Meridian Workstation  /  Advisor console — internal
Client:  All clients
 ·  Base: SGD  ·  FX: MAS ref

Report  ·  Generated
Confidential — Internal use only
Client Entity
Theme
Acting as Originator / RM
The multi-family office's book of business. Each row is a client family — click to open its full portfolio, reports, and compliance file. Figures reflect the selected snapshot; flags highlight families needing attention (mandate breaches, low cash, KYC).
Today's priorities — PM worklist
Every open item across the book, ranked by severity. Click an item to jump to where it's actioned.
Client families
Client family Relationship mgr AUM (SGD) ▼ MTD YTD Cash Top position KYC Next review Flags
Click a family to drill into its portfolio. Returns are approximate month-over-month AUM changes for the demo (not fee/flow-adjusted TWR).
End-to-end onboarding for a new client family — entity setup, key persons, document collection, screening, and review. Submission routes the application to Compliance review (and MLRO sign-off for High-risk / PEP / exception cases); the client appears in the roster only after approval.
Step 1 · Family & entity details
These two fields feed the AML customer risk assessment (industry & expected activity factors) — distinct from the investment mandate above.
Step 2 · Key persons (UBOs, beneficiaries, signatories)
Add every individual who needs a KYC record — principals, beneficial owners, trustees, signatories. At least one is required.
Add a person
Step 3 · Document collection
Upload the required KYC documents for each person. Files stay in your browser for this demo — nothing is uploaded anywhere — and are recorded against the person's KYC file exactly like existing clients.
Step 4 · Background & screening
Sanctions, PEP, and adverse-media screening runs automatically for each person.
Step 5 · Review & submit
Client onboarded
Portfolio trend (full history)
Asset class mix
Top 5 holdings · vs. prior month
TickerNameTypeBrokerPrior valueCurrent valueChangeWeightP&L
Largest movers vs. prior month
Regional snapshot
Sector snapshot
Quick risk status
Filter:
TickerNameTypeBroker CCY Region Sector Qty Price Local value SGD value Cost (SGD) P&L (SGD) Weight
Derivatives & structured products
Structured notes (fixed-coupon, autocallable, accelerator) and listed-option strategies (straddles, spreads) — held as term-sheet / broker-marked positions. Beyond the mark, the risk cockpit below shows net Greeks, barrier buffers, issuer credit exposure, the maturity ladder and a stress grid, then decomposes each note to its underlying names. Greeks and scenario figures are indicative (term sheet / risk model).
InstrumentTypeEntityNotionalMarket valueP&LNet Δ (SGD)Buffer to barrierCapital at riskMaturity
ScenarioBook P&L% of derivative MV
Delta + convexity + vega, indicative. Short-gamma income notes lose disproportionately in the −20% column near their barriers.
UnderlierDirect (SGD)Via derivatives (SGD)Combined% of AUMvs single-position limit
Target vs actual — asset class
Target vs actual — region
Economic exposure — physical vs derivative look-through
Physical shows where the money sits (custody securities, cash & deposits, plus derivatives at their mark). Economic re-casts each derivative into the asset class its delta actually tracks — so equity-linked notes and options add delta-equivalent equity exposure. The gap between the two is the leverage and optionality a market-value view hides.
Economic exposure uses delta-equivalent notional (not market value), so the total can sit above or below the physical book: geared notes (e.g. accelerators, delta > 1) push it above 100% of NAV — that excess is leverage — while delta-neutral options (straddles) hold market value but little directional exposure, pulling it below. Their risk is in the vega line, not the bars. Indicative; based on term-sheet deltas.
Currency exposure
By broker
Sector breakdown (equity + REIT positions only)
Sector detail table
SectorPositionsSGD value% of total% of equityUnrealized P&LTop holding
Rebalancing guide (to reach policy targets)
CategoryCurrent SGDCurrent %Target %DriftAction (SGD)
Rebalance amounts are indicative. Transaction costs and tax implications not included.
DateBrokerTypeDescriptionDebit (SGD)Credit (SGD)Running balanceRef
Reconciliation engine — period-end balance check
Validates: closing balance = opening balance + inflows − outflows. This check runs per broker before any month-end figure is reported.
BrokerOpeningInflowsOutflowsFX revaluationCalculated closingReported closingVarianceStatus
Cross-account cash flow — this period
Every cash movement across all custodians for the scope in view — money in (dividends, interest, structured-note coupons, sales & redemptions, funding) and money out (purchases, advisory/management fees, brokerage). Note coupons and advisory fees are accruals (settle on their own schedule) and are shown separately from the custodian reconciliation.
Income by asset class
Where the book's income comes from, by asset class. Equity dividends, REIT distributions and cash interest are actual receipts from the ledger; bond coupons, time-deposit interest and structured-note coupons are indicative accruals (run-rate), since they settle on their own schedules rather than as monthly cash.
Asset classSourceThis monthAnnualisedYield on valueBasis
Dividends received
Upcoming dividend schedule
Advisory & management fees
The firm's advisory fee on assets under management, accrued monthly on a tiered schedule — the client-facing cost side of the relationship, shown separately from custodian cash movements.
Yield-on-cost by position
TickerNameTypeCost (SGD)Annual div/unitSharesEst. annual incomeYield-on-costLast payment
* Estimated based on trailing 12-month dividends. Actual amounts may vary.
Monthly return vs benchmarks
Cumulative performance (full history)
Risk-adjusted metrics
Computed from the monthly return series over the available history. Family offices judge on risk-adjusted terms, not just headline return.
Sharpe uses a ~3% p.a. SGD risk-free rate. Volatility annualised from monthly σ. Max drawdown is the largest peak-to-trough decline in portfolio value. Demo series — indicative only.
Return attribution — this month
Which parts of the portfolio drove the month's return. Contributions sum to the portfolio MTD return.
RegionContributionAvg weight
Asset classContributionAvg weight
Top contributors & detractors — this month
By position, month-over-month value change. What actually moved the needle — the conversation starter for a client review call.
PositionΔ valueContribution
PositionΔ valueContribution
Benchmark comparison table
IndexMTD returnYTD returnvs Portfolio MTD
MAS 13O/13U entity structure
Legal-entity breakdown — every holding, transaction, and alternative asset is tagged to its legal entity, so reporting and access can be cleanly segregated per entity.
Holdings by entity
EntityTickerNameBrokerSGD valueWeightLocal inv.
PE / VC / private debt / real estate / hedge fund / art / crypto positions — valued by NAV or last transaction. Typically hand-entered or loaded from fund statements rather than broker-fed.
Capital-call coverage — book-wide
Unfunded commitments (commitment − contributed, active positions) vs each family's liquid cash. Coverage under 100% means a full capital call would force selling securities.
Alternative assets register
EntityAssetTypeManagerCommitmentContributedNAV (SGD)IRRMultipleVintageStatus
IRR and multiple (TVPI) are illustrative; written-off positions retain a residual NAV per manager marks.
Splits, rights issues, and dividends recorded against a ticker + action date, linked to the transactions that they generated — so cost-basis stays traceable after a split or rights subscription.
DateTickerActionRatioDiv/shareCurrencyNotes
This product makes no outside connections. All portfolio data arrives by statement import — the accounts below are a local register of your custodian relationships and where each figure last came from.
How portfolio data gets in — statement-based, on this device
Every custodian, bank and broker can produce a statement — so statement import works with any counterparty, including alternatives and non-standard funds that have no feed at all. Nothing is fetched from outside; you load the file, the product does the rest locally.
UPLOAD
1 · Statement upload
CSV / Excel / Word / PDF exports from any custodian portal
OCR
2 · On-device reading
Scanned PDFs read by on-device OCR — you verify every figure
BOOK
3 · Map & reconcile
Map columns once, preview, load into one consolidated book
Local Singapore custodians (e.g. OCBC Securities) don't open institutional APIs to every family office, and SGFinDex is retail-only — statement import works regardless. Direct custodian API sync is available as an optional extension in a networked deployment; this air-gapped build deliberately imports statements only.
Data freshness
Every position holds the value from its account's most recently imported statement — the book is exactly as fresh as the statements you load. Each holding carries a statement-date badge in the Holdings table.
Custodian accounts
Register an account
Create a local record of a custodian, bank or broker relationship. Registration is a bookkeeping entry only — data always arrives via statement import, and accounts are also created automatically the first time you import a statement for them.
Administrator functions for an on-premise deployment — manage the staff who can sign in (and their roles), and migrate an existing client book from a CSV export. Restricted to the MLRO / Compliance.
Segregation of duties: an onboarding file is originated by the Relationship Manager, reviewed by a Compliance Officer, and — for high-risk / PEP / exception cases — approved by the MLRO before the client is created and activated. No single person can both originate and approve. Every decision is recorded with who, when, and why. Use the "Acting as" switcher (top right) to change identity.
A dedicated ML/TF customer risk assessment, separate from the client's investment risk profile. Each client is rated across six weighted factors defined by MAS Notice SFA04-N02 and its Guidelines — geography, PEP exposure, structure complexity, industry, source of wealth, and expected transaction activity — with the scoring basis recorded for audit. This is the AML risk rating that drives EDD and review cadence; it is not the investment mandate.
Entity CDD record (legal person)
Legal-person identification captured at onboarding per MAS Notice SFA04-N02 & Guidelines Appendix A — legal form, registration, registered address, purpose of relationship, entity source of funds, and constitution / registry documents.
Family KYC profiles
Individual KYC records for principals, beneficiaries, and appointed professionals linked to each entity — name, age, occupation, background, source of funds, and supporting documents. Internal record for Founder Admin / MFO staff use.
KYC due — upcoming
Everything coming due across the book in the selected window — periodic reviews, document expiries, and data-sharing consent renewals. Risk-based cadence (Low +36m, Medium +12m, High +6m) with tiered routing: T-60 → Relationship Manager, T-30 → Compliance Officer, +7 overdue → auto-escalate to MLRO.
Horizon
Risk alerts & advisor actions
Alerts raised by the platform's rule-based policy checks require human sign-off. Click a status chip to record the advisor's decision (Pending → Adopted → Rejected) — the approver and date are stamped for audit.
Firm-level compliance status
Standing controls across the whole book — screening cadence, audit trail, and monitoring switches.
MAS 13O / 13U fund compliance checklist
Evaluated per qualifying fund entity against MAS's current criteria (updated 5 Jul 2023): minimum fund AUM, Capital Deployment Requirement, investment professionals, and tiered local business spending — tested continuously, not just at application.
13O: min S$20M designated investments · ≥2 investment professionals (≥1 non-family). 13U: min S$50M · ≥3 investment professionals (≥1 non-family). Local business spending tiered S$200k / S$500k / S$1M at AUM <S$50M / S$50–100M / ≥S$100M. Capital Deployment Requirement: ≥10% of AUM or S$10M (whichever lower) in qualifying investments. AUM measured as designated investments, tested continuously (no grace period since 5 Jul 2023); schemes extended to 31 Dec 2029. Figures are illustrative demo data; investment-professional and spending items are attested operational inputs. Verified against MAS criteria as at Jul 2026 — re-verify before client use.
Ongoing KYC / AML monitoring
Monitoring event feed — sanctions & PEP re-screening on each list load or book-wide re-screen, document expiries, and overdue reviews. The review scheduler generates tasks when run (nightly in the desktop build); adverse-media coverage comes from entries in the loaded offline list.
Client consent & third-party sharing
Every custodian feed requires the client's documented consent (signed LOA + platform consent record). Feeds for a client without current consent stay paused. The sharing log records what left the platform, to whom, and under which consent — PDPA purpose-limitation evidence.
Client familyConsent statusScopeObtained viaValid untilSharing-log entries
Renewals are surfaced in the PM worklist 90 days before expiry. Revocation pauses all feeds for that client immediately and is stamped into the audit log.
MAS readiness map — third-party arrangements
How the platform's controls line up with the MAS instruments a CMS licensee reviews before adopting a third-party service. A discussion aid for the compliance review — not a legal opinion.
Guidelines on Outsourcing (FIs other than Banks) — eff. 11 Dec 2024, rev. 24 Jan 2025; due diligence, audit & MAS access rights, exitClient-hosted deployment
Technology Risk Management Guidelines (18 Jan 2021) + binding Notice FSM-N21 (eff. 10 May 2024) — encryption, access control, critical-system availability, incident notificationIn place
PDPA 2012 (as amended 2020) — consent, purpose & transfer limitation, breach notification; all processing stays on this deviceConsent registry · on-device
Cyber Hygiene Notice FSM-N22 (eff. 10 May 2024) — admin accounts, patching, security standards, network perimeter, malware protection, MFADeployment-dependent
AML/CFT Notice SFA04-N02 (30 Jun 2025, under FSMA s16) — CDD records, screening, ongoing monitoringKYC + monitoring modules
Record keeping — SFA s102(3) & SFA04-N02 §11: ≥5 yearsImmutable audit log
Data residency: MAS does not mandate Singapore-only storage (offshore is permitted with safeguards under the Outsourcing Guidelines and PDPA s26) — this platform defaults to Singapore residency as the simpler posture. Watch item: MAS consulted on Third-Party Risk Management Guidelines (Mar 2026) that will supersede the Outsourcing Guidelines and cover all third-party arrangements including SaaS; not yet in force as of Jul 2026. Instrument names verified Jul 2026 — re-verify during onboarding.
What-if — rebalance simulator
Model trimming the largest position to the mandate's single-stock limit and see the effect on concentration and cash before advising the client.
Cash & equivalents detail
Every cash sub-account by broker and currency, valued at MAS reference rates for the snapshot.
BrokerTickerCurrencyBalance (local)FX rateSGD valueWeightValuationMAS local?
Report version control
Each report snapshot is assigned a unique version for audit traceability. Retained at least 5 years per SFA s102(3) and MAS Notice SFA04-N02; the platform's 7-year default is a conservative firm-policy buffer above the statutory floor.
Current version
Generated at
Data snapshot date
Source data hash
Bumps version, re-stamps timestamp, recomputes hash. No underlying figures change in this demo.
Version history
VersionGeneratedTriggerStatus
How client data is ingested, processed, stored, shared, retained, and deleted — written in plain language for compliance and IT sign-off. This is a demo build: control attestations describe the production deployment and should be verified during vendor due diligence.
How data moves through the platform
1
Ingest
Statement upload only (CSV / Excel / Word / PDF) — always under the client's recorded consent; nothing is fetched from outside
2
Clean & standardise
OCR, ticker/name normalisation, FX conversion, dedup — inside the deployment boundary
3
Store
Encrypted single-tenant database, Singapore region or your own server
4
Analyse & report
Dashboards, reports, and checks computed in place — data does not move to be analysed
5
Share
Only user-initiated exports and consent-gated flows ever leave — each one audit-logged
Where data is stored
Single-tenant by design — on-premise the book never leaves the firm’s own machineOn-prem; trial is shared
Encryption at rest — AES-256Enabled
Encryption in transit — TLS 1.3Enabled
Data residency — on-premise has no egress at all; the hosted trial runs in the Singapore region, though AI features still reach the model provider abroadSG region · AI egress
Row-level security keyed on entity_id (tenant isolation inside the firm)Not in this build
Encrypted backups, same jurisdiction as primaryNot in this build
Uploaded documents (statements, KYC, term sheets) — same encrypted store, never a third-party file serviceIn boundary
Who can access what
Role-based access control — Originator / Compliance / MLRO / read-only (live in this demo; switch via "Acting as")Enforced
Maker-checker segregation — no one can originate and approve the same clientEnforced
Multi-factor authentication — TOTP on the on-premise build; the browser demo has no loginOn-premise build only
Every view, change, and export written to a hash-chained audit logAlways on
Client-facing access (roadmap) — separate login, scoped to that client's own bookPlanned
Vendor engineers on client-hosted deploymentsNo access
Vendor engineers on vendor-hosted deploymentsAudited break-glass only
What leaves the platform — and what never does
Outbound flowTriggerWhat is sentSafeguard
AI agent connector (optional, off by default)Admin-enabled, read-onlyCompliance projection of the book (raw watchlist excluded) — served locally to a client-hosted AI agentLocal loopback + per-session token; read-only; every call audited; the product itself makes no outbound call
Reports (PDF/CSV)User-initiatedOnly the sections the user selectsVersioned, watermarked, export recorded in audit log
Everything elseNothingNo telemetry, no third-party analytics, no advertising SDKs, client data never used to train AI models
Retention & deletion
Client, transaction & CDD records — statutory minimum per SFA 2001 s102(3) and MAS Notice SFA04-N02 §11≥5 years
Firm retention policy — configurable above the statutory floorConfigurable
Audit log — immutable, same retention clockImmutable
Offboarding — full structured export to the firm, then cryptographic erasure within 30 daysContractual
PDPA retention limitation — personal data not kept once purpose ceases and retention period lapsesPolicy
Consent & PDPA
Consent registry — every statement import tied to a recorded, dated client consentGates imports
Purpose limitation — data used only for reporting, analysis & compliance the client signed up forPolicy
Transfer limitation — personal data leaves Singapore only with comparable protection in placePDPA s26
Data breach response — assess, contain, notify PDPC within 3 calendar days of assessing a breach notifiableRunbook
Data Protection Officer — named per deployment, contact published to clientsNamed
Deployment models & vendor access
ModelWhere data livesVendor access to client dataBest for
On-premiseYour own server (e.g. office hardware)NoneMaximum control; MAS outsourcing posture simplest
Client cloudYour AWS / Azure account, Singapore regionNoneControl with managed infrastructure
Vendor cloudDedicated single-tenant environment, Singapore regionAudited break-glass onlyFastest start; full client audit rights contractually
In every model the firm can demand logs, run security reviews, and exit with a full data export — the audit/access/exit rights MAS expects a regulated firm to hold over its service providers.
Regulatory alignment
Summary view — the detailed control-by-control mapping lives in Risk & compliance → MAS readiness map. A discussion aid for due diligence, not a legal opinion.
Why this is safe — the one-minute version
  1. Your data stays inside a boundary you choose — your server, your cloud, or a dedicated Singapore tenant. Nothing streams to the vendor.
  2. Nothing leaves that boundary except what a named user deliberately exports — and every such event is audit-logged. (An optional, off-by-default AI-agent connector lets a client-hosted agent read the book locally and read-only; it, too, is audited.)
  3. Every custodian feed is tied to a client's recorded consent; no consent, no feed.
  4. Storage is encrypted and access is role-based; the on-premise build adds a real login with MFA. Every action is written to a hash-chained audit log — the trail a regulator or auditor asks for already exists.
  5. Retention follows the MAS statutory floor and your firm's policy; when you leave, you take a full export and the rest is cryptographically erased.
  6. The platform tracks the rules it operates under — 13O/13U criteria, AML/KYC monitoring, consent, and third-party expectations — in the product itself, so compliance evidence is a screenshot, not a spreadsheet hunt.
Demo build. Control attestations, certifications (SOC 2 / ISO 27001 on roadmap), and the regulatory mapping are commitments for the production deployment — verify against the current MAS and PDPC texts and your internal policies during vendor due diligence.
Security & deployment
Singapore family offices are bound by the PDPA; client data should not leave the jurisdiction without control. Deployment and security posture for procurement / IT sign-off.
Singapore-local (on-premise / private server)Supported
AWS / Azure Singapore region (private cloud, data residency)Supported
Data residency — no cross-border egress by defaultEnforced
Single-tenant isolation per MFOAvailable
Encryption at rest (AES-256)Enabled
Encryption in transit (TLS 1.3)Enabled
Immutable audit log — ≥5-year statutory retention (SFA s102(3), SFA04-N02), 7-year defaultActive
PDPA alignmentAligned
SOC 2 Type II & ISO 27001On roadmap
Certification timelines and control attestations are commitments for the production build, shown here for the procurement conversation — not yet independently audited in this demo.
Data quality score — this snapshot
Completeness × 0.4 + accuracy × 0.4 + consistency × 0.2 = overall grade.
Data quality trend (12-month)
Dirty vs. cleaned — OCR extraction sample
Illustrates the data-cleaning rule engine against a sample extracted from the latest imported statement.
Raw OCR extraction
TickerNameDateCost basisSource
Cleaned & standardized
TickerNameDateCost basisRule applied
Audit log
Immutable audit trail — every insert, update, export, and view recorded with actor, timestamp, and reason. Retained at least 5 years per SFA s102(3) / MAS Notice SFA04-N02 (7-year firm default).
Timestamp (UTC)EntityTableOperationPerformed byReasonHash