Independent Singapore VCC guidance
Direct answer
A VCC cyber incident needs one decision log even when several firms own the affected systems. Establish an incident lead, preserve evidence, identify the VCC, sub-fund, data and business services at risk, and separate technical containment from fund decisions about dealing, NAV, cash and communications. The fund manager must assess its own MAS obligations according to its regulatory status; the VCC board should demand verified operational facts and control any decision affecting the vehicle or investors.
At a glance
- Use one command structure and one verified fact log across providers.
- Classify the affected fund service before estimating business impact.
- Keep technical containment separate from board decisions on cash, NAV or dealing.
- Map regulatory and contractual notifications to the entity that actually owes them.
- Recover from reconciled source records, then test for silent data corruption.
Who this is for
- VCC boards and operating teams coordinating with a permissible manager, administrator, custodian, bank, secretary and technology providers after a suspected cyber event.
Important exclusions
- A universal statement of MAS, privacy, criminal-reporting or foreign notification duties; those depend on the entities, licences, data and facts involved.
Separate the legal entities from the incident
Start with an entity-and-service map. The VCC is the fund vehicle; its manager, administrator, custodian, bank, company secretary and technology vendors may each operate different systems and owe different duties. A compromised administrator portal may affect the VCC’s investor ledger without making the administrator’s incident legally identical to the manager’s. MAS guidance states that the technology-risk notice applies to holders of a capital markets services licence, among other financial institutions. Confirm the manager’s actual status and do not present that notice as automatically binding on every VCC or provider.
Sources: MAS · ACRA · Singapore Statutes Online| Affected service | Operational fact owner | VCC decision owner |
|---|---|---|
| Investor register or portal | Administrator or transfer agent | Board and manager decide dealing and communication effects |
| Portfolio or order system | Manager and trading provider | Manager controls investment response; board oversees vehicle impact |
| Bank or custody access | Bank, custodian and authorised users | Board and manager control cash or asset restrictions |
| Corporate records or email | Secretary and relevant technology provider | Board controls authority, resolutions and record recovery |
| Shared identity service | Contracted technology owner | Every affected entity assesses its own access and notification duties |
Related guidance: VCC directors, managers and provider roles
Open one command log
Nominate an incident lead, technical lead, legal and compliance lead, fund-operations lead and board liaison. Create a protected log that records time, source, verified fact, hypothesis, decision, owner and next check. Providers may keep their own forensic records, but the VCC needs a consolidated view of the consequences for each sub-fund and critical service. Restrict the group to people who need access; uncontrolled forwarding can compromise evidence, confidentiality and coordinated communications. Record uncertainty explicitly instead of converting assumptions into status updates.
Sources: MAS · MAS- Authenticate the alert through a second channel before following any instruction contained in it.
- Preserve logs, messages, access records and affected files without asking ordinary users to investigate destructively.
- Name the VCC, sub-fund, systems, accounts, data sets and providers potentially affected.
- Freeze unverified changes to bank mandates, payment templates, investor standing data and privileged access.
- Record every decision to continue, restrict or suspend a fund service with the facts and authority relied on.
- Keep external communications under one approval route while each entity assesses its own obligations.
Related guidance: build a VCC board agenda and evidence pack
Route by critical fund service
Impact is not measured only by whether a server is online. Ask whether the team can prove investor ownership, calculate NAV, value assets, accept or reject dealing, move cash, settle trades, produce board authority and communicate through trusted channels. A system may appear available while its data is corrupted or its credentials are compromised. MAS business-continuity guidance emphasises identifying critical business services and recovery dependencies. Translate that approach into fund-specific recovery tolerances approved by the responsible entity, without inventing one generic deadline for every VCC.
Sources: MAS · MAS- Can the source record be trusted?If integrity is uncertain, stop dependent processing and compare against an independent, time-stamped source before making fund decisions.
- Can cash or assets move safely?If credentials, mandates or instructions may be compromised, restrict movement and confirm authority through established alternative channels.
- Can NAV and dealing be supported?If holdings, prices, investor data or approvals are incomplete, escalate the affected dealing and valuation decision under the fund documents.
- Can investors be contacted reliably?If email or portal integrity is uncertain, use a pre-approved alternative and warn recipients how to authenticate future instructions.
- Is the affected entity regulated or contractually bound?Have that entity assess its reporting and notification obligations using the facts in the shared command log.
Control fund decisions during containment
Technical responders may isolate systems, reset credentials or restore backups; they should not decide whether the VCC accepts subscriptions, pays redemptions, strikes NAV or changes a bank mandate. Route those decisions to the authority in the constitution, offering documents, board delegations and provider agreements. Use the smallest safe restriction: one user, account, sub-fund, data feed or dealing function where the evidence supports it. A platform-wide shutdown may be justified, but it should be a conscious fund decision rather than an accidental consequence of a vendor action.
Sources: MAS · Singapore Statutes Online · ACRA- TriageAuthenticate the event, protect people and evidence, map affected entities and stop obviously unsafe access or instructions.
- ContainIsolate compromised paths while preserving alternative access for verified critical fund services where that remains safe.
- DecideEscalate cash, dealing, NAV, disclosure and communication choices to the authority named in the governing documents.
- RecoverRestore from trusted sources, rotate access, reconcile records and require independent checks before reopening each service.
- LearnComplete root-cause, control, contract, provider and board-action reviews, then track remediation to evidenced closure.
Related guidance: correct a VCC NAV error without losing control
Recover from independent records
Recovery is a reconciliation exercise, not merely a backup restoration. Establish the last trusted point for investor holdings, portfolio positions, cash, pending trades, subscriptions, redemptions, fees, corporate approvals and access rights. Compare restored data to independent bank, custody, broker, administrator and signed corporate records. Sample high-risk changes made near the incident, including payee amendments, user creation, investor bank details and manual prices. Reopen each service only when its owner signs off the evidence and any residual manual control.
Sources: MAS · MAS| Record | Independent comparator | Release test |
|---|---|---|
| Investor ledger | Signed forms, prior close and bank receipts | Holdings and pending dealing reconcile |
| Portfolio book | Custody, broker and trade confirmations | Positions, cash and unsettled trades reconcile |
| NAV inputs | Independent prices and approved valuation records | No unexplained source or override remains |
| Payment setup | Bank records and authorised mandates | Payees, approvers and limits are revalidated |
| Corporate authority | Signed minutes, resolutions and statutory records | Current delegation and signatory data are restored |
Related guidance: VCC compliance checklist
Frequently asked questions
Is the VCC itself subject to the MAS technology-risk notice?
Do not assume that result from the VCC label alone. MAS identifies the financial institutions within scope, including holders of a capital markets services licence. Assess the manager and every affected entity by its own regulatory status and seek advice on the facts.
Who should lead a multi-provider incident?
Name one coordinator for the VCC impact while each provider retains technical responsibility for its systems. The coordinator should maintain the verified fact and decision log, but should not override a provider’s forensic work or an entity’s own legal and regulatory duties.
Should dealing stop whenever a provider reports an incident?
Not automatically. Determine whether reliable investor, valuation, cash, authority and communication controls remain available, then use the decision route in the fund documents. Any continuation or restriction should be based on verified impact, not the incident label alone.
Can the team communicate through the affected email system?
Only after the security owner confirms it is safe for the intended purpose. Use authenticated alternative channels from the continuity plan where integrity is uncertain, and tell recipients how to verify payment, credential or investor-data instructions through a second channel.
What proves that recovery is complete?
A restored system is not enough. Keep reconciliations to independent records, access revalidation, tests of critical fund services, provider sign-offs, board decisions, notification assessments, residual-risk acceptance and a remediation register with owners and closure evidence.
Official sources and further reading
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.