Independent Singapore VCC guidance
Direct answer
Tune transaction monitoring for a VCC by starting with the vehicle’s actual investor, jurisdiction, payment and dealing risks, then mapping each risk to reliable data and a defined alert scenario. Test whether the scenario finds known examples, routes complete evidence to an investigator and produces consistent dispositions. Track missed events, overrides and unproductive alerts. Recalibrate through controlled changes with before-and-after testing, while the VCC retains enough oversight to challenge work performed by its eligible financial institution.
At a glance
- Start with risk and behaviour, not a library of generic thresholds.
- Prove that every scenario has complete, timely and correctly scoped data.
- Review alert dispositions for consistency, evidence and escalation quality.
- Treat false negatives and control bypasses as more important than a low alert count.
- Recalibrate through versioned testing and accountable approval.
Who this is for
- VCC investor and transaction monitoring performed internally or through an eligible financial institution, administrator or other authorised service provider.
Important exclusions
- A list of secret monitoring thresholds, a conclusion that a named transaction is suspicious, or instructions to evade financial-crime controls.
Map risks to observable VCC activity
Begin with the VCC’s current risk assessment and operating model. Identify how value enters, moves within and leaves the vehicle: subscriptions, redemptions, distributions, transfers, capital calls, drawdowns, asset transfers, fees, refunds and payments involving connected parties. Map the expected investor population, beneficial owners, source-of-funds profile, jurisdictions, currencies, bank accounts, sub-funds, share classes and intermediaries. Then describe behaviours that would depart from that profile. A generic large-payment alert is less useful than a scenario tied to an unexpected payer, rapid subscription and redemption, unexplained third-party destination or activity inconsistent with the approved investor purpose.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance| Risk question | Data needed | Example behaviour | Owner |
|---|---|---|---|
| Who funded the investment? | Investor, payer, account and beneficial-owner identifiers | Money arrives from an unapproved third party | Onboarding and AML operations |
| Does activity fit the purpose? | Approved profile, expected size, frequency and route | Rapid entry and exit without a credible investment reason | AML investigator |
| Is one pool obscuring another? | VCC, sub-fund, class and transaction ownership | Funds move through a shared account without a clear owner | Fund operations |
| Has risk information changed? | Screening, ownership, jurisdiction and adverse-information updates | Activity continues after a material risk change | Compliance |
| Are exceptions recurring? | Alert, override, outcome and root-cause history | Repeated manual closure for the same data gap | VCC oversight owner |
Related guidance: suspicious transaction escalation workflow
Prove the data perimeter before tuning thresholds
A scenario cannot compensate for missing data. Reconcile the monitoring feed to the administrator, registrar, bank, custody and accounting populations. Confirm that attempted and rejected transactions are available where relevant, not only settled cash. Test identifiers across legal investor, beneficial owner, payer, beneficiary, authorised person, VCC and sub-fund. Review time zones, currency conversion, duplicate records, reversals, backdated events and manual journals. Where the eligible financial institution performs monitoring, the VCC should understand the data it receives, the activity excluded and the path for obtaining case evidence. Record every known gap and the interim control instead of silently lowering expectations.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority- Reconcile source-system totals and identifiers to the population entering the monitoring engine.
- Test subscriptions, redemptions, distributions, transfers, refunds, fees and manual adjustments separately.
- Confirm that VCC, sub-fund and class ownership survives every transformation and aggregation step.
- Identify delayed feeds, excluded channels, failed interfaces and users able to change records outside the normal workflow.
- Document the interim review that covers each gap and the evidence required to retire that workaround.
Related guidance: politically exposed investor review
Write scenarios that investigators can explain
Each scenario needs a risk statement, population, logic, data fields, exclusions, alert information, review steps and escalation criteria. Use thresholds only where they follow the risk and can be explained. Combine amount with behaviour, relationship and timing where that improves discrimination. For example, an unexpected third-party payer may matter even when the amount is modest, while a large planned capital call from a verified account may be ordinary. The alert should show the investigator what triggered, the relevant investor profile, related transactions, account history and unresolved onboarding conditions. Avoid opaque risk scores that cannot be traced to facts.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Ministry of Finance- State the riskDescribe the misuse or inconsistency the scenario is intended to detect in the VCC’s actual operating model.
- Define the populationName the transaction types, investors, accounts, sub-funds, periods and channels included or excluded.
- Specify the logicRecord fields, relationships, aggregation windows, conditions and the reason any threshold supports the risk.
- Design the case viewGive the investigator the trigger, profile, related activity, source records and prior case history needed for judgement.
- Set escalation criteriaSeparate requests for more information, monitoring concern, transaction control and suspicious-transaction decision routes.
Related guidance: sanctions-screening alert response
Test detection and disposition quality
Test whether known or constructed examples trigger as intended, whether ordinary examples remain manageable and whether changes in identifiers or routes create bypasses. Include edge cases from prior incidents, complaints, provider failures and investigator feedback. Then sample dispositions across investigators and outcomes. A good closure explains the activity, compares it with the approved profile, cites evidence, records unresolved facts and states why escalation is or is not needed. Labels such as expected, false positive or business as usual are conclusions, not reasoning. Track reopened cases, repeated requests and alerts closed without complete records as quality indicators.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · RT Compliance- Alert is explained and consistentClose with the supporting profile, transaction evidence and a clear reason that no further escalation is needed.
- Evidence is incompleteKeep the case open or apply a controlled restriction while the assigned owner obtains the missing information.
- Activity remains unusualEscalate through the authorised AML route without treating the alert engine as the final reporting decision.
- Scenario or data failedOpen a control issue, identify potentially missed activity and apply retrospective or interim review where proportionate.
Related guidance: investor onboarding evidence map
Recalibrate through controlled change
Recalibration should respond to risk changes, new products, investor populations, jurisdictions, payment routes, confirmed cases, data changes and alert-quality evidence. Preserve the old logic, proposed change, rationale, test population, expected impact, actual result, approval and effective time. Review whether a reduction in alerts reflects better precision or lost coverage. Use parallel testing where a material change could hide activity. After release, compare volumes, investigator outcomes, escalation patterns and known-event detection with the prior version. If a provider changes logic, the VCC should receive an intelligible change record and enough evidence to challenge the effect on its monitoring perimeter.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of Singapore- ProposeState the risk or quality problem and the evidence supporting the change before editing live logic.
- TestRun known, ordinary and edge-case examples against old and proposed versions using reconciled data.
- ApproveRecord coverage trade-offs, unresolved limitations, interim controls and the accountable release decision.
- ObserveCompare live volumes, case outcomes, escalations and missed-event indicators after the effective time.
- RetireRemove temporary workarounds only when the repaired scenario and data path have produced reliable evidence.
Related guidance: VCC compliance checklist
Frequently asked questions
Does the VCC need its own transaction monitoring system?
Not necessarily. Monitoring work may be performed through the eligible financial institution or another authorised service arrangement, depending on the operating model. The VCC still needs enough oversight to understand the covered activity, data gaps, material scenarios, escalation route, provider evidence and unresolved issues rather than assuming that a system-generated report proves effective monitoring.
What is a useful transaction monitoring alert?
A useful alert identifies behaviour connected to a stated risk, shows the investigator the relevant profile and transaction context, and supports a consistent decision. High volume is not evidence of quality. The alert should be explainable, based on reliable data, capable of finding known examples and linked to a clear route for information requests and escalation.
Should thresholds be identical for every VCC investor?
Uniform thresholds may ignore meaningful differences in investor purpose, expected activity, jurisdiction, payment route and risk. A risk-based design can use different segments where the distinctions are justified, governed and tested. Segmentation should never become a hidden method for excluding higher-risk activity or avoiding investigation of transactions that remain inconsistent with the approved profile.
How should false positives be handled?
Investigate and record them consistently, then analyse why they occur. Repeated unproductive alerts may justify better data, segmentation or logic, but closure volume alone does not support weakening the control. Test proposed changes against known risky and ordinary examples, examine lost coverage, approve the change and monitor results after release.
When should monitoring be recalibrated?
Recalibrate when risk, investor populations, products, payment channels, jurisdictions, data sources or operating processes change, and when cases or testing reveal missed activity or poor discrimination. Keep a versioned change record, before-and-after test evidence, approval, effective time and post-release review so the VCC can explain the control in force for any period.
Official sources and further reading
- Notice VCC-N01 on Prevention of Money Laundering and Countering the Financing of Terrorism for VCCs (Monetary Authority of Singapore)
- Guidelines to Notice VCC-N01 (Monetary Authority of Singapore)
- Money Laundering and Terrorism Financing Risk Assessment of Legal Persons (Ministry of Finance)
- Understanding VCC Features, Eligibility and Requirements (Accounting and Corporate Regulatory Authority)
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- AML/CFT Compliance Checklist for Singapore Fund Managers (RT Compliance)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.



