Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

EU vs SECO: Compliance audit and testing: what businesses miss

A mid-sized Swiss trading house operating through a Brussels subsidiary runs its quarterly counterparty screen. The EU list and the SECO list return different results for the same entity. One regime flags it; the other does not. The compliance team is unsure which list governs, which test applies, and whether the internal audit log is sufficient if a regulator asks. These are not edge cases. In our cross-border practice, this scenario – or a close variant – arises in almost every multi-regime compliance engagement we handle.

EU compliance audit and testing (the structured process of verifying that a sanctions compliance programme reliably identifies, escalates, and documents potential breaches) operates under Council regulations administered by competent authorities in each member state. Swiss law under the State Secretariat for Economic Affairs (SECO) establishes a parallel regime with its own list, ownership test, and enforcement posture. The two regimes share broad policy objectives but diverge materially on the ownership-and-control test, licensing architecture, record-keeping obligations, and audit trigger events. As of July 2026, the gap between them is wide enough to require separate audit tracks for businesses subject to both.

This analysis maps the divergence criterion by criterion, identifies the compliance failures we see most often in cross-regime engagements, and sets out the practical audit steps that close the gap.

Why the EU and SECO regimes are not interchangeable

The EU sanctions regime and the SECO regime both draw on UN Security Council Consolidated List designations as a baseline, but each adds its own autonomous measures. That means a counterparty can be listed under one regime and not the other – and a compliance audit that treats the two as identical will miss exactly those asymmetric designations. Businesses subject to both regimes must screen against both lists in every counterparty check.

The legal basis also differs structurally. EU autonomous sanctions rest on Council regulations that have direct effect in all member states without transposition. SECO sanctions are issued as federal ordinances under Swiss domestic law. The difference matters for audit purposes: under the EU regime, a competent authority in the member state where the business is established takes the lead on enforcement. Under SECO, enforcement is centralised. An audit that maps only one enforcement contact point will be incomplete for the other regime.

In our experience advising businesses with operations on both sides of the Swiss–EU border, the single most common structural failure in compliance programmes is a unified "EU + SECO" screening configuration that treats the two lists as a single combined source. They are not. List update cycles, designation criteria, and delisting procedures differ. An audit that does not separately verify the currency and completeness of each feed will carry a latent false-negative risk.

How do the ownership-and-control tests compare?

The ownership-and-control test is the most consequential point of divergence between the two regimes, and it is where compliance audits most often surface hidden gaps. Under EU Council regulations, a non-listed entity is caught when a listed person owns or controls it: ownership at 50 percent or more triggers an automatic block, and control through other means – board composition, contractual dominance, veto rights – can extend the net further. SECO applies a broadly similar ownership threshold but the control analysis under Swiss federal ordinances is applied by SECO on a case-by-case basis and the published guidance is less developed than the EU position.

That asymmetry creates a specific audit risk. A company might pass the EU control test and fail the SECO test, or vice versa. An audit that applies only the EU five-factor ownership analysis to a Swiss-incorporated counterparty will not satisfy SECO's standard. Conversely, a SECO-only threshold check will not capture the full range of control indicators that EU competent authorities examine.

What should a compliance audit actually test here? It should verify: (a) that the screening tool applies the correct legal standard for each regime separately; (b) that the ownership-chain mapping extends to the requisite depth under each standard; (c) that the escalation procedure distinguishes between an EU-only hit, a SECO-only hit, and a concurrent hit; and (d) that the case file documents which test was applied and why the outcome was reached. We regularly advise clients that items (c) and (d) are almost universally absent from audit documentation in the first review.

Record-keeping obligations – where audit trails break down

Record-keeping obligations under the EU regime require businesses to retain documentation related to frozen assets, refused transactions, and licensing decisions for a defined period – and EU competent authorities can and do request production of that documentation during supervisory reviews. The precise retention period is set by the relevant thematic regulations and may vary by programme, but practitioners advising on EU matters should treat five years as the working standard where programme-specific rules do not specify otherwise, and verify the current position before relying on it.

SECO imposes its own retention obligations under Swiss ordinances, and the periods and scope differ from the EU standard. In a compliance audit covering both regimes, a single record-keeping policy that is calibrated to one regime will almost certainly be non-compliant with the other.

The practical audit test is straightforward: for each category of records – screening results, escalation decisions, licensing correspondence, frozen-asset notifications, and transaction refusals – the audit should confirm that the retention period applied meets the longer of the two regime standards. Where the business cannot confirm which regime's standard is longer for a given category, the safe default is to apply the more demanding obligation until verified.

A second and equally common failure is metadata. Regulators reviewing an audit trail want to see not only that a screen was run, but when it was run, which list version was in use, who approved the outcome, and what the escalation path was. Compliance programmes that generate a screening log but do not capture list version and approver identity will struggle to demonstrate effective testing in a supervisory review.

Licensing architecture and the gap it creates in audit design

EU specific licences (case-by-case authorisations to conduct an otherwise prohibited transaction) are issued by competent authorities in the relevant member state, not by an EU-level body. That means a business with operations in multiple member states may hold licences from different national authorities for related transactions, each with its own conditions. A compliance audit must map all active licences, the authority that issued each, the conditions attached, and the monitoring obligation the business has accepted.

SECO issues authorisations centrally through a federal licensing process. The audit architecture for SECO licences is therefore simpler in structure but different in kind. An audit that applies the EU multi-authority mapping exercise to a SECO licence will overcomplicate the wrong question and potentially miss the right one: whether the business is complying with SECO's specific conditions and reporting obligations under that licence.

The position above covers the standard licensing audit. Your facts – the counterparty, the transaction type, the member states involved, and whether a SECO authorisation is in parallel – change the analysis significantly. To discuss a cross-regime licensing review, contact Calder & Vance at info@caldervance.com.

A further audit requirement that is often overlooked: the interaction between an EU licence and a SECO licence for the same underlying transaction. The two authorisations are legally independent. A business that holds one but not the other is not authorised under the regime for which the licence is missing. Audit programmes should include a transaction-level cross-check that confirms authorisation status under every regime that applies to that specific transaction.

What does a cross-regime compliance audit actually test?

A well-constructed compliance audit covering both the EU and SECO regimes tests seven distinct elements, each against the applicable standard for that regime. Working through each in turn is more useful than a generic programme review.

First: list completeness and currency. The audit verifies that the screening tool draws from the correct and current EU consolidated list and the correct and current SECO list as separate feeds, and that the update cycle for each meets the refresh standard set by the relevant regime.

Second: ownership and control logic. The audit tests whether the tool and the analyst process apply the EU ownership-and-control standard to EU-nexus counterparties and the SECO standard to Swiss-nexus counterparties, without conflating them.

Third: escalation procedures. The audit reviews whether escalation triggers are calibrated to each regime. A SECO-only hit should not automatically generate an EU frozen-asset notification, and an EU hit should not be resolved by reference to a SECO licence.

Fourth: licensing and authorisation mapping. The audit confirms that all active licences are catalogued, that compliance with conditions is monitored, and that no licence has expired without renewal.

Fifth: record-keeping. The audit verifies retention periods, metadata capture, and the completeness of the audit trail for each category of record under each regime.

Sixth: training and awareness. The audit tests whether staff responsible for sanctions decisions have current knowledge of both regimes, including the points of divergence identified in this analysis.

Seventh: testing frequency and methodology. The audit confirms whether the programme uses transaction testing, scenario testing, or both – and whether the testing methodology is appropriate to the risk profile of the business.

If a filing has already been refused, or a supervisory enquiry has been received, an early review of the audit trail can preserve options that narrow quickly. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.

Common risk flags: what businesses miss and why

Six failure patterns account for the large majority of compliance audit findings we see in EU–SECO cross-regime engagements. Naming them precisely is more useful than a generic risk description.

Unified list feeds. As discussed, treating EU and SECO lists as a single combined source. The fix is a documented dual-feed architecture with separate update-verification logs.

Single-standard ownership analysis. Applying only the EU ownership test to Swiss-incorporated counterparties, or the reverse. The fix is a jurisdiction-of-incorporation trigger that routes counterparties to the correct regime's analysis.

Missing SECO notifications. Under the Swiss regime, certain transactions and asset-freezing events carry reporting obligations to SECO. Businesses that are well-practised in notifying EU competent authorities sometimes have no equivalent SECO notification workflow. An audit should specifically test whether the notification trigger exists and whether it has been activated correctly in recent transactions.

Licence-condition monitoring. Holding a licence is not the same as complying with it. Both the EU regime and SECO impose conditions on authorisations – reporting requirements, permitted use restrictions, end-use undertakings. Audit programmes that log the licence but do not monitor the conditions will produce a misleading clean result.

Extraterritorial blind spots. The EU regime has a broader extraterritorial dimension than is sometimes appreciated. Businesses outside the EU that process EU-currency transactions, use EU-incorporated subsidiaries, or route payments through EU correspondent banks may have EU sanctions exposure that their SECO-focused programme does not capture. A compliance audit covering only the Swiss entity in a group structure will miss the EU exposure at the subsidiary level. This is the cross-border angle that most often surprises compliance teams when we raise it.

Inadequate scenario testing. Many compliance programmes run name-matching screens but do not scenario-test the escalation and decision procedure. The question "what would happen if a positive match arrived at 17:30 on a Friday?" is not rhetorical. Regulators reviewing enforcement cases often focus precisely on the decision-making process in difficult conditions. An audit should replicate that pressure to expose procedural weaknesses.

When to involve counsel – and what that engagement looks like

The myth we encounter most regularly in this area is that a compliance audit is an internal exercise, and that external counsel is only relevant once a regulator is already involved. That view is mistaken in two distinct ways.

First, a well-structured compliance audit carried out with external sanctions counsel in advance of a supervisory review produces a documented record of good-faith effort. That record is directly relevant to how regulators assess culpability and penalty level if a breach is later identified. An internal audit that surfaces a problem and corrects it before regulatory contact is the best outcome available; an internal audit that misses a problem that a regulator then finds is considerably worse.

Second, the divergence between the EU and SECO regimes on the questions analysed above – ownership tests, record-keeping periods, licensing architecture, notification obligations – is a legal question, not purely a process question. Compliance officers are well-positioned to run a screen; they are less well-positioned to advise on whether a particular control structure satisfies the SECO control test or whether an EU licence condition has been complied with. That is the legal analysis that external counsel provides.

In a recent matter, a financial-services business operating in both Switzerland and the EU asked us to review its compliance programme following an internal concern about the ownership analysis applied to a counterparty group. We mapped the ownership chain, applied the EU and SECO control tests separately, identified a control nexus that the programme's automated logic had not flagged, and advised on the steps needed to document the analysis and correct the programme. The matter was resolved without regulatory contact. That outcome is not guaranteed in any engagement, but early involvement consistently improves the range of options available.

Counsel should be involved at four specific points: (1) when designing the audit methodology for a cross-regime programme for the first time; (2) when the audit surfaces a potential historic breach or a gap in the notification record; (3) when a regulator makes a supervisory enquiry or requests documentation; and (4) when a corporate event – an acquisition, a restructuring, or a new market entry – creates a new regime nexus that the existing programme was not designed to cover.

Related practices

Frequently asked questions

Where do the regimes diverge on compliance audit and testing?
The EU and SECO regimes diverge most materially on four points: the ownership-and-control test (the EU applies a detailed multi-factor control analysis; SECO's published guidance is less developed), the licensing architecture (EU licences are issued by national competent authorities in each member state; SECO issues centrally), record-keeping periods (which differ between the regimes and must be verified separately for each programme), and the scope of notification obligations for asset-freezing events. An audit that does not separately test each regime against its own standard will produce an incomplete result.
Which regime is stricter on compliance audit and testing?
Neither regime is uniformly stricter than the other. The EU regime has a broader extraterritorial reach and a more developed enforcement record for businesses connected to EU-currency transactions or EU-incorporated entities. SECO enforcement is centralised and well-resourced, and SECO's autonomous measures can capture counterparties that the EU list does not. The prudent position for a cross-border business is to design an audit programme that satisfies the more demanding obligation on each specific point – ownership test, record-keeping, notification – rather than to designate one regime as the primary standard and apply it to both.
What should a cross-border business do about compliance audit and testing?
A cross-border business subject to both the EU and SECO regimes should run separate audit tracks for each regime rather than a single unified programme. The practical steps are: verify that screening feeds are separate and independently current; apply the correct ownership-and-control test for each regime's nexus; maintain a licence register that maps conditions and monitoring obligations by regime; confirm that notification workflows exist for both EU competent authorities and SECO; and document each decision with sufficient metadata to reconstruct the process if a regulator requests it. Where any of these elements is uncertain, external counsel should be instructed before the next supervisory cycle.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.