Independent Singapore VCC guidance

By Variable Capital Companies Actregulatory explainer

Direct answer

A VCC cyber incident needs one decision log even when several firms own the affected systems. Establish an incident lead, preserve evidence, identify the VCC, sub-fund, data and business services at risk, and separate technical containment from fund decisions about dealing, NAV, cash and communications. The fund manager must assess its own MAS obligations according to its regulatory status; the VCC board should demand verified operational facts and control any decision affecting the vehicle or investors.

At a glance

  • Use one command structure and one verified fact log across providers.
  • Classify the affected fund service before estimating business impact.
  • Keep technical containment separate from board decisions on cash, NAV or dealing.
  • Map regulatory and contractual notifications to the entity that actually owes them.
  • Recover from reconciled source records, then test for silent data corruption.

Who this is for

  • VCC boards and operating teams coordinating with a permissible manager, administrator, custodian, bank, secretary and technology providers after a suspected cyber event.

Important exclusions

  • A universal statement of MAS, privacy, criminal-reporting or foreign notification duties; those depend on the entities, licences, data and facts involved.

Open one command log

Nominate an incident lead, technical lead, legal and compliance lead, fund-operations lead and board liaison. Create a protected log that records time, source, verified fact, hypothesis, decision, owner and next check. Providers may keep their own forensic records, but the VCC needs a consolidated view of the consequences for each sub-fund and critical service. Restrict the group to people who need access; uncontrolled forwarding can compromise evidence, confidentiality and coordinated communications. Record uncertainty explicitly instead of converting assumptions into status updates.

Sources: MAS · MAS
  • Authenticate the alert through a second channel before following any instruction contained in it.
  • Preserve logs, messages, access records and affected files without asking ordinary users to investigate destructively.
  • Name the VCC, sub-fund, systems, accounts, data sets and providers potentially affected.
  • Freeze unverified changes to bank mandates, payment templates, investor standing data and privileged access.
  • Record every decision to continue, restrict or suspend a fund service with the facts and authority relied on.
  • Keep external communications under one approval route while each entity assesses its own obligations.
Sources: MAS · MAS

Route by critical fund service

Impact is not measured only by whether a server is online. Ask whether the team can prove investor ownership, calculate NAV, value assets, accept or reject dealing, move cash, settle trades, produce board authority and communicate through trusted channels. A system may appear available while its data is corrupted or its credentials are compromised. MAS business-continuity guidance emphasises identifying critical business services and recovery dependencies. Translate that approach into fund-specific recovery tolerances approved by the responsible entity, without inventing one generic deadline for every VCC.

Sources: MAS · MAS
  1. Can the source record be trusted?If integrity is uncertain, stop dependent processing and compare against an independent, time-stamped source before making fund decisions.
  2. Can cash or assets move safely?If credentials, mandates or instructions may be compromised, restrict movement and confirm authority through established alternative channels.
  3. Can NAV and dealing be supported?If holdings, prices, investor data or approvals are incomplete, escalate the affected dealing and valuation decision under the fund documents.
  4. Can investors be contacted reliably?If email or portal integrity is uncertain, use a pre-approved alternative and warn recipients how to authenticate future instructions.
  5. Is the affected entity regulated or contractually bound?Have that entity assess its reporting and notification obligations using the facts in the shared command log.
Sources: MAS · MAS · ACRA

Control fund decisions during containment

Technical responders may isolate systems, reset credentials or restore backups; they should not decide whether the VCC accepts subscriptions, pays redemptions, strikes NAV or changes a bank mandate. Route those decisions to the authority in the constitution, offering documents, board delegations and provider agreements. Use the smallest safe restriction: one user, account, sub-fund, data feed or dealing function where the evidence supports it. A platform-wide shutdown may be justified, but it should be a conscious fund decision rather than an accidental consequence of a vendor action.

Sources: MAS · Singapore Statutes Online · ACRA
  1. TriageAuthenticate the event, protect people and evidence, map affected entities and stop obviously unsafe access or instructions.
  2. ContainIsolate compromised paths while preserving alternative access for verified critical fund services where that remains safe.
  3. DecideEscalate cash, dealing, NAV, disclosure and communication choices to the authority named in the governing documents.
  4. RecoverRestore from trusted sources, rotate access, reconcile records and require independent checks before reopening each service.
  5. LearnComplete root-cause, control, contract, provider and board-action reviews, then track remediation to evidenced closure.
Sources: MAS · MAS

Recover from independent records

Recovery is a reconciliation exercise, not merely a backup restoration. Establish the last trusted point for investor holdings, portfolio positions, cash, pending trades, subscriptions, redemptions, fees, corporate approvals and access rights. Compare restored data to independent bank, custody, broker, administrator and signed corporate records. Sample high-risk changes made near the incident, including payee amendments, user creation, investor bank details and manual prices. Reopen each service only when its owner signs off the evidence and any residual manual control.

Sources: MAS · MAS
Recovery evidence
RecordIndependent comparatorRelease test
Investor ledgerSigned forms, prior close and bank receiptsHoldings and pending dealing reconcile
Portfolio bookCustody, broker and trade confirmationsPositions, cash and unsettled trades reconcile
NAV inputsIndependent prices and approved valuation recordsNo unexplained source or override remains
Payment setupBank records and authorised mandatesPayees, approvers and limits are revalidated
Corporate authoritySigned minutes, resolutions and statutory recordsCurrent delegation and signatory data are restored
Sources: MAS · ACRA

Frequently asked questions

Is the VCC itself subject to the MAS technology-risk notice?

Do not assume that result from the VCC label alone. MAS identifies the financial institutions within scope, including holders of a capital markets services licence. Assess the manager and every affected entity by its own regulatory status and seek advice on the facts.

Who should lead a multi-provider incident?

Name one coordinator for the VCC impact while each provider retains technical responsibility for its systems. The coordinator should maintain the verified fact and decision log, but should not override a provider’s forensic work or an entity’s own legal and regulatory duties.

Should dealing stop whenever a provider reports an incident?

Not automatically. Determine whether reliable investor, valuation, cash, authority and communication controls remain available, then use the decision route in the fund documents. Any continuation or restriction should be based on verified impact, not the incident label alone.

Can the team communicate through the affected email system?

Only after the security owner confirms it is safe for the intended purpose. Use authenticated alternative channels from the continuity plan where integrity is uncertain, and tell recipients how to verify payment, credential or investor-data instructions through a second channel.

What proves that recovery is complete?

A restored system is not enough. Keep reconciliations to independent records, access revalidation, tests of critical fund services, provider sign-offs, board decisions, notification assessments, residual-risk acceptance and a remediation register with owners and closure evidence.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

An independent website by Raffles Corporate Services Pte Ltd. Not affiliated with or endorsed by ACRA, MAS or IRAS. General information only.