessons so the next change starts with known failure modes rather than a blank template.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeEnhanced monitoring evidence
- Opening and closing balances reconcile by VCC, sub-fund, class, currency and material asset or liability type.
- Selected NAV, fee, investor and performance outputs agree with independently expected calculations.
- Interface rejects, duplicates, delays and manual workarounds are tracked to resolution and reviewed for impact.
- Privileged activity and changed entitlements match the approved access design and operational need.
- Exit from enhanced monitoring is approved against evidence rather than the passage of time alone.
Frequently asked questions
Which fund accounting changes need formal change control?
Use impact, not the vendor label. A configuration, interface, reference-data, access or report change can be material when it affects investor transactions, NAV, fees, accounting records, sub-fund ownership or regulatory output, even if the supplier calls it routine.
Is parallel running always required?
Use a method proportionate to risk, but material calculations and migrated records need independent expected results and end-to-end evidence. A parallel comparison is often useful, provided differences are explained and the current system is not assumed to be correct automatically.
Can the administrator approve its own system migration?
The provider can certify its work, but the VCC or manager should retain accountable business acceptance and independent challenge over material data, calculations, access and outputs. Contractual delegation does not eliminate the need for informed oversight.
What makes a rollback plan credible?
It names the decision owner, trigger, latest decision time, steps, dependencies and communication route, and explains how transactions or data created after cutover will be preserved or replayed. The prior environment and required access must actually remain available.
When can enhanced monitoring end?
End it when agreed production evidence has passed, control totals reconcile, material outputs are independently checked and remaining defects or workarounds have accepted owners and risk. A quiet support queue or elapsed calendar period is not enough on its own.
Official sources and further reading
- Technology Risk Management Guidelines (Monetary Authority of Singapore)
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Guideline SFA 04-G05 on Licensing and Conduct of Business for Fund Managers (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.