Skip to content
VARIABLE CAPITAL
COMPANIES ACT
Let’s talk

Singapore VCC insights

Control Authorised Signatories Across an Umbrella VCC

Independent Singapore VCC guidance

By Variable Capital Companies Actworked scenario

Direct answer

Create one controlled authority inventory that links each person or service identity to the VCC, sub-fund, provider, account, action, approval combination, limit, channel, effective date and source approval. Reconcile that inventory to provider-held mandates and live system roles, not merely internal resolutions. Separate preparation, approval and release, preserve sub-fund boundaries, and test representative transactions. Changes should trigger coordinated provider updates, independent readback, access removal and evidence that obsolete authority no longer works.

At a glance

  • Inventory authority by action and sub-fund, not only by person or job title.
  • Reconcile internal approvals with provider records and live system entitlements.
  • Separate preparer, approver and release capability across manual and digital channels.
  • Complete joiner, mover and leaver changes across every provider before considering the request closed.
  • Test both permitted and prohibited actions to prove that boundaries operate.

Who this is for

  • An umbrella VCC using banks, custodians, administrators, filing portals or other systems where people can instruct, approve, release or amend fund activity.

Important exclusions

  • A bank-specific legal mandate, a delegation of investment authority, or permission to broaden authority beyond current constitutive and provider documents.

Build the authority population by action

Collect board and manager approvals, bank and custody mandates, administrator authority forms, payment portals, dealing platforms, filing access, secure email lists and emergency arrangements. For each record, identify the legal entity, sub-fund, account, system and action. Distinguish view, prepare, approve, release, amend static data, create users and change limits. Record whether authority is individual, joint, sequential or role-based. Include service identities and automated interfaces where they can initiate or release activity. A person-level list is incomplete when the same individual can perform different actions for different sub-funds or through several channels.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority
Authority inventory fields
FieldQuestionEvidence
ScopeWhich VCC, sub-fund and account are affected?Named fund and provider record.
ActionWhat can the identity view, prepare, approve or release?Current mandate or role definition.
CombinationWho else is needed for completion?Joint or sequential rule.
BoundaryWhich limit, channel or restriction applies?Provider configuration and approval.
LifecycleWhen did authority start, change or end?Effective date and readback evidence.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Preserve sub-fund and action boundaries

An umbrella VCC may share people and providers, but the authority record should still show which sub-fund and account each action affects. Avoid group roles that permit a user to select any account when only a defined population was approved. Where one payment or custody portal contains several sub-funds, configure entitlements and approval combinations to preserve the intended boundary. Distinguish operating payments, investor money movements, securities instructions, static-data changes and administrative filings because their risks and approvers differ. If a provider cannot express the required granularity, document the limitation, apply a compensating review and decide whether the arrangement remains acceptable.

Sources: Accounting and Corporate Regulatory Authority · Monetary Authority of Singapore · Monetary Authority of Singapore

Boundary checks

  • Every account and portal role maps to a named VCC or sub-fund population and approved purpose.
  • Shared users cannot select an unapproved account merely because the provider groups it under one client profile.
  • Static-data changes use stronger review than ordinary preparation because they can redirect future transactions.
  • Investment, payment, filing and user-administration authority remain distinct where the operating model expects separation.
  • Provider limitations and compensating controls are visible to the accountable acceptance authority.
Sources: Accounting and Corporate Regulatory Authority · Monetary Authority of Singapore · Monetary Authority of Singapore

Worked scenario for a departing approver

Assume an operations director who jointly releases custody and banking instructions will leave, while remaining on notice for a handover period. The internal resolution names a replacement, but one bank portal, the custodian mandate, the administrator contact list and an emergency release procedure each use different change routes. The correct outcome is not simply adding the replacement. The team should determine the final permitted action date for the departing person, sequence additions and removals, preserve joint-control capacity, restrict user-administration rights, notify each provider through an authenticated channel and obtain an independent readback. Open transactions should be reassigned without sharing credentials or leaving both users unnecessarily active.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Authority change timeline

  1. ApproveRecord the old and new authority, effective timing, affected sub-funds, accounts, actions and required approval combinations.
  2. SequencePlan provider changes so the VCC retains safe operating capacity without creating an uncontrolled overlap of authority.
  3. SubmitSend authenticated change instructions through each provider channel and preserve receipt, queries and accepted scope.
  4. Read backObtain independent confirmation of live roles, mandates, limits and effective dates from provider records or controlled screens.
  5. Test and closeConfirm permitted actions work, prohibited actions fail, open items are reassigned and obsolete access is removed.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Reconcile internal and provider records

Compare the approved authority inventory with provider-held mandates, live user exports, account profiles and workflow rules. Use stable identifiers so similar names do not create false matches. Investigate authority found at a provider but absent internally, internal approval not reflected by the provider, expired authority that still works and service accounts with unclear ownership. Ask a reviewer independent of user administration to perform the comparison. Screenshot alone may not show hidden approval combinations or dormant alternate channels, so obtain formal confirmation where needed. Record exceptions by VCC, sub-fund, provider, identity and action, then restrict unsafe authority while the discrepancy is resolved.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Reconciliation evidence

  • Internal approval population agrees to provider mandate and live entitlement populations by stable identity.
  • Approval combinations, transaction limits, account scope and user-administration rights are explicitly compared.
  • Dormant, duplicate, generic and service identities have current owners and justified purposes.
  • Alternative channels such as secure email, paper forms and emergency procedures are included in the review.
  • Exceptions show interim restriction, accountable owner, provider action and verified closure evidence.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Test permitted and prohibited actions

Select representative accounts and actions across sub-funds and providers. Confirm that an authorised preparer can create but not release an instruction, that the required approver combination can complete it, and that a user outside the approved scope cannot access or submit it. Test static-data and user-administration boundaries separately. Where live tests would move assets or change records, use a provider test environment, controlled non-value transaction or evidence-based role simulation. Preserve expected and actual outcomes, participants, date, account scope and any cleanup. A successful permitted action does not prove the prohibited path is blocked, so both sides of the control need evidence.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore
Authority test matrix
TestExpected resultClosure evidence
Prepare in scopeInstruction created but not releasedWorkflow status and user record.
Release with correct pairApproved action completes through normal controlProvider confirmation and audit trail.
Attempt outside sub-fundAccess or action is blockedDenied event or provider evidence.
Change static dataEnhanced approval and confirmation applyBefore-and-after record with authority.
Use removed identityLogin and alternate instruction channels failAccess evidence and provider readback.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Maintain authority through change

Connect the inventory to joiner, role-change, absence, conflict, leave and termination processes. A role title change should not silently inherit authority from a predecessor. Trigger review when accounts, sub-funds, providers, workflows or approval limits change. Require periodic certification by business owners and independent comparison with provider records, while avoiding a check-box exercise based only on last period’s list. Emergency authority should be time-bound, separately approved, monitored and removed after use. Feed access exceptions, rejected instructions and provider delays into the control review. Retain prior versions so reviewers can explain who could act, for which fund, through which channel and under whose approval at any point.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Frequently asked questions

Is a board resolution enough to update provider access?

No. It records internal authority but does not prove that each bank, custodian, administrator or portal implemented the change. Close the request only after provider acceptance, independent readback and testing show that new authority works and obsolete authority no longer does.

Can one signatory act for every umbrella VCC sub-fund?

That depends on the approved documents and operating model. Even where the same person is authorised across several sub-funds, the inventory and provider configuration should preserve account, action and approval boundaries so an instruction cannot be misdirected or attributed vaguely.

Should service accounts appear in the signatory inventory?

Include any service identity or automated interface that can initiate, approve, release or alter material activity. Record its owner, credential control, permitted actions, monitored use and retirement route. Automation does not remove the need for accountable authority.

How should temporary emergency authority be handled?

Define the triggering event, permitted actions, sub-funds, approvers, start and expiry, monitoring and removal evidence. Test the emergency route before reliance where practical, and reconcile every action taken under it when normal control resumes.

What proves a leaver has lost authority?

Use evidence from every relevant provider and channel, including disabled login, removed mandate, changed approval combination, withdrawn secure-email authority and updated emergency records. Also confirm that open instructions and shared resources were reassigned without credential sharing.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

Your next step.

Let’s talk about your plans.

A fund, a family office or a trust structure. We coordinate corporate work alongside experienced law firms for legal and tax advice.

Talk to our team