Operational resilience for Singapore fund managers: the 2026 rulebook, and what's coming
Ask what could actually kill a fund management business and the honest answers are rarely market risk: it is the administrator outage on dealing day, the cyber incident in the investor register, the cloud dependency nobody mapped. MAS has spent 2026 rebuilding its framework around exactly that reality — twin March consultations on operational risk and third-party risk, a supervisory-priorities circular for capital markets entities, and a thematic paper on fund managers' risk practices. Here is what an LFMC or VCC manager must already comply with, and what changes next.
The short answer
Operational resilience in Singapore is not a bank-only regime. MAS frames it across four pillars — operational risk management, technology and cyber risk, third-party risk, and business continuity — and applies the framework to capital markets entities, expressly including fund managers and REIT managers. For a licensed fund management company running a VCC, the current baseline is four instruments: the BCM Guidelines (June 2022), the Technology Risk Management Guidelines (January 2021), the binding Cyber Hygiene Notice FSM-N22 (effective 2024), and the outsourcing guidelines for non-bank FIs. The 2026 news is that two of those pillars are being rebuilt: on 6 March MAS consulted on updated Operational Risk Management guidelines (superseding the 2013 version) and new Third-Party Risk Management guidelines (superseding the outsourcing regime), with final texts pending and a six-month transition expected once they land.
Why 2026 is the year this got loud
Three MAS moves in four months put resilience on every compliance agenda. The 6 March consultations proposed the first ground-up refresh of operational-risk expectations in over a decade — adding change-management discipline and disclosure expectations — and a third-party regime that reaches far beyond classic outsourcing to any material third-party arrangement: cloud, SaaS, market-data vendors, intragroup services. In April, MAS's supervisory-priorities circular for capital markets entities named operational resilience alongside governance and AML as a 2026/27 focus, and flagged what is queued behind it: updated technology-risk notices, liquidity-risk guidelines for fund managers, and AI risk-management guidelines. In May, an information paper on fund management companies' risk practices — drawn from thematic inspections — told managers where their peers actually fall short. The direction is unmistakable: expectations built for banks are being generalised, proportionately, to the whole regulated perimeter — and the global backdrop of headline IT outages taking down dependent firms across industries did the persuading.
The current baseline: what already applies
| Instrument | Since | What it requires of a fund manager |
|---|---|---|
| BCM Guidelines | Jun 2022 (runway ended 2023) | Identify critical business services; set a Service Recovery Time Objective for each; map end-to-end dependencies; test severe-but-plausible scenarios; annual senior-management attestation to the board; BCM audit at least every 3 years |
| TRM Guidelines | Jan 2021 | Board-level technology governance, secure development, cloud and API risk management, cyber resilience — applies to capital markets intermediaries |
| Cyber Hygiene Notice FSM-N22 | 2024 (binding) | Secured admin accounts, security patching, baseline standards, network defences, anti-malware, strong authentication — LFMCs expressly in scope |
| Outsourcing Guidelines (non-bank FIs) | current, to be superseded | Due diligence, contractual protections, audit/access rights and register for outsourced services — the regime the 2026 TPRM guidelines will replace |
The BCM piece deserves emphasis because its deadlines have already passed: the compliance runway ended in 2023 and first audits fell due in 2024. A manager who cannot show a critical-business-services map, recovery objectives and test evidence is not behind on something new — they are behind on something current.
What a fund manager's "critical business service" actually is
The bank examples — payments, ATMs — translate poorly, so managers under-scope. For a fund manager the honest list looks like: striking and delivering NAV; processing subscriptions and redemptions; executing and settling trades; meeting capital calls and margin obligations; investor reporting and communications; and the regulatory filing calendar. Each runs on a dependency chain that mostly sits outside the firm — the fund administrator, the custodian, the cloud and market-data stack, sometimes a sub-adviser. Which is exactly why the third-party pillar is the one MAS chose to rebuild.
The third-party shift: from "outsourcing" to everything
The proposed Third-Party Risk Management guidelines redraw the perimeter. Where the outsourcing regime asked "have you outsourced a function?", the new frame asks "what do you depend on?" — and expects a register of material arrangements, lifecycle management from pre-contract due diligence through exit, visibility into sub-contractors, and assessment of concentration risk. For a typical VCC manager the concentration is stark: one administrator carrying NAV, transfer agency and FATCA/CRS; one custodian; one or two cloud platforms. None of that is wrong — it is the economic point of the model — but under the incoming regime it must be known, documented, tested and exit-planned rather than assumed. Managers who wait for the final text will be building registers under deadline; the consultation paper is a perfectly good blueprint to start against now.
A practical 2026 self-assessment
- Map the services, not the org chart. List the six-or-so services above, assign each an owner and a recovery-time objective, and trace every dependency to a named provider — including theirs.
- Test the ugly scenario. Administrator down on dealing day; cyber incident in the register; key-person loss in a two-professional shop. Severe-but-plausible means uncomfortable, or it is not the test MAS means.
- Close the FSM-N22 basics. Admin-account controls, patch cadence, MFA. Binding notice, small firm no defence.
- Build the third-party register early. Inventory arrangements, check exit and data-return clauses, note sub-contractors and concentration — ahead of the final TPRM guidelines.
- Put it on the board agenda. The annual BCM attestation is due anyway; use it to drive the rest, and keep the audit trail — the every-three-years BCM audit clock is running.
Resilience is also becoming a commercial screen, not just a regulatory one: allocators' operational due diligence now walks these exact questions, and in a flat-alternatives fundraising market the managers who answer them cleanly convert diligence into commitments faster.
Tightening your fund's operational stack?
Tell us how your fund runs today — who holds the NAV, the register, the filings — and where the gaps worry you. We refer clients to an established international fund-services group with a Singapore office for the administration and operational layer, alongside MAS-licensed managers and compliance specialists where the mandate needs them.
Request a fund-services referral →Do MAS operational resilience rules apply to fund managers, or just banks?
They apply to fund managers. MAS frames operational resilience across four pillars — operational risk management, technology and cyber risk, third-party risk, and business continuity — and its scope statements expressly cover capital markets entities including fund managers and REIT managers. The Business Continuity Management Guidelines, Technology Risk Management Guidelines and the Cyber Hygiene Notice (FSM-N22) all bind or apply to licensed fund management companies, and the 2026 consultation papers propose FI-wide guidelines rather than bank-only ones.
What changed on operational resilience in 2026?
On 6 March 2026 MAS published twin consultation papers: updated Guidelines on Operational Risk Management, superseding the 2013 operational-risk guidelines and adding change-management and disclosure expectations, and new Guidelines on Third-Party Risk Management, which would replace the outsourcing guidelines with a broader regime covering all third-party arrangements — cloud, SaaS, data vendors, intragroup services. Consultation closed 20 April 2026, with final guidelines pending and a six-month transition expected. MAS's April 2026 supervisory-priorities circular for capital markets entities and a May 2026 information paper on fund managers' risk practices completed the picture.
What do the MAS Business Continuity Management Guidelines require?
The June 2022 BCM Guidelines require an end-to-end, service-centric approach: identify critical business services, set a Service Recovery Time Objective for each, map dependencies across people, processes, technology and third parties, test against severe-but-plausible scenarios, and manage concentration risk. Senior management must attest to the board annually on BCM preparedness, and the framework must be audited at least once every three years. The compliance runway ended in 2023, so these are current expectations, not aspirations.
What does the Cyber Hygiene Notice require of a fund management company?
Notice FSM-N22 — legally binding, effective 2024, and explicitly applicable to licensed fund management companies — requires securing administrative accounts, timely security patching, baseline security standards, network perimeter defences, anti-malware protection and strong user authentication. It sits alongside the 2021 Technology Risk Management Guidelines, which set broader expectations on technology governance, secure development and cyber resilience.
What should a VCC manager do about third-party and administrator dependency?
Treat it as a named risk. A typical VCC concentrates its operations in a handful of providers — administrator, custodian, cloud platforms — and MAS's proposed Third-Party Risk Management guidelines would formalise expectations most managers only partially meet: a register of arrangements, lifecycle due diligence, sub-contractor visibility and concentration-risk assessment. Practical first steps: inventory every material third party, check exit and data-return clauses, and test what actually happens to NAV delivery and investor servicing if a key provider fails.
- MAS — Achieving Operational Resilience for Financial Institutions
- MAS — Guidelines on Business Continuity Management (June 2022)
- MAS — Notice FSM-N22: Cyber Hygiene
- MAS — Consultation on Updated Guidelines on Operational Risk Management (6 March 2026)
- Baker McKenzie — MAS proposes Third-Party Risk Management Guidelines (March 2026)
