— · Base: SGD · FX: MAS ref — —
Report · Generated Confidential — Internal use only
ClientEntity
Theme
Acting asOriginator / RM
The multi-family office's book of business. Each row is a client family — click to open its full portfolio, reports, and compliance file. Figures reflect the selected snapshot; flags highlight families needing attention (mandate breaches, low cash, KYC).
Today's priorities — PM worklist
Every open item across the book, ranked by severity. Click an item to jump to where it's actioned.
Client families
Client family
Relationship mgr
AUM (SGD) ▼
MTD
YTD
Cash
Top position
KYC
Next review
Flags
Click a family to drill into its portfolio. Returns are approximate month-over-month AUM changes for the demo (not fee/flow-adjusted TWR).
End-to-end onboarding for a new client family — entity setup, key persons, document collection, screening, and review. Submission routes the application to Compliance review (and MLRO sign-off for High-risk / PEP / exception cases); the client appears in the roster only after approval.
Step 1 · Family & entity details
These two fields feed the AML customer risk assessment (industry & expected activity factors) — distinct from the investment mandate above.
Entity identification (CDD — MAS Notice SFA04-N02 & Guidelines Appendix A)
Add every individual who needs a KYC record — principals, beneficial owners, trustees, signatories. At least one is required.
Add a person
Step 3 · Document collection
Upload the required KYC documents for each person. Files stay in your browser for this demo — nothing is uploaded anywhere — and are recorded against the person's KYC file exactly like existing clients.
Step 4 · Background & screening
Sanctions, PEP, and adverse-media screening runs automatically for each person.
Step 5 · Review & submit
Client onboarded
Portfolio trend (full history)
Asset class mix
Top 5 holdings · vs. prior month
Ticker
Name
Type
Broker
Prior value
Current value
Change
Weight
P&L
Largest movers vs. prior month
Regional snapshot
Sector snapshot
Quick risk status
Filter:
Ticker
Name
Type
Broker
CCY
Region
Sector
Qty
Price
Local value
SGD value
Cost (SGD)
P&L (SGD)
Weight
Derivatives & structured products
Structured notes (fixed-coupon, autocallable, accelerator) and listed-option strategies (straddles, spreads) — held as term-sheet / broker-marked positions. Beyond the mark, the risk cockpit below shows net Greeks, barrier buffers, issuer credit exposure, the maturity ladder and a stress grid, then decomposes each note to its underlying names. Greeks and scenario figures are indicative (term sheet / risk model).
Net Greeks & risk
Instrument
Type
Entity
Notional
Market value
P&L
Net Δ (SGD)
Buffer to barrier
Capital at risk
Maturity
Scenario stress — book P&L
Scenario
Book P&L
% of derivative MV
Delta + convexity + vega, indicative. Short-gamma income notes lose disproportionately in the −20% column near their barriers.
Issuer / counterparty concentration
Maturity ladder (notional)
Combined underlying exposure — direct shares + delta-adjusted derivative exposure
Underlier
Direct (SGD)
Via derivatives (SGD)
Combined
% of AUM
vs single-position limit
Target vs actual — asset class
Target vs actual — region
Economic exposure — physical vs derivative look-through
Physical shows where the money sits (custody securities, cash & deposits, plus derivatives at their mark). Economic re-casts each derivative into the asset class its delta actually tracks — so equity-linked notes and options add delta-equivalent equity exposure. The gap between the two is the leverage and optionality a market-value view hides.
Economic exposure uses delta-equivalent notional (not market value), so the total can sit above or below the physical book: geared notes (e.g. accelerators, delta > 1) push it above 100% of NAV — that excess is leverage — while delta-neutral options (straddles) hold market value but little directional exposure, pulling it below. Their risk is in the vega line, not the bars. Indicative; based on term-sheet deltas.
Currency exposure
By broker
Sector breakdown (equity + REIT positions only)
Sector detail table
Sector
Positions
SGD value
% of total
% of equity
Unrealized P&L
Top holding
Rebalancing guide (to reach policy targets)
Category
Current SGD
Current %
Target %
Drift
Action (SGD)
Rebalance amounts are indicative. Transaction costs and tax implications not included.
Date
Broker
Type
Description
Debit (SGD)
Credit (SGD)
Running balance
Ref
Reconciliation engine — period-end balance check
Validates: closing balance = opening balance + inflows − outflows. This check runs per broker before any month-end figure is reported.
Broker
Opening
Inflows
Outflows
FX revaluation
Calculated closing
Reported closing
Variance
Status
Cross-account cash flow — this period
Every cash movement across all custodians for the scope in view — money in (dividends, interest, structured-note coupons, sales & redemptions, funding) and money out (purchases, advisory/management fees, brokerage). Note coupons and advisory fees are accruals (settle on their own schedule) and are shown separately from the custodian reconciliation.
Money in
Money out
Income by asset class
Where the book's income comes from, by asset class. Equity dividends, REIT distributions and cash interest are actual receipts from the ledger; bond coupons, time-deposit interest and structured-note coupons are indicative accruals (run-rate), since they settle on their own schedules rather than as monthly cash.
Asset class
Source
This month
Annualised
Yield on value
Basis
Dividends received
Upcoming dividend schedule
Advisory & management fees
The firm's advisory fee on assets under management, accrued monthly on a tiered schedule — the client-facing cost side of the relationship, shown separately from custodian cash movements.
Yield-on-cost by position
Ticker
Name
Type
Cost (SGD)
Annual div/unit
Shares
Est. annual income
Yield-on-cost
Last payment
* Estimated based on trailing 12-month dividends. Actual amounts may vary.
Monthly return vs benchmarks
Cumulative performance (full history)
Risk-adjusted metrics
Computed from the monthly return series over the available history. Family offices judge on risk-adjusted terms, not just headline return.
Sharpe uses a ~3% p.a. SGD risk-free rate. Volatility annualised from monthly σ. Max drawdown is the largest peak-to-trough decline in portfolio value. Demo series — indicative only.
Return attribution — this month
Which parts of the portfolio drove the month's return. Contributions sum to the portfolio MTD return.
By region
Region
Contribution
Avg weight
By asset class
Asset class
Contribution
Avg weight
Top contributors & detractors — this month
By position, month-over-month value change. What actually moved the needle — the conversation starter for a client review call.
Top contributors
Position
Δ value
Contribution
Top detractors
Position
Δ value
Contribution
Benchmark comparison table
IndexMTD returnYTD returnvs Portfolio MTD
MAS 13O/13U entity structure
Legal-entity breakdown — every holding, transaction, and alternative asset is tagged to its legal entity, so reporting and access can be cleanly segregated per entity.
Holdings by entity
Entity
Ticker
Name
Broker
SGD value
Weight
Local inv.
PE / VC / private debt / real estate / hedge fund / art / crypto positions — valued by NAV or last transaction. Typically hand-entered or loaded from fund statements rather than broker-fed.
Capital-call coverage — book-wide
Unfunded commitments (commitment − contributed, active positions) vs each family's liquid cash. Coverage under 100% means a full capital call would force selling securities.
Alternative assets register
Entity
Asset
Type
Manager
Commitment
Contributed
NAV (SGD)
IRR
Multiple
Vintage
Status
IRR and multiple (TVPI) are illustrative; written-off positions retain a residual NAV per manager marks.
Splits, rights issues, and dividends recorded against a ticker + action date, linked to the transactions that they generated — so cost-basis stays traceable after a split or rights subscription.
Date
Ticker
Action
Ratio
Div/share
Currency
Notes
This product makes no outside connections. All portfolio data arrives by statement import — the accounts below are a local register of your custodian relationships and where each figure last came from.
How portfolio data gets in — statement-based, on this device
Every custodian, bank and broker can produce a statement — so statement import works with any counterparty, including alternatives and non-standard funds that have no feed at all. Nothing is fetched from outside; you load the file, the product does the rest locally.
UPLOAD
1 · Statement upload
CSV / Excel / Word / PDF exports from any custodian portal
→
OCR
2 · On-device reading
Scanned PDFs read by on-device OCR — you verify every figure
→
BOOK
3 · Map & reconcile
Map columns once, preview, load into one consolidated book
Local Singapore custodians (e.g. OCBC Securities) don't open institutional APIs to every family office, and SGFinDex is retail-only — statement import works regardless. Direct custodian API sync is available as an optional extension in a networked deployment; this air-gapped build deliberately imports statements only.
Data freshness
Every position holds the value from its account's most recently imported statement — the book is exactly as fresh as the statements you load. Each holding carries a statement-date badge in the Holdings table.
Custodian accounts
Register an account
Create a local record of a custodian, bank or broker relationship. Registration is a bookkeeping entry only — data always arrives via statement import, and accounts are also created automatically the first time you import a statement for them.
Generate PDF report
Built client-side from current dashboard data
to
Administrator functions for an on-premise deployment — manage the staff who can sign in (and their roles), and migrate an existing client book from a CSV export. Restricted to the MLRO / Compliance.
Segregation of duties: an onboarding file is originated by the Relationship Manager, reviewed by a Compliance Officer, and — for high-risk / PEP / exception cases — approved by the MLRO before the client is created and activated. No single person can both originate and approve. Every decision is recorded with who, when, and why. Use the "Acting as" switcher (top right) to change identity.
A dedicated ML/TF customer risk assessment, separate from the client's investment risk profile. Each client is rated across six weighted factors defined by MAS Notice SFA04-N02 and its Guidelines — geography, PEP exposure, structure complexity, industry, source of wealth, and expected transaction activity — with the scoring basis recorded for audit. This is the AML risk rating that drives EDD and review cadence; it is not the investment mandate.
Entity CDD record (legal person)
Legal-person identification captured at onboarding per MAS Notice SFA04-N02 & Guidelines Appendix A — legal form, registration, registered address, purpose of relationship, entity source of funds, and constitution / registry documents.
Family KYC profiles
Individual KYC records for principals, beneficiaries, and appointed professionals linked to each entity — name, age, occupation, background, source of funds, and supporting documents. Internal record for Founder Admin / MFO staff use.
KYC due — upcoming
Everything coming due across the book in the selected window — periodic reviews, document expiries, and data-sharing consent renewals. Risk-based cadence (Low +36m, Medium +12m, High +6m) with tiered routing: T-60 → Relationship Manager, T-30 → Compliance Officer, +7 overdue → auto-escalate to MLRO.
Horizon
Risk alerts & advisor actions
Alerts raised by the platform's rule-based policy checks require human sign-off. Click a status chip to record the advisor's decision (Pending → Adopted → Rejected) — the approver and date are stamped for audit.
Firm-level compliance status
Standing controls across the whole book — screening cadence, audit trail, and monitoring switches.
MAS 13O / 13U fund compliance checklist
Evaluated per qualifying fund entity against MAS's current criteria (updated 5 Jul 2023): minimum fund AUM, Capital Deployment Requirement, investment professionals, and tiered local business spending — tested continuously, not just at application.
13O: min S$20M designated investments · ≥2 investment professionals (≥1 non-family). 13U: min S$50M · ≥3 investment professionals (≥1 non-family). Local business spending tiered S$200k / S$500k / S$1M at AUM <S$50M / S$50–100M / ≥S$100M. Capital Deployment Requirement: ≥10% of AUM or S$10M (whichever lower) in qualifying investments. AUM measured as designated investments, tested continuously (no grace period since 5 Jul 2023); schemes extended to 31 Dec 2029. Figures are illustrative demo data; investment-professional and spending items are attested operational inputs. Verified against MAS criteria as at Jul 2026 — re-verify before client use.
Ongoing KYC / AML monitoring
Monitoring event feed — sanctions & PEP re-screening on each list load or book-wide re-screen, document expiries, and overdue reviews. The review scheduler generates tasks when run (nightly in the desktop build); adverse-media coverage comes from entries in the loaded offline list.
Client consent & third-party sharing
Every custodian feed requires the client's documented consent (signed LOA + platform consent record). Feeds for a client without current consent stay paused. The sharing log records what left the platform, to whom, and under which consent — PDPA purpose-limitation evidence.
Client family
Consent status
Scope
Obtained via
Valid until
Sharing-log entries
Renewals are surfaced in the PM worklist 90 days before expiry. Revocation pauses all feeds for that client immediately and is stamped into the audit log.
MAS readiness map — third-party arrangements
How the platform's controls line up with the MAS instruments a CMS licensee reviews before adopting a third-party service. A discussion aid for the compliance review — not a legal opinion.
Guidelines on Outsourcing (FIs other than Banks) — eff. 11 Dec 2024, rev. 24 Jan 2025; due diligence, audit & MAS access rights, exitClient-hosted deployment
Technology Risk Management Guidelines (18 Jan 2021) + binding Notice FSM-N21 (eff. 10 May 2024) — encryption, access control, critical-system availability, incident notificationIn place
PDPA 2012 (as amended 2020) — consent, purpose & transfer limitation, breach notification; all processing stays on this deviceConsent registry · on-device
Data residency: MAS does not mandate Singapore-only storage (offshore is permitted with safeguards under the Outsourcing Guidelines and PDPA s26) — this platform defaults to Singapore residency as the simpler posture. Watch item: MAS consulted on Third-Party Risk Management Guidelines (Mar 2026) that will supersede the Outsourcing Guidelines and cover all third-party arrangements including SaaS; not yet in force as of Jul 2026. Instrument names verified Jul 2026 — re-verify during onboarding.
What-if — rebalance simulator
Model trimming the largest position to the mandate's single-stock limit and see the effect on concentration and cash before advising the client.
Cash & equivalents detail
Every cash sub-account by broker and currency, valued at MAS reference rates for the snapshot.
Broker
Ticker
Currency
Balance (local)
FX rate
SGD value
Weight
Valuation
MAS local?
Report version control
Each report snapshot is assigned a unique version for audit traceability. Retained at least 5 years per SFA s102(3) and MAS Notice SFA04-N02; the platform's 7-year default is a conservative firm-policy buffer above the statutory floor.
Current version—
Generated at—
Data snapshot date—
Source data hash—
Bumps version, re-stamps timestamp, recomputes hash. No underlying figures change in this demo.
Version history
Version
Generated
Trigger
Status
How client data is ingested, processed, stored, shared, retained, and deleted — written in plain language for compliance and IT sign-off. This is a demo build: control attestations describe the production deployment and should be verified during vendor due diligence.
How data moves through the platform
1
Ingest
Statement upload only (CSV / Excel / Word / PDF) — always under the client's recorded consent; nothing is fetched from outside
→
2
Clean & standardise
OCR, ticker/name normalisation, FX conversion, dedup — inside the deployment boundary
→
3
Store
Encrypted single-tenant database, Singapore region or your own server
→
4
Analyse & report
Dashboards, reports, and checks computed in place — data does not move to be analysed
→
5
Share
Only user-initiated exports and consent-gated flows ever leave — each one audit-logged
Where data is stored
Single-tenant by design — on-premise the book never leaves the firm’s own machineOn-prem; trial is shared
Encryption at rest — AES-256Enabled
Encryption in transit — TLS 1.3Enabled
Data residency — on-premise has no egress at all; the hosted trial runs in the Singapore region, though AI features still reach the model provider abroadSG region · AI egress
Row-level security keyed on entity_id (tenant isolation inside the firm)Not in this build
Encrypted backups, same jurisdiction as primaryNot in this build
Uploaded documents (statements, KYC, term sheets) — same encrypted store, never a third-party file serviceIn boundary
Who can access what
Role-based access control — Originator / Compliance / MLRO / read-only (live in this demo; switch via "Acting as")Enforced
Maker-checker segregation — no one can originate and approve the same clientEnforced
Multi-factor authentication — TOTP on the on-premise build; the browser demo has no loginOn-premise build only
Every view, change, and export written to a hash-chained audit logAlways on
Client-facing access (roadmap) — separate login, scoped to that client's own bookPlanned
Vendor engineers on client-hosted deploymentsNo access
Vendor engineers on vendor-hosted deploymentsAudited break-glass only
What leaves the platform — and what never does
Outbound flow
Trigger
What is sent
Safeguard
AI agent connector (optional, off by default)
Admin-enabled, read-only
Compliance projection of the book (raw watchlist excluded) — served locally to a client-hosted AI agent
Local loopback + per-session token; read-only; every call audited; the product itself makes no outbound call
Reports (PDF/CSV)
User-initiated
Only the sections the user selects
Versioned, watermarked, export recorded in audit log
Everything else
—
Nothing
No telemetry, no third-party analytics, no advertising SDKs, client data never used to train AI models
Retention & deletion
Client, transaction & CDD records — statutory minimum per SFA 2001 s102(3) and MAS Notice SFA04-N02 §11≥5 years
Firm retention policy — configurable above the statutory floorConfigurable
Audit log — immutable, same retention clockImmutable
Offboarding — full structured export to the firm, then cryptographic erasure within 30 daysContractual
PDPA retention limitation — personal data not kept once purpose ceases and retention period lapsesPolicy
Consent & PDPA
Consent registry — every statement import tied to a recorded, dated client consentGates imports
Purpose limitation — data used only for reporting, analysis & compliance the client signed up forPolicy
Transfer limitation — personal data leaves Singapore only with comparable protection in placePDPA s26
Data breach response — assess, contain, notify PDPC within 3 calendar days of assessing a breach notifiableRunbook
Data Protection Officer — named per deployment, contact published to clientsNamed
Deployment models & vendor access
Model
Where data lives
Vendor access to client data
Best for
On-premise
Your own server (e.g. office hardware)
None
Maximum control; MAS outsourcing posture simplest
Client cloud
Your AWS / Azure account, Singapore region
None
Control with managed infrastructure
Vendor cloud
Dedicated single-tenant environment, Singapore region
Audited break-glass only
Fastest start; full client audit rights contractually
In every model the firm can demand logs, run security reviews, and exit with a full data export — the audit/access/exit rights MAS expects a regulated firm to hold over its service providers.
Regulatory alignment
Summary view — the detailed control-by-control mapping lives in Risk & compliance → MAS readiness map. A discussion aid for due diligence, not a legal opinion.
Why this is safe — the one-minute version
Your data stays inside a boundary you choose — your server, your cloud, or a dedicated Singapore tenant. Nothing streams to the vendor.
Nothing leaves that boundary except what a named user deliberately exports — and every such event is audit-logged. (An optional, off-by-default AI-agent connector lets a client-hosted agent read the book locally and read-only; it, too, is audited.)
Every custodian feed is tied to a client's recorded consent; no consent, no feed.
Storage is encrypted and access is role-based; the on-premise build adds a real login with MFA. Every action is written to a hash-chained audit log — the trail a regulator or auditor asks for already exists.
Retention follows the MAS statutory floor and your firm's policy; when you leave, you take a full export and the rest is cryptographically erased.
The platform tracks the rules it operates under — 13O/13U criteria, AML/KYC monitoring, consent, and third-party expectations — in the product itself, so compliance evidence is a screenshot, not a spreadsheet hunt.
Demo build. Control attestations, certifications (SOC 2 / ISO 27001 on roadmap), and the regulatory mapping are commitments for the production deployment — verify against the current MAS and PDPC texts and your internal policies during vendor due diligence.
Security & deployment
Singapore family offices are bound by the PDPA; client data should not leave the jurisdiction without control. Deployment and security posture for procurement / IT sign-off.
Certification timelines and control attestations are commitments for the production build, shown here for the procurement conversation — not yet independently audited in this demo.
Illustrates the data-cleaning rule engine against a sample extracted from the latest imported statement.
Raw OCR extraction
Ticker
Name
Date
Cost basis
Source
Cleaned & standardized
Ticker
Name
Date
Cost basis
Rule applied
Audit log
Immutable audit trail — every insert, update, export, and view recorded with actor, timestamp, and reason. Retained at least 5 years per SFA s102(3) / MAS Notice SFA04-N02 (7-year firm default).