Independent Singapore VCC guidance
Direct answer
Use a manual workaround only when the critical service cannot wait for normal recovery and the team can preserve authority, segregation, reliable inputs, evidence and reconciliation. Define exactly which transactions or records may be handled, set volume and time limits, name the approver and checker, and identify a stop trigger. Log every manual action against the source request. When systems recover, reconcile the complete population before closing the workaround or treating normal service as restored.
At a glance
- Approve a narrow service and transaction population, not a general permission to work outside normal controls.
- Retain independent checking, verified instructions and an immutable action log wherever the ordinary system is unavailable.
- Set expiry, capacity and stop triggers before the first manual action is taken.
- Recovery is incomplete until every manual action is reconciled into the authoritative records.
Who this is for
- Fund managers, administrators and VCC oversight teams considering a temporary manual route because a critical system or provider process is unavailable.
Important exclusions
- Bypassing investment authority, investor terms, legal obligations or a control that cannot be reproduced safely outside the normal process.
Define the minimum service that cannot wait
Start with the outcome that must continue, such as funding a settlement, recording a time-sensitive investor instruction or producing a controlled valuation input. Separate it from convenient but deferrable work. Record the affected VCC or sub-fund, the deadline, the consequence of waiting, the unavailable dependency and the expected recovery path. This prevents a narrow continuity measure from expanding into an undocumented parallel operating model. If delay is safer than manual processing, record the hold and the person authorised to release it.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore| Question | Evidence | Decision effect |
|---|---|---|
| What must continue? | Named service and affected transaction population | Limits the workaround to a defined outcome. |
| Why can it not wait? | Settlement, dealing, valuation or governance consequence | Shows whether urgency is real and material. |
| What is unavailable? | System, provider, data feed or approval route | Identifies the missing control and recovery owner. |
| What can be deferred? | Backlog list with owner and review point | Reduces manual volume and error exposure. |
Related guidance: critical VCC service outage map
Test whether the missing controls can be recreated
Map the normal process step by step and mark which controls disappear in the outage. A spreadsheet or email route may reproduce calculation but not entitlement, version control, duplicate detection, segregation or downstream validation. For each missing control, identify a temporary control that produces evidence a checker can review. If a material control cannot be recreated, pause the affected activity or escalate for a different continuity decision. A provider assurance that the process is safe should not replace the manager or VCC oversight assessment.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeMinimum controls before activation
- Verify the source instruction through an approved channel and confirm the correct VCC or sub-fund.
- Separate preparation, approval and release unless an authorised exception explicitly addresses the conflict.
- Use a controlled template with unique identifiers, timestamps and version history.
- Check duplicates, limits, cash, holdings and downstream dependencies before release.
- Define where evidence is retained and how the authoritative system will later be updated.
Approve a bounded operating envelope
The approval should state the permitted service, affected entities, start time, expiry, transaction and value limits, approved users, checker, data sources, communication channel, evidence location and stop triggers. Name the decision owner who may extend or terminate the route. Avoid an open-ended statement that business may continue manually. If the workaround requires a conflict, reduced review or delayed record, describe that residual risk and the additional safeguard. Commercial urgency does not transfer approval authority to a provider or portfolio team that does not own the risk.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeWorkaround approval decision
- Controls can be reproducedActivate only within the documented limits, notify the named owners and start the manual-action register immediately.
- One control is weaker but boundedEscalate the residual risk, add a safeguard and use a short expiry before reassessment.
- Authority or reliable data is missingDo not proceed until the required authority or trusted input is restored.
- Potential harm exceeds delay costHold the activity and use the formal incident and stakeholder response route.
Related guidance: VCC service-provider incident response
Operate one controlled manual-action register
Give every action a unique identifier and link it to the original request, preparer, checker, release evidence and affected records. Capture rejected and cancelled actions as well as successful ones. The register should reconcile totals by VCC and sub-fund and show capacity against the approved limit. Keep the event chronology separate from individual transaction evidence so the incident owner can see changes in scope, while operations can prove each action. Review the register during the outage, not only after recovery.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeReconcile before returning to normal service
When the system or provider returns, freeze new manual entries at a recorded time. Reconcile the manual register to requests, released actions, bank or broker records, administrator books, custody positions, valuations and reports as applicable. Upload or re-enter records only through an approved recovery method and prevent duplicate processing. Investigate every unmatched item and confirm which downstream outputs must be rerun. The decision to resume normal operations should identify remaining backlog, temporary restrictions and the person accepting any residual uncertainty.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeControlled withdrawal sequence
- Set the cutover pointRecord when manual intake stops and which pending items remain inside the workaround.
- Reconcile the populationMatch every request, action, response and authoritative record across the complete population without sampling.
- Repair downstream outputsRerun affected limits, cash, positions, valuations and reports in the correct sequence.
- Approve normal serviceDocument unresolved items, temporary restrictions, accountable ownership and the authority that approves the return to normal service.
Review the workaround as incident evidence
Close the workaround separately from the underlying outage. Assess whether the continuity design, capacity, provider escalation, access, templates and reconciliation worked as expected. Record manual errors and near misses even when financial outcomes were corrected. Convert lessons into owned actions and test the revised process before relying on it again. A workaround that is repeatedly extended should be treated as an operating-model issue, not a permanent exception disguised as continuity.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeRelated guidance: VCC administrator continuity test · operational incident and near-miss classification
Frequently asked questions
Who should approve a manual VCC workaround?
Use the authority defined for the affected service and risk. Operations may design the route, but the person accountable for the service, compliance boundary and residual risk should approve it, with escalation where normal segregation is weakened.
Can email replace a failed workflow system?
Only if approved channels, identity checks, version control, segregation, evidence and reconciliation can be reproduced. Ordinary email alone rarely provides the complete control set for a sensitive instruction.
Should the team process the full backlog manually?
Usually not. Restrict manual work to the minimum service and defer items that can wait safely. Volume limits protect both accuracy and the ability to reconcile.
When should the workaround stop?
Stop at the stated expiry, a capacity or control breach, loss of reliable data, recovery of the normal process, or any other pre-agreed trigger. An extension requires a fresh decision, not silence.
Is the outage closed when the system returns?
No. The team must reconcile all manual actions, repair downstream records, resolve unmatched items and document the controlled return to normal service. The underlying incident and any remediation may remain open after ordinary processing resumes.
Official sources and further reading
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Technology Risk Management Guidelines (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.