Operational resilience for Singapore fund managers: obligations and proposed changes
An administrator outage, compromised investor register or unavailable technology provider can interrupt a fund’s operations. This guide considers the resilience framework for fund managers, the March 2026 consultations on operational and third-party risk, and the work needed to assess critical services and provider dependencies.
Framework overview
Operational resilience in Singapore is not a bank-only regime. MAS frames it across four pillars — operational risk management, technology and cyber risk, third-party risk, and business continuity — and applies the framework to capital markets entities, expressly including fund managers and REIT managers. For a licensed fund management company running a VCC, the current baseline is four instruments: the BCM Guidelines (June 2022), the Technology Risk Management Guidelines (January 2021), the binding Cyber Hygiene Notice FSM-N22 (effective 2024), and the outsourcing guidelines for non-bank FIs. The 2026 news is that two of those pillars are being rebuilt: on 6 March MAS consulted on updated Operational Risk Management guidelines (superseding the 2013 version) and new Third-Party Risk Management guidelines (superseding the outsourcing regime), with final texts pending and a six-month transition expected once they land.
Regulatory developments in 2026
Three MAS moves in four months put resilience on every compliance agenda. The 6 March consultations proposed the first ground-up refresh of operational-risk expectations in over a decade — adding change-management discipline and disclosure expectations — and a third-party regime that reaches far beyond classic outsourcing to any material third-party arrangement: cloud, SaaS, market-data vendors, intragroup services. In April, MAS's supervisory-priorities circular for capital markets entities named operational resilience alongside governance and AML as a 2026/27 focus, and flagged what is queued behind it: updated technology-risk notices, liquidity-risk guidelines for fund managers, and AI risk-management guidelines. In May, an information paper on fund management companies' risk practices — drawn from thematic inspections — told managers where their peers actually fall short. The direction is unmistakable: expectations built for banks are being generalised, proportionately, to the whole regulated perimeter — and the global backdrop of headline IT outages taking down dependent firms across industries did the persuading.
The current baseline: what already applies
| Instrument | Since | What it requires of a fund manager |
|---|---|---|
| BCM Guidelines | Jun 2022 (runway ended 2023) | Identify critical business services; set a Service Recovery Time Objective for each; map end-to-end dependencies; test severe-but-plausible scenarios; annual senior-management attestation to the board; BCM audit at least every 3 years |
| TRM Guidelines | Jan 2021 | Board-level technology governance, secure development, cloud and API risk management, cyber resilience — applies to capital markets intermediaries |
| Cyber Hygiene Notice FSM-N22 | 2024 (binding) | Secured admin accounts, security patching, baseline standards, network defences, anti-malware, strong authentication — LFMCs expressly in scope |
| Outsourcing Guidelines (non-bank FIs) | current, to be superseded | Due diligence, contractual protections, audit/access rights and register for outsourced services — the regime the 2026 TPRM guidelines will replace |
The BCM expectations described above are already in effect. Review the critical-services map, recovery objectives and test records against the applicable requirements, rather than treating them solely as preparation for new proposals.
Identifying critical business services
For a fund manager, critical services may include NAV calculation and delivery, subscriptions and redemptions, trade execution and settlement, capital calls and margin payments, investor communications, and regulatory filings. Map each service to its internal owner and external dependencies, including the fund administrator, custodian, technology providers and any sub-adviser. Use that map to identify points of failure and recovery arrangements.
Third-party arrangements beyond outsourcing
The proposed third-party framework extends the assessment beyond outsourced functions to material provider dependencies. Preparation can include a register of arrangements, due diligence throughout the relationship, subcontractor information, concentration assessment and exit planning. A VCC manager may rely on one administrator for several services and a small number of custody and technology providers. Record these concentrations and test the consequences of disruption. Reassess the preparation against the final guidelines when issued.
A practical 2026 self-assessment
- Map critical services. Assign an owner and recovery objective, then identify the people, processes, systems and external providers on which each service depends.
- Test severe but plausible disruption. Include an administrator outage on a dealing day, an investor-register incident and the absence of a key professional. Record the operational consequences and corrective actions.
- Review cyber-hygiene controls. Check administrative accounts, patching and authentication against the applicable notice and maintain evidence of implementation.
- Prepare the third-party register. Identify material arrangements, subcontractors, concentration exposures, and the contractual provisions for exit and data return. Reassess it against the final guidelines when issued.
- Maintain board oversight. Use the BCM review and attestation process to track outstanding actions, and retain the evidence needed for the periodic audit.
Operational due diligence may examine these controls alongside the fund’s investment process. Clear records of dependencies, testing and remedial actions support that assessment. The asset management survey provides wider market context.
Review fund operating arrangements
Describe how NAV, investor records and filings are managed, together with the provider dependencies or control gaps requiring attention. We can use the brief to identify relevant administration, fund management or compliance expertise.
Request a fund-services referral →Do MAS operational resilience rules apply to fund managers, or just banks?
They apply to fund managers. MAS frames operational resilience across four pillars — operational risk management, technology and cyber risk, third-party risk, and business continuity — and its scope statements expressly cover capital markets entities including fund managers and REIT managers. The Business Continuity Management Guidelines, Technology Risk Management Guidelines and the Cyber Hygiene Notice (FSM-N22) all bind or apply to licensed fund management companies, and the 2026 consultation papers propose FI-wide guidelines rather than bank-only ones.
What changed on operational resilience in 2026?
On 6 March 2026 MAS published twin consultation papers: updated Guidelines on Operational Risk Management, superseding the 2013 operational-risk guidelines and adding change-management and disclosure expectations, and new Guidelines on Third-Party Risk Management, which would replace the outsourcing guidelines with a broader regime covering all third-party arrangements — cloud, SaaS, data vendors, intragroup services. Consultation closed 20 April 2026, with final guidelines pending and a six-month transition expected. MAS's April 2026 supervisory-priorities circular for capital markets entities and a May 2026 information paper on fund managers' risk practices completed the picture.
What do the MAS Business Continuity Management Guidelines require?
The June 2022 BCM Guidelines require an end-to-end, service-centric approach: identify critical business services, set a Service Recovery Time Objective for each, map dependencies across people, processes, technology and third parties, test against severe-but-plausible scenarios, and manage concentration risk. Senior management must attest to the board annually on BCM preparedness, and the framework must be audited at least once every three years. The compliance runway ended in 2023, so these are current expectations, not aspirations.
What does the Cyber Hygiene Notice require of a fund management company?
Notice FSM-N22 — legally binding, effective 2024, and explicitly applicable to licensed fund management companies — requires securing administrative accounts, timely security patching, baseline security standards, network perimeter defences, anti-malware protection and strong user authentication. It sits alongside the 2021 Technology Risk Management Guidelines, which set broader expectations on technology governance, secure development and cyber resilience.
What should a VCC manager do about third-party and administrator dependency?
Record each material provider dependency, including administration, custody and technology. Assess concentration, review exit and data-return clauses, and test the effect of a provider failure on NAV delivery and investor servicing. Update the register and controls against the final third-party guidelines when issued.
- MAS — Achieving Operational Resilience for Financial Institutions
- MAS — Guidelines on Business Continuity Management (June 2022)
- MAS — Notice FSM-N22: Cyber Hygiene
- MAS — Consultation on Updated Guidelines on Operational Risk Management (6 March 2026)
- Baker McKenzie — MAS proposes Third-Party Risk Management Guidelines (March 2026)
