Skip to content
VARIABLE CAPITAL
COMPANIES ACT
Let’s talk

Singapore VCC insights

Exercise Audit Rights Over a VCC Service Provider

Independent Singapore VCC guidance

By Variable Capital Companies Actchecklist

Direct answer

Use a VCC provider audit right when ordinary oversight cannot answer a material control question, or when an incident, repeated failure, major change or weak assurance creates a specific evidence gap. Define the affected service, VCC and sub-funds, risk question, period and expected evidence before contacting the provider. Start with reliable existing assurance where it addresses the same control and population; add focused walkthroughs, samples or direct testing only where gaps remain. Finish with a documented reliance decision, owned remediation, retest criteria and escalation if access is obstructed.

At a glance

  • Tie the audit request to a specific risk question and affected VCC service.
  • Use existing assurance only when its scope, period and exceptions answer that question.
  • Protect confidential information while preserving enough access to test the control.
  • Convert findings into reliance, remediation and exit-readiness decisions.

Who this is for

  • VCC directors, managers and outsourcing owners overseeing administrators, technology, compliance, data or other critical providers.

Important exclusions

  • A financial-statement audit opinion, legal interpretation of a disputed contract or unrestricted access to another client environment.

Start with the oversight question

Do not begin by asking for every policy and report the provider holds. State the event or uncertainty that makes current oversight inadequate, the affected service and the decision that evidence must support. A recurring processing failure may require transaction sampling and root-cause evidence, while a system change may call for access, testing and migration controls. Map the question to the VCC, sub-funds, processes, data, locations, subcontractors and period in scope. Record why routine service reviews, incident reports or standard assurance did not resolve it. This keeps the exercise proportionate and prevents a broad document request from consuming effort without revealing whether the important control works.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority
Audit-right trigger assessment
TriggerEvidence gapLikely response
Repeated service failureCause, population and repair are not independently supportedFocused sample, walkthrough and remediation validation
Material system or operating-model changeReadiness evidence does not show end-to-end controlChange evidence, access review and selected process testing
Weak or qualified assuranceControl scope, period or exception treatment is incompleteBridge evidence and direct testing of the missing area
Provider blocks ordinary oversightThe VCC cannot establish current control performanceFormal contractual escalation and reliance decision
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority

Read the contract before setting scope

Locate the executed agreement, amendments, service schedules, data terms and relevant subcontracting provisions. Confirm who may request evidence, the permitted methods, notice route, confidentiality restrictions, location limits, cost allocation and treatment of other clients information. Distinguish an information right from an audit right and a regulator-access clause from the VCC own review. Identify whether the provider may satisfy requests through pooled assurance, independent reports or certifications, and what happens when those materials are insufficient. The practical scope should fit the contract while still answering the oversight question. If the contract cannot support reasonable verification of a critical service, record that weakness as a separate governance and renewal issue.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Scope-setting file

  • Executed contract and all amendments have been checked for the relevant rights and limitations.
  • The affected service, process, system, location, subcontractor and evidence period are explicit.
  • The request states the control question and the decision that the evidence must support.
  • Confidentiality, personal-data and other-client boundaries have a practical handling plan.
  • Provider contacts, VCC owners, reviewers, escalation routes and expected outputs are named.
  • Existing assurance and prior findings are attached so work is not repeated without purpose.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Choose the least intrusive evidence route that works

Assess whether an independent assurance report, certification, control summary, management representation or prior audit can answer the current question. Check the covered entity, service, systems, locations, control objectives, testing period, sample basis, exceptions, complementary user controls and any gap between the report period and today. A clean conclusion is not useful when the relevant process sits outside scope. If pooled assurance answers part of the question, use it and narrow direct work to the residual gap. When documents alone cannot prove operation, add a walkthrough, selected evidence sample, remote demonstration or on-site test. The method should be strong enough to change a reliance decision if the control fails.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Evidence-route decision

  1. Existing assurance matchesUse it where entity, service, control, period and exception treatment align with the VCC oversight question.
  2. Assurance partly matchesAccept the supported portion and request bridge evidence or targeted testing only for the identified gap.
  3. No reliable assuranceAgree a controlled walkthrough and sample that can show design, operation, exceptions and accountable ownership.
  4. Evidence is restrictedUse redaction, supervised inspection or independent confirmation without accepting a conclusion that cannot be challenged.
  5. Access is obstructedEscalate under the contract, reassess reliance and prepare continuity or exit actions proportionate to the exposure.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Test controls through complete evidence chains

Select samples that can expose the suspected failure, not only ordinary successful items chosen by the provider. For a processing control, trace source instruction, validation, approval, system event, exception, output and downstream reconciliation. For access, connect the user request, approval, configured role, activity and removal. For change control, link the requirement, test result, defect, release approval and post-release monitoring. Preserve the sampling rule and population totals so omitted items are visible. Interview evidence can explain a process, but it should not replace records showing what occurred. Note provider explanations separately from independently observed facts and record every restriction that limits the strength of the conclusion.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Evidence-quality tests

  • The population is complete enough to support the chosen sample and is reconciled to an independent total.
  • Samples include exceptions, changes or stressed cases capable of disproving comfortable process descriptions.
  • Documents show the same transaction, account or change across the full control chain.
  • System evidence identifies source, time, user and status rather than relying on recreated screenshots.
  • Provider explanations are distinguished from records observed or independently confirmed.
  • Any redaction, unavailable evidence or scope restriction is reflected in the conclusion.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore

Turn findings into a reliance decision

Classify each finding by affected service, cause, population, VCC and sub-fund consequence, current exposure and the control that failed. Separate a one-time correction from remediation that prevents recurrence. The provider should supply an accountable owner, target state, interim safeguard and evidence that will demonstrate operation. The VCC and manager should decide whether reliance continues unchanged, continues with restrictions and monitoring, requires independent checks, or is no longer acceptable. Do not close a finding because a policy was rewritten or a ticket was marked complete. Retest the failed path with evidence capable of showing that the repair works under normal and exceptional conditions.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Finding-to-reliance sequence

  1. ConfirmAgree the factual condition, affected population and evidence limitations without negotiating away an observed control gap.
  2. ContainApply an interim safeguard that reduces current VCC and sub-fund exposure while durable repair is prepared.
  3. RepairAssign provider and VCC owners, define the target state and connect actions to the underlying cause.
  4. RetestSample the repaired path under conditions that could reveal recurrence, incomplete coverage or workarounds.
  5. DecideRecord continued, restricted or ended reliance and update oversight, contract, continuity and exit plans accordingly.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Report the outcome without overstating assurance

Give directors and accountable managers a concise report of the question tested, scope, evidence route, restrictions, findings, affected services, remediation status and residual uncertainty. Avoid a blanket statement that the provider passed when only one process or period was examined. Connect open items to the provider obligations calendar, service reviews, incident record, risk assessment and exit readiness. Where several VCCs or sub-funds share the provider, state whether the conclusion applies to all of them or only the sampled configuration. Schedule follow-up according to consequence and change, not a ceremonial annual date. Retain the request, evidence index, work performed, conclusion and final decisions as one traceable file.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore

Frequently asked questions

Must every provider receive an on-site audit?

No. The evidence method should match the service risk and the unresolved question. Reliable independent assurance may be enough for some controls, while direct testing may be necessary after repeated failures, major changes, weak reports or obstructed oversight.

Can a provider refuse access to other clients information?

Yes, legitimate confidentiality boundaries may limit what can be shown. Use redaction, supervised inspection, representative evidence or independent assurance, but record any restriction that prevents the VCC from reaching a sufficiently supported conclusion.

Is a clean assurance report enough?

Only if its entity, service, systems, control objectives, period and exceptions match the oversight question. Read the scope and complementary user controls carefully, and obtain bridge evidence when the report period or service coverage leaves a material gap.

Who should lead the provider review?

An owner who understands the affected VCC service should sponsor it, with risk, compliance, technology, legal or audit support as needed. The reviewer should be sufficiently independent from day-to-day provider performance claims to challenge evidence and conclusions.

When is an audit finding closed?

Close it when the factual gap is corrected, the underlying cause is addressed and a retest shows the repaired control operates across the relevant population. A revised policy, promised action or completed ticket alone does not prove effective remediation.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

Your next step.

Let’s talk about your plans.

A fund, a family office or a trust structure. We coordinate corporate work alongside experienced law firms for legal and tax advice.

Talk to our team