Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

EU vs SECO: Apparent-violation assessment: what businesses miss

A trading company based in an EU member state discovers, during a routine internal review, that a payment processed six months earlier may have passed through a correspondent account linked to a listed entity. The finance team flags it. Legal is called. The immediate question is not whether a breach occurred – it is how to assess the apparent violation, decide what to disclose, and manage the exposure before the regulator acts first. That question is different in Brussels than it is in Bern, and the difference can be decisive.

An apparent-violation assessment (the structured legal and factual analysis a business undertakes when it identifies a transaction that may breach sanctions rules) triggers distinct obligations and carries distinct risks under the EU regime and under Switzerland's SECO (State Secretariat for Economic Affairs, the Swiss sanctions authority). As of March 2026, the EU operates through directly applicable Council Regulations enforced by member-state competent authorities, while SECO administers Switzerland's autonomous sanctions ordinances as a single federal authority. The procedural gap between the two is significant, and businesses caught between them face asymmetric disclosure obligations.

This analysis maps the two regimes side by side, identifies the points of divergence that practitioners most often underestimate, and sets out the practical steps a cross-border business should take when an apparent violation surfaces.

How does the EU apparent-violation regime work?

Under the EU regime, the legal basis for sanctions prohibitions sits in Council Regulations that are directly applicable across all member states, but enforcement is delegated to national competent authorities. That structure creates an immediate complexity for any apparent-violation assessment: the substantive rule is uniform, but the enforcement posture, reporting expectations, and penalty frameworks differ by member state.

There is no single EU-wide obligation to report an apparent violation to a central authority. Some member-state competent authorities publish explicit guidance inviting or requiring notification. Others operate on a less formalised basis, where a voluntary disclosure may mitigate a penalty without being formally required by the applicable national instrument. In our cross-border practice, the first question we put to a client who identifies a potential EU breach is: which member state or states have jurisdiction, and what does the relevant competent authority expect?

The assessment itself follows a recognisable pattern. The business must first establish the factual matrix – the parties to the transaction, the goods or services, the payment flows, the dates, and the listed-entity connection. It must then map those facts to the applicable Council Regulation and determine whether a prohibition was engaged. If it was, the next question is whether an exception, derogation, or prior authorisation applied. Only once that analysis is complete can the business assess the severity of the potential breach, the mitigating factors available to it, and the disclosure calculus.

The position above covers the standard analysis. Your facts – the counterparty, the relevant Council Regulation, the member-state authority with jurisdiction, and the goods or funds involved – change the risk profile materially. For a structured assessment of your EU exposure, contact Calder & Vance at info@caldervance.com.

How does SECO approach the same assessment?

Switzerland's approach is structurally simpler but operationally distinct. SECO administers Switzerland's sanctions ordinances as a single federal authority, acting under the embargo legislation that implements both UN Security Council measures and Switzerland's own autonomous sanctions measures. There is no devolution to cantonal enforcement bodies for financial sanctions.

The single-authority structure means that a business assessing an apparent SECO violation deals with one regulator. The factual and legal analysis is similar to the EU model – identify the transaction, map it to the applicable ordinance, determine whether a prohibition was engaged, and assess the availability of any exemption or authorisation. But the downstream disclosure question is handled within a single institutional setting, which can simplify the coordination burden for businesses whose transactions touched Switzerland as a financial centre or transit jurisdiction.

Switzerland's autonomous sanctions are not identical to the EU's. The measures under the applicable ordinances follow EU designations closely in many programmes, but the timing of alignments, the scope of exemptions, and the penalty regime under Swiss criminal law differ from the EU position. A transaction that is fully exempted under an EU Council Regulation may not carry an equivalent Swiss exemption, or vice versa. We regularly advise clients who assume that EU and Swiss compliance positions are interchangeable – they are not, and the discrepancies are precisely where apparent violations arise.

Where do the regimes diverge on apparent-violation assessment?

The most consequential divergences sit in four areas: the authority structure, the disclosure obligation, the aggravating and mitigating factor analysis, and the interaction with criminal liability.

Authority structure. The EU's fragmented enforcement model means that a single transaction touching two member states may attract the attention of two competent authorities with different investigative cultures. Switzerland's single-authority model avoids that multiplicity but concentrates risk in SECO's hands. A business that self-discloses to one EU member-state authority should consider whether a parallel disclosure to another is necessary – an analysis that has no Swiss equivalent.

Disclosure obligations. Certain EU member states have formalised reporting requirements for apparent violations, particularly in the financial sector. SECO's regime does not operate on the same basis. The practical implication is that a financial institution subject to both EU and Swiss obligations must run two separate disclosure analyses, each against its own standard, without assuming that a disclosure to one satisfies the other.

Mitigating factors. Both regimes give weight to voluntary disclosure, the existence of a compliance programme, and the speed of remediation. But the weight assigned to each factor, and the procedural route for presenting mitigating evidence, differs. Under the EU framework, practice varies by member-state authority. SECO applies its own assessment criteria under Swiss administrative and criminal law, which place particular emphasis on cooperation and on whether the business had adequate internal controls at the time of the breach.

Criminal liability. Swiss sanctions law has a criminal enforcement dimension that operates alongside administrative measures. Depending on the gravity of the apparent violation, SECO may refer a matter to the federal prosecuting authorities. EU member-state regimes vary on criminalisation – some treat serious sanctions breaches as criminal offences, others as administrative. The apparent-violation assessment for a SECO matter must therefore include a preliminary criminal-law review at an earlier stage than a purely administrative EU matter might require.

Which regime is stricter on apparent-violation assessment?

The question of relative strictness is more nuanced than it first appears. Strictness in a sanctions enforcement context can mean the size of financial penalties, the speed of investigation, the likelihood of criminal referral, or the degree of procedural formality. No single metric captures all of them.

The EU regime is, in aggregate, capable of imposing severe financial penalties – and the highest penalties have come from member states with the most active enforcement cultures. But the fragmented structure means that outcomes are variable. A business assessed by a less active competent authority may face a different penalty exposure than the same business assessed by a member state with a well-resourced sanctions enforcement unit.

SECO's criminal-law dimension makes it distinctly serious for individuals within the business. A Swiss criminal referral can result in personal liability for the officers or employees who authorised or processed the offending transaction. That risk sits at a different point on the severity scale than a corporate administrative fine, and it concentrates minds in a way that a civil penalty notice may not. In our experience, businesses that have previously managed EU enforcement matters sometimes underestimate the personal-liability dimension of a SECO matter until it is explicitly raised in the assessment process.

The honest answer is that neither regime is categorically stricter across all dimensions. The EU can impose larger corporate penalties in high-value cases. Switzerland can impose personal criminal liability more directly. A cross-border business should not rank them – it should assess each on its own terms, in parallel, and not defer the Swiss analysis because it appears procedurally simpler.

If a transaction has already been flagged, or an internal review has surfaced a potential breach, an early parallel assessment preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.

What does the apparent-violation assessment process look like in practice?

A well-structured apparent-violation assessment is not a checklist exercise. It is a sequenced analytical process that moves from fact-gathering, through legal mapping, to a disclosure and remediation decision. The sequence matters because decisions taken early – particularly any communications with the counterparty or the correspondent bank – can affect the assessment's credibility with the regulator.

The first phase is containment and documentation. The business should preserve all transaction records, communications, and screening outputs relating to the apparent violation. Nothing should be deleted or amended. The legal team should be instructed before any external communication about the transaction. This phase is common to both the EU and SECO assessments, but it is where the most costly mistakes occur: a well-intentioned email to the counterparty explaining the issue can look very different to an enforcement officer reviewing it six months later.

The second phase is legal and factual analysis. Counsel maps the transaction to the applicable Council Regulation (EU) or applicable ordinance (SECO), identifies the prohibition or prohibitions potentially engaged, and assesses the availability of any exception or derogation. This is also the phase at which the ownership-and-control question is resolved: was the listed entity directly a party, or was it a controlling or owning person behind a non-listed entity? The answer affects both the legal characterisation of the apparent violation and the evidence that must be gathered.

The third phase is the disclosure decision. For an EU apparent violation, the decision turns on the member-state authority's expectations, the regulatory sector of the business, and the availability of mitigating factors. For a SECO matter, the decision includes a preliminary assessment of criminal-law risk. In a cross-border matter touching both regimes, the disclosure decisions must be coordinated – not because a single disclosure satisfies both, but because inconsistent disclosures to different authorities raise credibility problems that an experienced enforcement officer will identify.

In a recent matter, a financial services firm identified a historical payment that appeared to have reached a correspondent account connected to a designated entity under both the applicable EU Council Regulation and the equivalent Swiss ordinance. We conducted a parallel factual and legal analysis under both regimes, assessed the disclosure obligations separately for the member-state authority with jurisdiction and for SECO, and coordinated the submissions so that the factual narrative was consistent across both proceedings. The matter concluded without criminal referral by SECO and with a reduced administrative measure under the EU framework, on the basis of the voluntary disclosure and the documented compliance-programme improvements. No outcome of this kind can be guaranteed; each case turns on its own facts.

What risk flags do businesses most often miss?

Several risk factors recur in the matters we handle, and they are worth addressing directly because they are systematically underweighted in initial internal assessments.

Correspondent-banking exposure. A payment that the business believes it made to a clean counterparty may still have passed through a chain of correspondent accounts that included a blocked or listed entity. This is an EU and SECO issue equally. The business that processed the payment may have an apparent violation even if its direct counterparty was not listed. Screening the direct counterparty is necessary but not sufficient.

Multi-jurisdictional delay. A business that identifies an apparent EU violation and begins the EU assessment process often defers the SECO analysis on the basis that Switzerland is "not the main jurisdiction". That deferral can cause the business to miss SECO's own expectations for timely engagement – expectations that, while less formalised than some EU member-state requirements, are nonetheless real and taken into account in any subsequent assessment of the business's cooperation.

The compliance-programme defence. Both regimes treat the existence of an adequate compliance programme as a mitigating factor. But "adequate" is assessed at the time of the apparent violation, not at the time of the disclosure. A business that upgrades its screening programme after identifying the apparent violation cannot rely on the upgraded programme to mitigate the historic breach. The assessment must honestly characterise the state of the programme at the relevant time.

Aggravating factors. Repetition, concealment, and the involvement of senior management are aggravating factors under both regimes. The apparent-violation assessment must identify whether any of these factors are present, because they affect both the disclosure strategy and the penalty exposure. We have acted for businesses that initially assessed a matter as a minor administrative issue and then discovered, during the evidence-gathering phase, that a pattern of similar transactions existed across a longer period. That discovery changes the legal and strategic position significantly.

Finally: the myth that SECO "follows" the EU automatically. It does not. Switzerland aligns its autonomous measures with EU designations in many programmes, but the process takes time and is not automatic. A listed entity under an EU Council Regulation may not yet be listed under the applicable Swiss ordinance on the date of the transaction in question, or vice versa. The apparent-violation assessment must be conducted against the applicable law on the relevant transaction dates, not the current consolidated position of either regime.

When should a business involve external sanctions counsel?

The short answer is: earlier than most businesses do. The apparent-violation assessment process generates legal analysis, factual findings, and strategic decisions about disclosure that can all be relevant to a subsequent enforcement proceeding. If that analysis is conducted without legal privilege, it may be disclosable to the regulator in circumstances where a privileged document would not be. External counsel involvement from the outset is not a cost centre; it is a structural protection for the assessment itself.

The more specific answer is that external counsel should be involved at the point at which the business identifies a transaction that might constitute a breach – before the factual investigation goes beyond initial document preservation, before any communication with the counterparty about the issue, and before any contact with the regulator. These are the moments at which the business's position can be most effectively protected and the options most effectively preserved.

Does your business have a clear protocol for the moment a compliance officer flags a potential apparent violation? In our experience, the businesses that manage these matters most effectively are those that have pre-agreed the first ten steps before the situation arises. Those that begin the assessment process by improvising – however competently – tend to find that some of those early steps created complications that a structured protocol would have avoided.

For a cross-border business with exposure to both EU and Swiss sanctions, the cross-regime coordination is a specific skill set. The EU analysis must be managed against the member-state authority with jurisdiction; the SECO analysis must be managed in parallel, at the same pace, with a consistent factual record. Calder & Vance regularly handles matters where both dimensions are live simultaneously. We assess eligibility for voluntary disclosure, prepare coordinated submissions to the relevant authorities, and manage the regulator's queries across both regimes.

Related practices

Frequently asked questions

Where do the regimes diverge on apparent-violation assessment?
The EU and SECO regimes diverge most sharply on authority structure, disclosure obligations, and criminal-liability risk. The EU delegates enforcement to member-state competent authorities, creating variable practice across the single-market area. SECO operates as a single federal authority, but its regime includes a direct criminal-law dimension that the EU administrative framework does not replicate uniformly. A cross-border assessment must treat each regime as analytically separate and avoid assuming that compliance with one satisfies the other.
Which regime is stricter on apparent-violation assessment?
Neither regime is categorically stricter across all dimensions. The EU can impose significant corporate penalties through national competent authorities, with the highest penalties arising in member states with active enforcement cultures. SECO can impose personal criminal liability on individuals within the business, which represents a qualitatively different order of risk. Businesses should not rank the regimes by severity; they should assess each on its own terms, in parallel, and with qualified counsel engaged from the outset of the assessment process.
What should a cross-border business do about apparent-violation assessment?
A cross-border business exposed to both EU and SECO sanctions should take three immediate steps when a potential apparent violation is identified: preserve all transaction documentation without alteration, instruct legal counsel before any external communication about the issue, and begin a parallel factual and legal analysis against the applicable rules of each regime as they stood on the transaction dates. Disclosure decisions for each regime must be coordinated, not duplicated, to maintain a consistent factual record across all proceedings.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.