Independent Singapore VCC guidance
Direct answer
Test the compliance function by following evidence, not by counting policies. Confirm that it has clear authority, suitable competence, direct access to decision-makers and the information needed across the VCC service chain. Select risk-based samples from investment, dealing, investor, provider and reporting activity; compare what the monitoring plan promised with what occurred; inspect challenge and escalation records; and retest completed remediation. Report unresolved limits, conflicts and resource gaps plainly to the relevant manager and VCC governance bodies.
At a glance
- Independence requires practical access and escalation, not only an organisation chart.
- Testing should cover provider-held evidence as well as records inside the manager.
- A finding is not closed until the changed control has been retested.
- The board report should distinguish assurance, limitation, open risk and management assertion.
Who this is for
- Boards and senior managers reviewing an internal, shared or outsourced compliance function supporting one or more VCC mandates.
Important exclusions
- A certification that a manager is compliant, an audit opinion, or a replacement for legal advice, regulatory reporting or independent AML assurance.
Start with mandate, authority and conflicts
Document what the compliance function is expected to cover for the manager and each VCC mandate. Identify its reporting line, decision rights, escalation route, access to committees and authority to obtain records or pause an activity. Review commercial, personal and reporting conflicts that could weaken challenge. An outsourced title or direct line to a board is not enough if the function receives filtered information, lacks time for testing or depends on the business owner to decide whether a finding reaches governance.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeAuthority and independence checks
- Map the formal reporting line and the practical route for urgent escalation.
- Identify who sets compliance priorities, approves resources and assesses performance.
- Test whether the function can obtain unedited manager and provider records directly.
- Review conflicts created by operational duties, revenue targets or prior involvement.
- Confirm how disagreement with senior management is preserved and reported.
Test coverage against the real mandate
Compare the compliance risk assessment and monitoring plan with the VCC activities actually performed. Include investment restrictions, order handling, conflicts, personal conduct, investor onboarding, communications, marketing, outsourcing, regulatory records and changes to products or providers. Trace new activities and incidents into the plan. A schedule that repeats last year work can look complete while missing the strategy, systems or service-chain changes that now create the greatest exposure.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Input | Test | Failure signal |
|---|---|---|
| Mandate and offering documents | Map obligations and restrictions to a named control and test | Important terms are covered only by a general policy. |
| Business and system change | Trace recent launches, instruments and releases into monitoring | The plan did not change after the operating model changed. |
| Incidents and complaints | Check whether patterns altered scope or sampling | Known issues are reported but do not influence assurance work. |
| Provider dependencies | Locate evidence held by administrators, brokers and custodians | The function accepts provider assurance without access or testing. |
| Prior findings | Verify remediation and recurrence monitoring | Items are closed on management confirmation alone. |
Related guidance: VCC compliance monitoring plan
Select samples that can disprove comfort
Use a mixture of ordinary transactions, exceptions, overrides, manual repairs, high-risk activity and items close to a limit. Sampling should be reproducible: record the population, selection rule, source, period and exclusions. Ask whether another reviewer could obtain the same population. For provider processes, reconcile manager records with the provider source rather than accepting a prepared summary. A test that cannot find an exception because it excludes rejected or amended items is measuring cleanliness of presentation, not effectiveness of control.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeEvidence-quality checks
- Reconcile the sample population to a controlled system or provider extract.
- Include cancelled, rejected, overridden and manually repaired items where relevant.
- Retain the selection logic so the test can be repeated independently.
- Inspect original evidence rather than screenshots selected by the process owner.
- Record unavailable data and assess the assurance limitation explicitly.
Related guidance: independent assurance for VCC AML controls
Inspect challenge and escalation in practice
Choose several issues and trace the compliance response from detection to challenge, decision and closure. Look for the original question, the evidence requested, the business response, unresolved disagreement, escalation timing and governance outcome. Strong challenge is proportionate and specific; it does not require a confrontational tone. Weak challenge accepts a narrative without testing it, changes a rating to avoid escalation or records a meeting without the decision. Interview process owners to confirm whether the written route matches practice.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Stage | Useful evidence | Question for the reviewer |
|---|---|---|
| Detection | Test result, alert or referral | Was the issue found through a designed control or by chance? |
| Analysis | Source records and alternative explanations | Did compliance test the business account independently? |
| Escalation | Decision record and recipients | Did the issue reach someone with authority to act? |
| Resolution | Action, owner and changed control | Was the cause addressed rather than the visible symptom? |
| Closure | Retest and residual risk decision | Is there evidence that the repair now works? |
Separate finding closure from action completion
An action can be completed without resolving the finding. A procedure may be updated, training delivered or a system field added, while the risky behaviour continues. For each material issue, record the causal weakness, intended control outcome, action, accountable owner, target evidence and retest. If management accepts residual risk, document that decision separately from compliance assurance. Compliance should not close its own finding merely because the same function drafted the remediation or received a completion email.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeFinding closure sequence
- Define the causeState the control weakness and affected population without hiding uncertainty behind a broad label.
- Approve remediationLink each action to the intended control outcome and assign accountable ownership.
- ImplementPreserve clear evidence of the actual change across systems, people, data routes and providers.
- RetestUse fresh transactions and negative cases to determine whether the weakness remains.
- Report residual riskKeep remaining exposure visible to the person authorised to accept or reject it.
Give the board a decision-ready conclusion
Summarise what was tested, what evidence was unavailable, which controls were effective, which findings remain open and what judgement the board or senior management must make. Distinguish compliance conclusions from management assertions and provider statements. Show trends in recurring causes and overdue remediation, but preserve the cases behind any dashboard. The report should also identify competence, capacity, technology or access constraints affecting the function itself, with a practical response and owner.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: MAS supervisory-review readiness checklist · VCC manager competency coverage test
Frequently asked questions
Does an outsourced compliance function count as independent?
Outsourcing can support independence, but the label does not settle the question. Review practical authority, conflicts, information access, resources, escalation and whether the provider can challenge the people who appoint and pay it without filtering findings.
Should the VCC board test the manager compliance function directly?
The exact oversight route depends on the governance model, but VCC directors need decision-relevant assurance about risks affecting the vehicle. They should understand the scope, limitations, significant findings and unresolved dependencies rather than receiving only a general comfort statement.
How much sampling is enough for an effectiveness review?
There is no useful universal number. Define the relevant population and choose a risk-based mix that can expose failure, including exceptions and overrides. Record the selection logic, limitations and reason the sample supports the stated conclusion.
Can training completion prove the compliance programme works?
Training records prove participation, not behaviour or control performance. Combine them with transaction testing, staff understanding, escalation evidence, observed challenge and issue recurrence to assess whether the intended conduct is operating in practice.
Who should close a compliance finding?
The action owner should evidence implementation, while an appropriately independent reviewer should retest the changed control. Any remaining risk should be accepted only by the authorised governance owner, not hidden inside the administrative act of closing a task.
Official sources and further reading
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Guideline SFA 04-G05 on Licensing and Conduct of Business for Fund Managers (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
- Guidelines on Fit and Proper Criteria (Monetary Authority of Singapore)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.