Skip to content
VARIABLE CAPITAL
COMPANIES ACT
Let’s talk

Singapore VCC insights

Set Guardrails for Generative AI in VCC Operations

Independent Singapore VCC guidance

By Variable Capital Companies Actregulatory explainer

Direct answer

Approve generative AI by use case, data class and consequence, not by product name alone. Keep confidential investor and portfolio data out of unapproved tools, assign a human owner who can test the output, and prevent a model from releasing payments, trades, valuations or investor communications by itself. Record the approved purpose, permitted inputs, validation method, provider controls, retention rule and shutdown trigger. Reassess the use case whenever the model, data source or operating process changes.

At a glance

  • Create an inventory of AI use cases with owners, data classes and prohibited actions.
  • Use human review that tests facts, calculations and context instead of accepting fluent output.
  • Treat the AI provider and connected applications as part of the service and data-control chain.
  • Retain prompts or equivalent inputs only where the approved evidence and privacy rules permit it.

Who this is for

  • VCC managers, administrators and family offices considering generative AI for research, drafting, reconciliation support or operational analysis.

Important exclusions

  • A claim that an AI tool can replace licensed judgment, board authority, legal advice or accountable control ownership.

Classify the use case before approving a tool

Start with the business action, not the novelty of the model. Describe who will use the output, what decision or record it may influence, which VCC or sub-fund is affected and what failure could follow. Drafting a meeting agenda from public material is different from summarising investor files, proposing a valuation input or generating a trade list. The VCC still operates through its appointed officers, fund manager and providers, so accountability cannot be transferred to software. Classify each use case by confidentiality, financial consequence, reversibility and the quality of human review available. A low-consequence assistant may be approved with simple controls, while a use that touches transactions, investor rights or official reporting needs stronger testing and may remain prohibited.

Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority · Personal Data Protection Commission
AI use-case classification record
QuestionLower-risk exampleHigher-risk indicator
PurposeDraft a public-source agendaInfluence a trade, NAV or investor outcome
DataPublic guidance and approved templatesInvestor, portfolio or credential information
OutputSuggestion reviewed before useInstruction passed directly to another system
Error recoveryEasy to discard and recreateHard to reverse after release
AccountabilityNamed employee owns the final textNo capable person can explain the result
Sources: Monetary Authority of Singapore · Personal Data Protection Commission · Personal Data Protection Commission

Control data before it enters the model

Define permitted inputs in operational language. A team should know whether it may use public documents, de-identified test data, internal procedures, portfolio information or investor records. Do not assume that removing a name makes a dataset safe when account identifiers, holdings, family relationships or transaction patterns can still identify a person. Confirm where the provider processes data, whether prompts are retained, who can access them, whether the data may train another model and how deletion is evidenced. Where personal data is involved, record the organisation and intermediary roles, the permitted purpose and the protection measures. Use the minimum information needed for the approved task and keep secrets, credentials and authentication material out of prompts.

Sources: Personal Data Protection Commission · Personal Data Protection Commission · Monetary Authority of Singapore

Input gate

  • The use-case record states which data classes are allowed and which are prohibited.
  • Personal or confidential fields are removed or transformed only under an approved method.
  • The user checks that pasted text, attachments and connected repositories match the permitted scope.
  • Credentials, private keys, authentication codes and unrestricted exports are never used as prompt material.
  • A secure alternative exists when the task cannot be completed without restricted information.
Sources: Personal Data Protection Commission · Personal Data Protection Commission · Monetary Authority of Singapore

Assess the provider and connected workflow

Review the full route from user to model and back. Browser extensions, plug-ins, document connectors, retrieval stores and workflow automations may receive the same information as the primary model. Record the contracting party, hosting and support arrangements, access controls, logging, retention, subcontractors, incident route and exit method. Test whether administrators can restrict connectors and disable public sharing. If the service changes material terms or model behaviour, the owner should reassess the use case before the new configuration becomes routine. Procurement approval alone is insufficient when the operating workflow later expands to new data or an automated downstream action. The approval record should describe the actual configuration that users are allowed to operate.

Sources: Personal Data Protection Commission · Monetary Authority of Singapore · Monetary Authority of Singapore

Provider approval sequence

  1. MapList the model, hosting route, connectors, repositories, administrators, support parties and downstream systems in the proposed workflow.
  2. ChallengeCompare contract statements with available settings, technical evidence, incident contacts, retention controls and practical exit capability.
  3. ConfigureDisable unnecessary sharing, training, connectors and automation before approved users receive access to the service.
  4. TestUse representative but controlled inputs to confirm access boundaries, logging, deletion and the behaviour of connected components.
  5. ApproveRecord the exact permitted configuration, accountable owner, user group, review date and suspension trigger.
Sources: Personal Data Protection Commission · Monetary Authority of Singapore · Monetary Authority of Singapore

Validate outputs with capable human review

Human review must be more than a click. The reviewer needs enough subject knowledge and source access to identify a fabricated citation, missing exception, stale instruction, inconsistent calculation or confident but unsupported conclusion. Define the tests by output type: compare extracted data to the source population, rerun calculations independently, inspect exceptions, verify citations and confirm that the conclusion fits the VCC mandate and current process. Preserve the version presented to the reviewer and the changes made before use. Do not let a model approve its own output through a second prompt that merely restates the answer. Where the evidence cannot support a reliable decision, stop the use case and return to the authoritative record or responsible professional.

Sources: Personal Data Protection Commission · Monetary Authority of Singapore · Monetary Authority of Singapore

Output decision route

  1. Low consequence and verifiedUse the output after the named reviewer confirms its facts, purpose, audience and approved data boundary.
  2. Material but independently reproducibleRequire a second control or system calculation and retain the comparison before any operational reliance.
  3. Unclear source or unexplained resultDo not use the output; investigate the source, prompt, model behaviour and missing evidence first.
  4. Prohibited action or restricted dataStop the workflow, contain any exposed information and activate the relevant incident assessment route.
Sources: Personal Data Protection Commission · Monetary Authority of Singapore · Monetary Authority of Singapore

Monitor change, incidents and continued value

Monitor whether the approved use still operates as designed. Sample completed work, review override patterns, investigate repeated corrections and ask users where they have built unofficial workarounds. Changes to the model version, provider terms, connected data, prompt template, output audience or downstream automation can alter risk even when the product name stays the same. Record incidents involving wrong recipients, confidential inputs, misleading analysis, unavailable evidence or unauthorised actions through the existing operational and data-response routes. Periodically compare time saved with the effort required to verify and correct outputs. Retire a use case when reliable review is uneconomic, the business purpose has ended, or the provider cannot meet the approved control conditions.

Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Personal Data Protection Commission

Ongoing control cycle

  1. ObserveCollect usage, exception, correction and access evidence for the approved use case without expanding data collection unnecessarily.
  2. ReviewSample outputs against authoritative sources and confirm that capable owners still perform the required validation.
  3. ChangeReassess material updates to models, terms, connectors, data sources, prompts, audiences or automated actions before adoption.
  4. RespondContain suspected disclosure or harmful output, preserve evidence and route the event through existing incident procedures.
  5. Renew or retireContinue only when the benefit, control performance and provider conditions remain acceptable to the accountable owner.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Personal Data Protection Commission

Frequently asked questions

Can staff use a public AI tool for VCC work?

Only if the use case and data are approved. Public availability does not establish suitable confidentiality, retention, access or contractual controls. Staff should use the authorised configuration, keep restricted information out of prompts and apply the required human review before any output enters a VCC record or process.

Is removing an investor name enough to de-identify data?

Not necessarily. Holdings, transaction history, family relationships, account references and rare attributes may still identify a person when combined. The owner should assess the full dataset and intended use, apply an approved transformation method and prefer synthetic or controlled test data where the task does not need real records.

May generative AI draft an investor communication?

It may assist under an approved low-risk workflow, but the responsible person should verify every fact, implication and audience restriction. The model should not release the message. Preserve the approved final version and follow the same communication authority that applies when a human prepares the first draft.

Does human review solve every AI risk?

No. Review is weak when the reviewer lacks expertise, cannot access the source evidence or is expected to approve too much output too quickly. Strong controls also restrict data, providers, connectors and automated actions, and they stop the use when a result cannot be independently supported.

When should an AI use case be reassessed?

Reassess it when the model, provider terms, hosting, connector, data source, prompt design, output audience or downstream action changes materially. Also reassess after an incident, repeated corrections or evidence that users have expanded the workflow beyond the approved purpose.

Official sources and further reading

Discuss a Singapore VCC structure

For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.

General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.

Your next step.

Let’s talk about your plans.

A fund, a family office or a trust structure. We coordinate corporate work alongside experienced law firms for legal and tax advice.

Talk to our team