Independent Singapore VCC guidance
Direct answer
A VCC risk and control self-assessment should begin with the mandate, service chain and decision population, not a generic risk list. Write each risk as a cause, event and consequence for the affected VCC or sub-fund. Map preventive, detective and corrective controls to named owners and current evidence, then challenge both design and operation. Ratings should follow documented criteria and failed tests. The accountable authority should accept only clearly described residual exposure with actions, monitoring and review triggers.
At a glance
- Define the assessed mandate, period, sub-funds, strategies, services and providers before scoring risk.
- Write risks as plausible events with causes and consequences rather than broad labels.
- Link every relied-on control to an owner, frequency, evidence population and testing result.
- Carry unresolved findings into residual-risk decisions instead of rating around them.
Who this is for
- A fund manager assessing investment, operational, compliance, technology and provider risks for a VCC mandate or a defined sub-fund population.
Important exclusions
- A universal risk taxonomy, a substitute for specialist assessments, or an exercise that guarantees regulatory adequacy through a score.
Fix the assessment boundary and population
State the VCC, sub-funds, strategies, investors, period, locations, systems and providers included. Map the material journeys from investment decision and trading through valuation, investor dealing, payments, reporting and records. Include outsourced steps and shared umbrella services even where another party performs them. Record recent changes, incidents, audit findings, complaints and regulatory developments that affect the period. A clear boundary prevents the assessment from mixing group-level controls with evidence that never operated for this mandate. It also lets reviewers identify omissions, inactive populations and dependencies that a functional risk list may hide.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority| Field | Question | Output |
|---|---|---|
| Mandate | Which VCC and strategy are assessed? | Named legal and operating scope. |
| Population | Which sub-funds, accounts and events are included? | Complete review universe. |
| Service chain | Who performs each material step? | Roles, providers and systems map. |
| Period | Which operation and change window is covered? | Current evidence cut-off. |
| Context | Which incidents or changes affect the assessment? | Specific challenge inputs. |
Write risks as cause, event and consequence
Avoid labels such as operations risk or compliance risk. Describe what could cause failure, the event that may occur and the consequence for investors, assets, decisions, records or obligations. Identify the affected VCC or sub-fund and the process where the exposure arises. Separate distinct events that need different controls, even if they share a category. Consider investment process, valuation, liquidity, trading, conflicts, data, access, providers, continuity, financial resources and governance. Use incident and exception evidence to challenge optimistic wording. A risk statement should be specific enough that a reviewer can decide whether the mapped controls actually address it.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeRisk-statement quality checks
- The cause is observable and relates to the actual mandate, service chain or operating change.
- The event describes a failure or uncertainty rather than repeating the name of a control.
- The consequence identifies the affected investor, asset, sub-fund, decision, record or obligation.
- Separate events remain separate where they require different owners, evidence or responses.
- Recent incidents, exceptions and external developments are used to challenge completeness.
Related guidance: VCC operational risk indicator calibration
Map controls to evidence and ownership
For each risk, distinguish preventive, detective and corrective controls. Describe the trigger, performer, reviewer, frequency or event, data population, expected evidence and escalation. Confirm the control operated for the assessed VCC and period, rather than assuming a group policy is enough. Where a provider performs the activity, record how the manager obtains evidence and challenges exceptions. Identify key controls whose failure would materially change the assessment. Do not count several documents as separate controls when they depend on the same person, system or data. Map compensating controls only when they address the same consequence and can be evidenced independently.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore| Element | Required question | Evidence example |
|---|---|---|
| Trigger | What causes the control to operate? | Scheduled run or defined event. |
| Performer | Who executes and who reviews? | Current accountable roles. |
| Population | Which transactions or decisions are covered? | Complete source listing. |
| Action | What comparison, approval or restriction occurs? | Reproducible control step. |
| Evidence | What proves the control operated and exceptions closed? | Dated record and outcome. |
Test design and operation separately
Design effectiveness asks whether the control, if performed as described, addresses the stated risk. Operating effectiveness asks whether it actually ran across the relevant population, by authorised people, with evidence and timely exception handling. Review procedures and configurations for design, then sample or reperform actual instances for operation. Include periods of stress, staff absence, provider change or high activity where those conditions matter. A control can be well designed but not performed, or consistently performed but incapable of preventing the stated consequence. Preserve failed samples and scope limitations, and do not average them away through a favourable narrative.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeControl test sequence
- UnderstandWalk through the process with the performer and compare the description with current systems, providers and records.
- Assess designDecide whether the control addresses the risk cause or event with appropriate authority and information.
- Select evidenceChoose a representative population and retain the basis for sample or reperformance coverage.
- Test operationInspect execution, review, exceptions and outcomes without replacing missing evidence with verbal assurance.
- ConcludeRecord design and operating results separately, including limitations and the resulting risk impact.
Related guidance: VCC manager compliance function test
Rate risk with evidence and challenge
Apply documented likelihood and impact criteria that make sense for the mandate, then explain the evidence behind each rating. Inherent risk should reflect the exposure before the mapped controls, while residual risk should reflect current tested performance and unresolved issues. Do not reduce a rating because a policy exists if the control has not operated or cannot be evidenced. Compare ratings across similar sub-funds and challenge unexplained differences. Use operational data, incidents, limit breaches, exceptions, complaints, provider findings and control tests as inputs without turning any single indicator into the conclusion. Record reviewer challenge and changes to the first assessment.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeRating challenge prompts
- The rating criteria are defined before the workshop and applied consistently across comparable risks.
- Inherent exposure is not reduced by controls that belong in the residual assessment.
- Failed, missing or limited control evidence changes the residual conclusion explicitly.
- Incidents and exceptions are reconciled with the narrative rather than excluded as unusual events.
- Management challenge, disagreement and final authority are preserved in the assessment record.
Accept residual risk and maintain the assessment
For risks above tolerance or with uncertain control evidence, define the exposure, interim protection, sustainable action, owner, due point, monitoring and escalation. The acceptance authority should have the mandate and information to understand what remains. Acceptance should not be permanent where it depends on a temporary workaround, provider promise or incomplete test. Link actions to issue records and verify closure through evidence. Refresh the assessment when the strategy, investors, service model, provider, system, key people or regulatory setting changes, and when an incident disproves an assumption. Preserve prior versions so the direction of risk remains understandable.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeResidual-risk decision
- Within tolerance and evidencedApprove the assessment with routine monitoring and a clear trigger for earlier review.
- Within tolerance but uncertainKeep the risk visible and obtain missing evidence before relying on the favourable conclusion.
- Above tolerance with a viable actionApply interim controls, assign the sustainable fix and escalate progress to the accountable authority.
- Above tolerance without a safe actionRestrict or stop the affected activity until authority accepts a defensible alternative or exposure changes.
- Material change occursReopen affected risks and controls rather than waiting for the next scheduled assessment cycle.
Related guidance: VCC residual risk acceptance register · VCC control finding evidence closure
Frequently asked questions
Should one RCSA cover every VCC managed by the firm?
A common taxonomy can support consistency, but the assessment should preserve each mandate’s strategies, investors, sub-funds, providers, systems, incidents and control evidence. Combine populations only when the same risks and controls genuinely apply and reviewers can still identify mandate-specific exposure.
Who owns the RCSA?
Risk or compliance may coordinate methodology and challenge, while business and control owners provide the operational assessment and evidence. Final residual-risk acceptance belongs with the authority defined by governance, not automatically with the person who compiles the spreadsheet.
Can a policy prove that a control is effective?
No. A policy may support control design, but operating effectiveness needs evidence that the control ran for the relevant population, by authorised people, with review and exception handling. Missing evidence should affect the conclusion rather than being replaced by a verbal confirmation.
How should outsourced controls appear?
Describe the provider activity, evidence the manager receives, review performed, exceptions found, escalation rights and continuity or exit dependencies. Outsourcing a task does not remove the need to understand how the risk is controlled for the VCC mandate.
When should the RCSA be refreshed?
Refresh affected areas after material strategy, investor, provider, system, people or regulatory changes and after incidents or failed tests challenge an assumption. A scheduled review remains useful, but it should not delay reassessment when current evidence changes the exposure.
Official sources and further reading
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Guideline SFA 04-G05 on Licensing and Conduct of Business for Fund Managers (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
- Technology Risk Management Guidelines (Monetary Authority of Singapore)
- Understanding VCC Features, Eligibility and Requirements (Accounting and Corporate Regulatory Authority)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.