Independent Singapore VCC guidance
Direct answer
A controls report is useful only after the VCC maps it to the services, systems, entities and period actually relied on. Confirm the report type and scope, identify excluded providers and applications, evaluate exceptions against the VCC's risk, and test every complementary user control assigned to the manager or VCC. Cover any period gap with specific evidence, then record residual issues and follow-up rather than filing the report unread.
At a glance
- Match the report to the contracted service and affected sub-funds.
- Read exceptions and exclusions in context, not as an automatic pass or fail.
- Test controls assigned to the VCC, manager or another provider.
- Bridge timing gaps with targeted evidence and tracked follow-up.
Who this is for
- VCC boards, managers, controllers and operations teams reviewing a fund administrator or other material provider.
Important exclusions
- An audit opinion, assurance conclusion or substitute for the VCC auditor's own assessment and procedures.
Confirm what the report is designed to show
An assurance report on service-organisation controls addresses a defined description of services and controls, and may include testing of operating effectiveness over a stated period. It is not a general certificate that every provider process is sound. Record the issuing service organisation, reporting framework, report period, auditor, covered locations, applications and stated control objectives before using it in VCC oversight.
Sources: International Auditing and Assurance Standards Board · Monetary Authority of Singapore| Question | Evidence to capture | Why it matters |
|---|---|---|
| Scope | Named entity, service, system, location and process. | The contracted administrator may use a different entity or platform. |
| Period | Start, end and report date. | The VCC may rely on services outside the tested period. |
| Assurance depth | Design coverage and any operating-effectiveness testing. | Different report forms answer different questions. |
| Dependencies | Subservice organisations and user controls. | Important controls may sit outside the report boundary. |
Related guidance: VCC investor operational due diligence checklist
Map scope to the VCC service inventory
Use the contract, responsibility matrix and current process inventory to map every relied-on activity. Typical administration work may include fund accounting, valuation support, investor records, dealing, payment preparation, expense processing and financial-reporting support. For an umbrella VCC, identify whether each sub-fund, share class, bank account and data feed sits within the reported environment. Mark activities as covered, partly covered, excluded or unclear.
Sources: Accounting and Corporate Regulatory Authority · Monetary Authority of SingaporeScope mapping checks
- The legal service provider in the contract matches the report entity.
- The VCC and all relevant sub-funds use covered systems and locations.
- Material manual processes and spreadsheets are identified rather than assumed covered.
- Interfaces with banks, custodians, transfer agents and pricing sources are mapped.
- Recent migrations, acquisitions or platform changes are assessed separately.
Related guidance: board-ready VCC outsourcing inventory
Evaluate exceptions and excluded dependencies
Read each testing exception together with the control objective, population, provider response and effect on the VCC. A small sample exception may still matter if it concerns a high-risk process; a larger administrative exception may have limited impact if a reliable downstream control catches it. For excluded subservice organisations, determine whether a separate report, contractual evidence or direct testing is needed.
Sources: International Auditing and Assurance Standards Board · Monetary Authority of SingaporeException disposition
- No relevant exposureDocument why the affected process, system, entity or period is outside the VCC reliance map.
- Compensating control existsTest the control, retain evidence and confirm it covers the same risk and period.
- Residual exposure remainsAssign remediation, interim monitoring and escalation until sufficient independent evidence supports a documented closure decision.
Related guidance: VCC administrator continuity test
Test complementary user controls
Controls reports commonly assume that the service user performs specified controls. Translate each applicable assumption into a named VCC, manager or provider owner. Examples may include approving static-data changes, reviewing NAV packs, restricting portal access, reconciling bank accounts or notifying the administrator of authorised changes. Obtain evidence for the same period and population; a policy statement without execution evidence does not prove that the assumed control operated.
Sources: International Auditing and Assurance Standards Board · Monetary Authority of SingaporeUser-control test
- AssignName the legal entity, function and responsible person for each applicable user control.
- LocateIdentify the population, frequency, evidence and escalation rule used during the report period.
- SampleInspect enough executions to understand whether the control worked as described and covered exceptions.
- CorrectRecord failures, impact, interim safeguards and the owner and due condition for remediation.
Bridge the period and close the review
If the assurance period ends before the VCC's reporting or review date, define the gap precisely. Obtain a provider statement covering material changes, incidents, control failures and remediation during the gap, then corroborate it with service reviews, reconciliations and issue logs. The final board or oversight record should state what was covered, what was not, how exceptions were treated and which residual items remain open.
Sources: Accounting and Corporate Regulatory Authority · Monetary Authority of Singapore · International Auditing and Assurance Standards BoardReview close sequence
- ReceiveLog the report version, reporting period, provider entity, auditor and applicable confidentiality restrictions.
- MapConnect report scope to contracts, systems, sub-funds and relied-on processes.
- TestAssess reported exceptions, subservice exclusions, complementary user controls and the identified period gap.
- DecideAccept scoped reliance, require additional supporting evidence or escalate the remaining residual exposure.
- TrackCarry open remediation into the provider oversight register until evidence supports closure.
Related guidance: VCC provider exit and handover plan · VCC audit confirmation workflow
Frequently asked questions
Does a clean controls report prove that the administrator is low risk?
No. It supports specific conclusions about defined services, controls and a stated period. The VCC must still assess scope, exceptions, excluded dependencies, user controls, service performance, financial condition, incidents and the relevance of the report to its actual arrangement.
What if the administrator uses an excluded subservice organisation?
Identify the outsourced activity and risk, then seek appropriate evidence such as a separate assurance report, contractual controls, certifications, service data or direct testing. Do not assume the primary report covers a provider that it expressly excludes.
Are all reported exceptions equally serious?
No. Evaluate the affected control objective, transaction population, duration, root cause, compensating controls and VCC exposure. A low-frequency exception in a critical process can matter more than several minor documentation issues.
Who should test complementary user controls?
The function that owns provider oversight should coordinate the test, but evidence may sit with the VCC, fund manager, administrator, secretary, custodian or another provider. The final record should name the actual owner and reviewer for each control.
How should a period gap be handled?
Define the gap, ask about material changes and incidents, inspect relevant service and exception evidence, and document the residual conclusion. A provider representation can support the review, but it should be corroborated where the affected risk is material.
Official sources and further reading
- Valuation Practices for Fund Management Companies (Monetary Authority of Singapore)
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Understanding VCC Features, Eligibility and Requirements (Accounting and Corporate Regulatory Authority)
- Steps to File a VCC Annual Return (Accounting and Corporate Regulatory Authority)
- ISAE 3402 Assurance Reports on Controls at a Service Organization (International Auditing and Assurance Standards Board)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.