A trading company with operations in both the European Union and Switzerland processes a payment instruction. The counterparty's beneficial owner appears on a watchlist. Both the EU and SECO – Switzerland's State Secretariat for Economic Affairs – may have a view on the transaction. Each regime has its own process for determining whether a potential violation exists, how it is assessed, and what happens next. Getting the analysis wrong under either regime carries material consequences.
An apparent-violation assessment (the structured internal or regulatory process for determining whether a transaction or activity may have breached a sanctions prohibition) differs meaningfully between EU member-state enforcement and SECO's autonomous Swiss regime. As of March 2026, the EU relies on member-state competent authorities applying Council regulations uniformly in theory but divergently in practice; SECO applies Switzerland's own ordinances under a single federal authority. The key divergences lie in the governing legal basis, the aggravating and mitigating factors used to evaluate severity, the reporting and disclosure expectations, and the ultimate consequences for the business.
This analysis maps those divergences criterion by criterion, identifies the risk flags that arise when both regimes are in play, and explains when cross-border counsel is warranted.
What is an apparent-violation assessment, and why does it matter for cross-border businesses?
An apparent-violation assessment is the structured process – whether conducted internally by a compliance team or initiated by a regulator – of determining whether a completed or in-progress transaction or activity appears to have breached a sanctions prohibition. It is not a finding of guilt; it is the analytical gateway that precedes any decision about disclosure, remediation, or enforcement response.
For a business operating across the EU and Switzerland, the assessment matters because both regimes may have a claim on the same set of facts. A payment routed through a Swiss bank to a counterparty in an EU member state, involving a person on both the EU Consolidated List (the EU's centralised list of designated persons subject to asset freezes and economic prohibitions) and Switzerland's SECO ordinance list, can trigger parallel assessment obligations. The two regimes do not coordinate their enforcement calendars, and a disclosure timed correctly for one authority may create exposure under the other.
In our cross-border practice, this is one of the most consistently underestimated risks for mid-sized multinationals. They run the apparent-violation analysis for one regime and assume the result carries across. It does not.
Governing legal basis: Council regulations versus SECO ordinances
The EU's sanctions regime is grounded in Council regulations (directly applicable EU law that confers obligations on natural and legal persons within the EU's territorial and jurisdictional reach) and their accompanying Council decisions. The regulations are uniform across all member states in their text; enforcement, however, is delegated to each member state's competent authority, and those authorities – whether in Paris, Amsterdam, Warsaw, or Vienna – apply differing administrative traditions, penalty scales, and prosecutorial discretion.
SECO, by contrast, administers Switzerland's autonomous sanctions regime under a series of federal ordinances that Switzerland enacts independently. Switzerland is not an EU member and does not automatically adopt EU Council regulations. Its ordinances substantially – but not identically – mirror EU-listed persons in practice for several major programmes, though the alignment is a policy choice renewed periodically, not a legal obligation. When the EU updates a designation and SECO's ordinance has not yet been amended, the gap creates a window in which the two regimes diverge on the designated-persons question itself.
The practical consequence for apparent-violation assessment is foundational: the legal instruments being assessed for breach are different documents. An act that clearly breaches an EU Council regulation may not yet be prohibited under the current SECO ordinance, and vice versa. Have you mapped which instrument governs each entity in your counterparty chain, or has your compliance team assumed equivalence?
How each regime identifies and evaluates the seriousness of an apparent violation
Under the EU regime, member-state competent authorities evaluate an apparent violation through a combination of factors drawn from the Council regulation itself and from the authority's own enforcement guidance. Severity factors commonly considered include: whether the violation was wilful or the result of negligence; the value and duration of the prohibited activity; the degree of senior-management involvement; and whether the business had a functioning compliance programme at the time. Mitigating factors – voluntary disclosure, prompt remediation, cooperation – are recognised in the enforcement guidance of several member-state authorities, though their formal weight varies significantly between jurisdictions.
SECO's assessment approach under Swiss federal law is administered by a single federal authority applying consistent criteria across Switzerland. SECO's framework examines the intent and knowledge of the person committing the act, the economic value of the transaction, and whether the act was isolated or systemic. Switzerland's criminal law tradition, which underlies sanctions enforcement in the Swiss context, gives greater formal weight to the mental-element question than some EU member-state administrative traditions do. An act committed without actual or constructive knowledge of the sanction may be assessed more leniently in the Swiss process than it would be in, for example, an EU jurisdiction with strict administrative-liability provisions that do not require intent.
In our experience, the intent question is the single most consequential divergence for businesses running a parallel assessment. A transaction processed by an operations team with no knowledge of the designation may produce very different assessments under the two regimes, and the internal investigation must be structured to address both tests.
The position above covers the standard case. Your facts – the counterparty, the goods involved, the route, the legal entities in the chain – change the analysis materially.
For an assessment of your exposure under the EU regime or under Switzerland's autonomous ordinances, contact Calder & Vance at info@caldervance.com.
Voluntary disclosure and self-reporting: divergent expectations and timelines
Voluntary disclosure – or VSD (a proactive report to a regulator of a potential violation discovered by the business itself, typically before the regulator becomes aware) – is treated very differently across the EU member states and by SECO, and that difference shapes how a parallel-regime apparent-violation assessment should be managed.
Across EU member states, the treatment of voluntary disclosure is not harmonised at the Council-regulation level. Several major member-state competent authorities have published guidance acknowledging VSD as a mitigating factor capable of producing a reduced penalty or a decision not to pursue formal proceedings. Others have no published policy at all, and the credit given to a disclosure is a matter of prosecutorial discretion applied case by case. This absence of harmonisation means that a business deciding whether to disclose to an EU authority must assess the specific authority in the member state with jurisdiction, not the EU regime as an undifferentiated whole. The timing of that disclosure – before or after the authority independently identifies the issue – consistently matters.
SECO's position on voluntary disclosure reflects Swiss administrative and criminal-law tradition. Switzerland recognises voluntary self-reporting as a factor that can reduce criminal or administrative consequences, and SECO has demonstrated a practice of treating early, complete disclosure as a meaningful mitigant. The expectation of completeness is high: a disclosure that later appears to have been partial or strategically framed tends to be treated as aggravating rather than mitigating.
The practical divergence for a cross-border business is one of sequencing and content. A disclosure made to a Swiss-German-corridor group simultaneously must satisfy SECO's expectation of full factual transparency while calibrating to the specific member-state authority's known posture on disclosure. These are not always compatible on the same document and the same timeline. Where both authorities have jurisdiction, we regularly advise clients to develop a parallel disclosure strategy rather than a single-document approach.
Record-keeping, cooperation obligations, and what the regulator expects to see
Both regimes impose record-keeping and cooperation obligations that shape how an apparent-violation file is assembled and presented. The content and format of what each authority expects to review differ in ways that matter when the same underlying transaction is being assessed by two regulators.
EU Council regulations require persons subject to the regulations to maintain documentation sufficient to demonstrate compliance. Member-state authorities typically expect, at minimum: evidence of the screening conducted at the time of the transaction; the ownership and control analysis performed on the counterparty; internal approval records; payment documentation; and any communications with the counterparty relevant to the sanctioned-person question. The depth of review expected varies by authority: some will request a narrow production; others will issue broad information requests requiring a reconstructed compliance chronology.
SECO expects substantively similar categories of documentation but within the context of Swiss administrative and criminal-law procedure. A formal SECO investigation may involve coordination with Swiss federal prosecutorial authorities under the criminal enforcement route. The procedural rights of the person under investigation in the Swiss context – including rights of access to the file and protections against self-incrimination in the criminal context – differ from the administrative procedure that governs most EU member-state enforcement actions. A cross-border business preparing its apparent-violation file must therefore structure document production so that disclosures made in the EU administrative process do not inadvertently compromise positions in a parallel Swiss criminal enquiry, or vice versa.
This is where the question of legal professional privilege and the confidentiality of the internal investigation becomes acute. If a transaction has already been flagged, or a filing has been refused, an early review of your documentation posture can preserve options that narrow with time.
Contact Calder & Vance at info@caldervance.com for a confidential review of how a parallel-regime investigation should be structured.
Penalty architecture and enforcement posture: EU member states versus SECO
The consequences of an adverse apparent-violation assessment differ in structure between the EU regime and the Swiss regime, and understanding those differences matters before a business decides how to respond to either authority.
Within the EU, penalties for sanctions violations are set at the member-state level; there is no single EU-wide penalty scale. The result is a wide range: some member states impose administrative penalties on a per-transaction or per-day basis; others proceed criminally for the most serious breaches. The presence or absence of a functioning compliance programme, the size and financial strength of the entity, and the degree of voluntary cooperation are factored into penalty determinations across most major jurisdictions, but the formal weighting each authority applies differs. A business with operations in multiple EU member states faces the theoretical possibility of parallel enforcement proceedings in more than one jurisdiction for the same underlying conduct if multiple member-state competent authorities assert jurisdiction.
SECO's enforcement posture follows Swiss law, which distinguishes between administrative measures and criminal penalties. Administrative measures – including asset freeze enforcement, information orders, and transaction prohibitions – are applied by SECO directly. Criminal sanctions, where the threshold is met, are referred to the competent Swiss federal prosecutorial authority. The criminal threshold in Swiss law is set by the applicable ordinance and by general Swiss criminal provisions, and it can be met by corporate entities as well as individuals where the necessary conditions are satisfied.
The divergence that matters most in practice is the jurisdictional aggregation risk. A transaction that produces a minor administrative matter in one EU member state may simultaneously trigger a criminal referral in Switzerland if the Swiss-law mental-element threshold is met. A coordinated apparent-violation assessment strategy must account for this asymmetry from the outset, rather than treating each jurisdiction's response as an independent problem.
The ownership-and-control question: where the regimes diverge in application
An apparent-violation assessment often turns, upstream, on whether the counterparty or beneficial owner was in fact designated at the time of the transaction. Both regimes apply an ownership and control test (the analysis of whether a non-listed entity is caught through a listed person's ownership or controlling influence over it), but the tests differ at the margin in ways that affect whether a violation exists at all.
The EU's approach to ownership and control under Council regulations requires an assessment of both direct and indirect ownership holdings and the exercise of control through non-ownership means – board dominance, contractual control, power to direct commercial policy. EU guidance documents issued by the European Commission provide a framework, but the application by individual competent authorities and, ultimately, by the EU General Court, has produced a body of practice that continues to develop. Where a non-listed entity is owned less than fifty percent by a listed person but is controlled through other means, the question of whether an EU asset-freeze obligation applied is frequently the crux of the apparent-violation analysis.
SECO's ordinances apply a similar ownership and control concept, but the Swiss legal framework for determining what constitutes control under federal law draws on Swiss corporate and contract law rather than EU law. The result is that the same shareholding structure may be assessed differently by SECO and by an EU member-state authority. A listed person owning forty-five percent of a target entity with a right to appoint a majority of the board may be found to exercise control under EU practice while the Swiss assessment reaches a different conclusion based on the specific ordinance and Swiss corporate-law analysis.
In our experience, the ownership and control question is where parallel apparent-violation assessments most often diverge in result, not just in procedure. A business that has concluded, on EU analysis, that no blocking obligation applied at the time of the transaction cannot assume that SECO will reach the same conclusion on the same facts.
Common risk flags and when to involve counsel
Several patterns consistently signal that an apparent-violation assessment requires immediate external input, particularly where both EU and SECO obligations are in play.
First, any transaction in which the designated-person question itself is in doubt – because of a temporal gap between an EU designation and the SECO ordinance amendment, or because of a complex layered ownership structure – requires legal analysis before the business decides how to characterise the potential violation to either authority. A self-assessment that understates the scope of the potential breach is not a neutral act; it becomes an aggravating factor if the authority later establishes a broader violation.
Second, transactions involving dual-use goods or technology add an export-control dimension that runs parallel to the financial-sanctions apparent-violation question. Where the EU's dual-use rules and Swiss export-control provisions are both in scope, the apparent-violation file must address both sets of obligations, and the relevant authorities – EU member-state export-control bodies and SECO in its export-control capacity – may be different from the financial-sanctions enforcement bodies. Does your current internal assessment process separate these two tracks, or does it treat them as a single compliance question?
Third, where senior management or board members were involved in or aware of the transaction at the time, the personal liability dimension under both regimes becomes material. Several EU member states permit enforcement proceedings against individual directors and officers as well as the corporate entity. Swiss law equally permits proceedings against individuals in appropriate cases. A corporate-level apparent-violation assessment that does not address personal liability risk from the outset leaves both the business and its people underprotected.
Fourth, group structures with entities in multiple EU member states and Switzerland face the compounded risk of parallel proceedings. A transaction involving a Swiss parent, a German subsidiary, and a payment processed through a French bank could engage Swiss federal enforcement, German competent-authority proceedings, and French supervisory review simultaneously. Each proceeding has its own disclosure expectations and its own timeline.
The myth that a single assessment addressing the "primary" regime is sufficient for a cross-border business is persistent and costly. Sanctions obligations do not defer to each other. Where the EU and SECO both have a plausible claim on a set of facts, each regime must be assessed on its own terms and the positions coordinated deliberately.
Related practices
- Apparent-violation assessment – EU enforcement service – legal assessment, disclosure strategy, and enforcement defence under EU Council regulations
- EU vs SECO apparent-violation assessment – further analysis – deeper comparative treatment of procedural divergences and disclosure sequencing
- OFAC vs Canada: apparent-violation assessment compared – comparative analysis for businesses with North American and EU exposure