Independent Singapore VCC guidance
Direct answer
Test an algorithmic order workflow as a controlled chain from investment decision to venue acknowledgement and completed-book record. Map mandate rules into pre-trade checks, challenge the algorithm with normal and extreme scenarios, prove that limits and emergency suspension work, and reconcile every rejected, cancelled and partially filled order. No material change should reach production without an owner, independent test evidence, approval and rollback plan. After release, monitor behaviour against expected ranges and investigate exceptions before increasing scope.
At a glance
- Map each coded control to a mandate, risk limit, venue rule or approved operating condition.
- Test failure paths, stale data and partial execution instead of demonstrating only a successful order.
- Give emergency suspension to reachable people who can identify the affected VCC and strategy.
- Reconcile algorithm records to order, broker, venue and accounting evidence after release.
Who this is for
- A fund manager using algorithms or automated routing to execute orders for a Singapore VCC or sub-fund.
Important exclusions
- A statement that a generic vendor certification proves the VCC mandate is safe for every strategy and venue.
Define the algorithm and mandate boundary
Document what the algorithm actually decides. It may schedule an approved parent order, choose venues, vary participation, select price parameters or create child orders. Separate those execution choices from portfolio construction and investment approval. Record the VCC, sub-funds, instruments, markets, accounts, brokers, trading windows and data feeds within scope. Link each coded restriction to the current mandate and risk framework so testers can see whether a failure would create an unauthorised investment, excessive exposure, poor execution or an operational break. If the same component serves several sub-funds, identify which configuration and limits belong to each one. A vendor description cannot replace the manager-specific boundary.
Sources: Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority · Monetary Authority of Singapore| Control area | Question | Evidence |
|---|---|---|
| Mandate | Which instruments, markets and accounts are allowed? | Rule map tied to approved mandate records |
| Order size | Which exposure and participation limits apply? | Configured thresholds and test cases |
| Market data | Which prices and timestamps drive decisions? | Feed inventory and stale-data response |
| Routing | Which brokers and venues are permitted? | Approved destination list and rejection proof |
| Ownership | Who may release, change or stop the algorithm? | Named roles and access evidence |
Related guidance: new investment instrument approval
Build a representative pre-release test pack
Use scenarios that reflect the strategy rather than a single happy path. Include thin liquidity, stale or missing prices, delayed acknowledgements, rejected destinations, partial fills, duplicate messages, session interruption and a rapid market move. Test the exact production configuration in a controlled environment where possible, and explain any difference between test and production. Record the input, expected behaviour, actual result, defect, owner and retest. Confirm that the algorithm does not silently broaden an order after a rejection or continue using stale data. Independent challenge should focus on assumptions and boundary conditions, while business owners confirm that the result remains faithful to the investment decision and mandate.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeMinimum test population
- A valid order completes through the intended broker and is recorded consistently across order and accounting records.
- An out-of-mandate instrument, account or destination is rejected with a usable reason and audit record.
- Stale, missing or implausible market data triggers the approved stop, fallback or human-review route.
- Partial fills, cancellations and duplicate acknowledgements do not create unintended residual orders.
- A system or network interruption leaves a known order state that can be reconciled before resumption.
- Emergency suspension prevents new activity and supports orderly treatment of orders already in flight.
Prove limits, overrides and emergency suspension
List hard limits, warning limits and discretionary parameters separately. A warning that users routinely ignore is not equivalent to a control that prevents prohibited activity. Define who may adjust each parameter, how a temporary change is approved, how long it remains valid and how the original setting is restored. Test emergency suspension from the locations and roles expected to use it, including when a primary operator is unavailable. The stop route should identify which strategy, account or component is affected so that an incident in one sub-fund does not cause uncontrolled action elsewhere. Preserve the command, acknowledgement, open-order status and decision on whether to cancel, amend or monitor orders already sent.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeResponse to an algorithmic control alert
- Known valid warningConfirm the order and current market condition, record the rationale and use only an authorised override route.
- Unexpected rejectionPause repeat attempts, compare configuration and mandate data, then resolve the underlying rule or instruction mismatch.
- Unexplained behaviourSuspend the affected component, identify every open order and preserve logs before attempting a restart.
- Wider control failureActivate incident governance, protect unaffected strategies and require reconciled evidence before any controlled resumption.
Control releases and parameter changes
Treat code, model, rule, data-feed and parameter changes according to their possible effect, not the label used by the supplier. A seemingly small change to rounding, time zones, destination priority or stale-price tolerance can alter execution. The release record should state the reason, affected strategies, test scope, unresolved limitations, approvers, deployment window and rollback condition. Separate development, testing and production access where practical, and prevent the person making a material change from being the only person to approve its evidence. After deployment, compare the live configuration with the approved package and run a bounded production check. If results diverge, restore the last known configuration or suspend the workflow.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeRelease gate
- AssessDescribe the operational and investment effect across every affected VCC account, strategy, broker, venue and data source.
- TestExecute normal, boundary and failure cases with expected results agreed before the evidence is reviewed.
- ApproveObtain accountable business and technology acceptance while recording limitations and the precise production package.
- DeployRelease within the controlled window, verify configuration and keep an immediately usable rollback or suspension route.
- ObserveReview initial orders, rejects, fills, latency and exceptions before expanding volume or strategy coverage.
Related guidance: investment-rule testing after a system release
Reconcile live orders and investigate deviations
Daily oversight should connect investment intent, parent order, child orders, broker and venue responses, executions, cancellations and the final books. Investigate unexplained differences in price, quantity, destination, participation, timing, reject rate or manual intervention. Compare behaviour with the assumptions established at approval and distinguish market conditions from model, data, configuration or user causes. Record whether a deviation affected best-execution evidence, a mandate rule, valuation, cash or investor reporting. Do not close a problem merely because the final position is correct; repeated cancels, duplicate attempts or stale data can reveal a control weakness before a financial loss occurs. Use findings to update scenarios and limits, then retest the failed path.
Sources: Monetary Authority of Singapore · Monetary Authority of SingaporeLive evidence review
- Parent and child order quantities reconcile to executions, cancellations and remaining open interest.
- Broker and venue destinations match the approved routing population for the affected strategy.
- Manual interventions and overrides identify the user, reason, authority and resulting order state.
- Rejects and stale-data events are reviewed for repeated patterns instead of cleared individually.
- Control changes arising from an incident are independently tested before the affected scope resumes.
Related guidance: best-execution evidence for a VCC trade · VCC trading-error classification and correction
Frequently asked questions
Is an execution algorithm the same as an investment model?
No. An execution algorithm may work an already approved order, while an investment model may decide what or how much to buy or sell. The control file should state where the investment decision ends and execution discretion begins, because the risks, approvals and testing differ.
Can a broker test the algorithm for the manager?
A broker or vendor can provide useful technical evidence, but the manager still needs to test its own mandate rules, accounts, limits, data, users and reconciliation. Supplier testing does not prove that the configured workflow is suitable for every VCC strategy or operating condition.
What should an emergency kill control do?
It should stop the approved scope of new automated activity, make open-order status visible and support an authorised decision on orders already sent. The control should be reachable, tested and specific enough to protect unaffected mandates from an unnecessarily broad or ambiguous shutdown.
Do parameter changes need the same testing as code?
Use a risk-based approach. A parameter can materially change order size, timing, routing or stale-data behaviour even when code is unchanged. Assess the effect, test the boundary, approve the precise setting and verify it after deployment instead of assuming configuration is harmless.
When may trading resume after unexplained behaviour?
Resume only after the affected orders are known, the cause or safe containment is established, the configuration is verified and the accountable owner accepts the evidence. A partial or restricted restart may be appropriate, but it should have explicit limits, monitoring and a new suspension trigger.
Official sources and further reading
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Technology Risk Management Guidelines (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
- Understanding VCC Features, Eligibility and Requirements (Accounting and Corporate Regulatory Authority)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.