Independent Singapore VCC guidance
Direct answer
A small VCC manager should separate the powers that create, approve, execute, record and review a material action. Where different employees cannot perform every stage, reduce the same-person authority, add independent evidence, use a suitably mandated provider or director for challenge, and monitor exceptions more closely. Do not treat a second click by an uninformed person as separation. Build the model around actual access and decisions across each VCC and sub-fund, then record temporary combinations, expiry dates and the person accountable for residual risk.
At a glance
- Map incompatible powers by process and system rather than by job title alone.
- Prioritise separation for investment, cash, valuation, investor and access decisions with high consequence.
- Use compensating review that can detect and challenge the action independently.
- Time-limit emergency role combinations and verify that access is removed afterward.
- Give the board an honest view of unresolved concentration and recurring overrides.
Who this is for
- Small licensed managers, family-office teams and VCC operating models with limited internal headcount and significant provider reliance.
Important exclusions
- A claim that outsourcing transfers accountability or that a generic dual-approval setting proves effective challenge.
Map powers instead of relying on titles
Begin with the complete action chain for investment decisions, orders, allocations, valuations, payments, investor records, reporting, access and compliance. For each stage, record who can initiate, change, approve, execute, post, reconcile, investigate and close. Include service-provider and portal permissions, shared credentials, emergency accounts and informal instructions that bypass the named process. A person may hold several job titles but still exercise one concentrated set of powers. Conversely, an administrator may process an action without providing independent challenge. Map the VCC and sub-fund scope of each right so authority over one mandate is not assumed to extend to another. The result should show practical capability, not merely the organisation chart or policy wording.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory Authority| Process | Powers to separate | Evidence of challenge |
|---|---|---|
| Investment and orders | Decision, order release and exception approval | Approved mandate, order trail and independent exception review |
| Cash and payments | Instruction creation, beneficiary change and release | Verified instruction, dual authority and bank readback |
| Valuation and NAV | Input selection, override and final acceptance | Source comparison, override rationale and reviewer sign-off |
| Investor records | Data change, dealing acceptance and distribution | Authenticated request, register reconciliation and release control |
| Technology access | Privilege grant, use and recertification | Ticket, log review and independent removal evidence |
Rank conflicts by consequence and concealment
Not every combination has the same risk. Prioritise duties where one person can create an exposure and also suppress, revalue or approve the evidence. Consider the financial and investor consequence, ease of reversal, ability to conceal, frequency, access level and quality of independent records. A portfolio manager preparing research may be expected, but that person should not be the only reviewer of a mandate exception or trading error involving their decision. A finance lead may prepare a payment, but beneficiary changes and release deserve stronger separation. Classify each combination as acceptable, acceptable with controls, temporary, or prohibited under the chosen model. Record why the design fits the actual size, strategy, provider chain and complexity.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeDuty-combination decision
- Low consequence and transparentAllow the combination when independent records expose errors promptly and the action cannot create a material irreversible outcome.
- Material but independently reviewableAdd informed approval, source comparison, access limits and post-action monitoring before accepting the combined role.
- Self-approval or concealment riskSeparate the duty through another qualified employee, director or provider with real authority and information.
- Emergency temporary combinationSet a narrow scope, explicit expiry, heightened monitoring and an independent retrospective review after normal coverage returns.
- No credible compensating controlDo not proceed until the authority, staffing, provider role or process has been redesigned safely.
Related guidance: VCC team remuneration conflict review
Build compensating review that can detect failure
A compensating control should see enough evidence, operate at the right time and have authority to stop or correct the action. A second approver who receives only a summary prepared by the first person may add ceremony without challenge. Give the reviewer the original instruction, mandate, source data, system record and exception history relevant to the decision. Use independent provider records where they improve detection, but confirm that the provider is not relying on the same person or data. Tailor review timing to consequence: some actions need approval before release, while others can be sampled after completion if they are reversible and independently visible. Document what the reviewer tested, not just that an approval button was pressed.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeCompensating-control quality test
- The reviewer is independent of the action and any personal benefit from its outcome.
- The reviewer receives source evidence rather than only a conclusion prepared by the maker.
- The review occurs before an irreversible result when the consequence demands it.
- The reviewer can reject, pause, escalate or require correction and is expected to use that authority.
- Exceptions, overrides and repeated combinations are visible in management and board reporting.
- The evidence identifies what was checked, which difference was found and how the final decision changed.
Related guidance: VCC manager compliance-function effectiveness test
Use providers without outsourcing accountability
Providers can perform calculations, maintain records, process instructions or supply independent data, but their role needs defined scope, information and escalation rights. Decide whether the provider is a processor, checker, control owner or source of evidence for each task. Avoid circular reliance in which the manager assumes the administrator checks the manager while the administrator assumes the manager approved the source. Confirm who reviews provider exceptions, changes static data, accepts NAV, releases communications and closes incidents. In a family-office setting, personal relationships or shared ownership should not replace documented authority. Give the VCC board enough information to understand the manager-provider boundary and any concentration where the same provider prepares and validates a material output.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory AuthorityProvider role design
- DefineState the provider action, VCC scope, source information, authority, prohibited decisions and escalation points in operational terms.
- ConnectMap which internal owner supplies instructions, challenges output, approves exceptions and receives evidence of completion or failure.
- TestSample a normal item and an exception to confirm that both organisations follow the intended separation and escalation route.
- ObserveReview ageing, overrides, disagreements, late evidence and repeat defects instead of measuring only timely task completion.
- ChangeReassess the control whenever systems, staff, ownership, service scope or sub-fund complexity alters the practical authority map.
Control absence, emergency access and overrides
Small teams need planned coverage rather than improvised credential sharing. Identify critical roles, open decisions, provider contacts and accounts before an absence. Pre-approve bounded alternates who have suitable competence and only the access needed for the coverage task. If emergency access combines duties, record the reason, scope, start, expiry and independent review. Monitor actions performed under the temporary role and verify removal across internal and external systems after handback. Do not leave dormant broad rights for hypothetical convenience. Repeated use of emergency combinations is evidence that the operating model may be understaffed or poorly sequenced. Bring the pattern, not only individual approvals, to accountable management and the VCC board.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Monetary Authority of SingaporeTemporary combination lifecycle
- PrepareIdentify coverage tasks, competent alternates, restricted permissions, open work and provider recognition before the primary person becomes unavailable.
- ActivateApprove the exact combined duties, VCC scope, access, monitoring, start time and expiry through a traceable route.
- OperateReview transactions, changes, overrides and exceptions performed under temporary authority while the exposure remains active.
- Hand backTransfer open items, reconcile actions and obtain acceptance from the returning or permanent role owner.
- RevokeRemove temporary rights across every provider and system, then independently verify that no unexplained authority remains.
Related guidance: temporary trading authority for a VCC mandate
Report the residual concentration honestly
Maintain a concise register of combined duties, rationale, compensating control, owner, evidence, review date and closure condition. Distinguish structural concentration from a temporary absence or incident. Report breaches of the intended design, approvals given after the event, repeated override use and controls that depend on one person’s memory. The board does not need a list of every routine click, but it should understand where one person can affect investments, cash, valuation, investors or evidence without timely detection. Test a sample from source action to independent review. If a control exists only in policy, reclassify the exposure and assign a repair. Renew acceptance only after reconsidering alternatives such as sequencing, system restriction, provider scope or added capability.
Sources: Monetary Authority of Singapore · Monetary Authority of Singapore · Accounting and Corporate Regulatory AuthorityRelated guidance: VCC investment committee dissent records
Frequently asked questions
Does every VCC task need two employees?
No. Design separation according to consequence, reversibility, access and available independent evidence. Some low-risk tasks can be combined, while investment, payment, valuation, investor and privileged-access actions often need stronger challenge. Record why the chosen control is proportionate to the actual operating model.
Can a service provider act as the checker?
Yes, if the provider has suitable information, authority, independence and a clearly defined control role. Processing an instruction is not automatically independent challenge. Confirm who can reject an item, who reviews provider exceptions and whether both parties rely on the same source or person.
Is dual approval always effective segregation?
No. Dual approval is weak when the second person lacks source evidence, expertise, time or authority to disagree. Test whether the reviewer can detect a realistic error and whether a rejection changes the outcome. The evidence should show what was checked, not only two user names.
How should emergency access be handled?
Use named alternates, narrow scope, time-limited access, action monitoring and an explicit handback. Record why incompatible duties were combined and arrange independent retrospective review. Revoke rights across all internal and provider systems, then verify that no residual authority remains.
What should VCC directors receive?
Directors should see material duty concentrations, failed or late controls, repeated emergency combinations, unresolved conflicts and management’s repair plan. Reporting should connect the issue to the affected VCC or sub-fund and show whether the compensating control actually operated.
Official sources and further reading
- Risk Management Practices for Fund Management Companies (Monetary Authority of Singapore)
- Guidelines on Individual Accountability and Conduct (Monetary Authority of Singapore)
- Technology Risk Management Guidelines (Monetary Authority of Singapore)
- Guideline SFA 04-G05 on Licensing and Conduct of Business for Fund Managers (Monetary Authority of Singapore)
- Understanding VCC Features, Eligibility and Requirements (Accounting and Corporate Regulatory Authority)
Discuss a Singapore VCC structure
For help coordinating a Singapore VCC setup or corporate administration, contact Raffles Corporate Services.
General information only. This article is not legal, tax, regulatory or investment advice and does not imply affiliation with or endorsement by ACRA, MAS or IRAS.