Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

EU vs SECO: Sanctions compliance programmes compared

A Swiss trading house with EU distribution subsidiaries receives a compliance query from its bank: does it run separate sanctions compliance programmes for each jurisdiction, or does one programme cover both? The answer affects every transaction the group touches. Get it wrong under either regime and the consequences range from regulatory censure to criminal liability for senior management.

The EU and Switzerland (SECO) both require regulated and exposed businesses to maintain effective sanctions compliance programmes (structured internal systems for identifying, preventing, and managing sanctions risk), but the two regimes diverge on legal basis, administrative architecture, ownership-and-control tests, and enforcement philosophy. A single programme drafted to one regime's standard will have gaps when measured against the other.

This analysis maps those divergences criterion by criterion, identifies the practical risk flags for cross-border groups, and closes with the steps a compliance team should take before the next audit cycle.

How the legal basis shapes programme design

EU sanctions rest on directly applicable Council Regulations, which take effect simultaneously across all Member States without national implementing legislation. SECO administers Switzerland's autonomous sanctions regime through ordinances enacted under its own constitutional framework, which is structurally separate from EU law and operates independently of it.

That structural difference matters for programme architecture. A compliance programme built for an EU subsidiary must account for Council Regulations that are binding, uniform, and directly enforceable by national competent authorities in each Member State. The same programme applied to a Swiss entity must instead be calibrated to SECO ordinances, which can – and sometimes do – diverge from the EU's asset-freeze and prohibition lists in both timing and scope. The EU acts by qualified majority in Council; Switzerland acts through a different constitutional process. Alignment between the two is the norm in practice but is never automatic, and gaps can open during the interval between an EU designation and a corresponding Swiss measure.

In our cross-border practice, the single most common structural error we identify is the assumption that an EU-compliant programme covers a Swiss affiliate as a matter of course. It does not. Each entity in the group needs a programme element mapped to the applicable ordinance, not only to the Council Regulation.

Governing authorities and their enforcement posture

On the EU side, programme oversight is distributed: the Council sets the legal framework, but enforcement sits with national competent authorities in each Member State, whose approaches, resourcing, and penalty scales vary. On the SECO side, authority is centralised: the State Secretariat for Economic Affairs administers, investigates, and refers cases for prosecution within a single federal structure.

That centralisation at SECO creates a different practical dynamic. A business dealing with SECO has one interlocutor for licensing queries, for reporting obligations, and for any enforcement inquiry. A business dealing with an EU exposure may face coordinated enquiries from the competent authority in each Member State where it operates – and those authorities do not necessarily share information automatically or move at the same pace. The EU has mechanisms to improve supervisory convergence, but national enforcement remains the reality.

What does this mean for programme design? EU-operating entities need escalation protocols that can activate local compliance resources in multiple Member States simultaneously. SECO-regulated entities need a clear direct line to Bern, with documented procedures for licensing and exception requests to a single authority. A cross-border group needs both – with a governance layer that can coordinate them without creating a single point of failure.

Is your programme's escalation matrix tested against a simultaneous multi-jurisdiction inquiry, or only against a single national authority?

What do the ownership-and-control tests require?

Both regimes apply an ownership and control test – the principle that a non-listed entity can be caught by sanctions if a listed person owns or controls it – but the tests operate differently in important respects.

Under EU Council Regulations, the test combines ownership and control. A non-listed entity is subject to an asset freeze where a listed person owns it, controls it, or acts on its behalf or at its direction. Control is assessed by reference to governance rights, contractual arrangements, and factual influence, not ownership alone. A listed person holding a minority stake but exercising effective board control can bring an entire entity within the freeze.

SECO's approach follows a comparable logic, but the interpretive guidance issued under the Swiss ordinances is less developed than the guidance the EU Commission and Member State authorities have published over the programme of successive sanctions packages. In our experience, Swiss businesses have historically relied more on their own legal analysis and less on a body of regulatory guidance. That gap is narrowing, but it means a cross-border compliance team must be more self-reliant in assessing the Swiss limb of a control analysis.

For the compliance programme, the practical implication is screening that goes beyond the first layer of ownership. Both regimes require a business to trace the chain. A programme that screens only direct counterparties and stops at the first legal entity fails the standard under both regimes. The programme must map the full ownership and control chain of each material counterparty, document the analysis, and retain that documentation for the applicable record-keeping period.

Screening architecture: where the regimes create different demands

Effective screening under both regimes requires access to current consolidated lists – the EU Consolidated List maintained by the EU and SECO's published ordinance annexes – and a process that checks those lists against counterparties, beneficial owners, and transaction parties in real time or at defined intervals.

The EU Consolidated List is published in the Official Journal and maintained in a machine-readable format. Updates follow Council decisions and can occur rapidly, particularly during active sanctions periods. A compliance programme for an EU entity must be capable of ingesting those updates promptly; a programme with a manual weekly update cycle is structurally inadequate. The list also includes EU measures implementing UN Security Council Consolidated List designations, so a single EU screening run covers both the autonomous EU programme and the UN layer.

SECO publishes its own annexes. Swiss autonomous measures do not automatically mirror EU timing or scope. A SECO-regulated entity must therefore run a separate screening pass against the Swiss lists, not merely rely on the EU consolidated run. In practice, many cross-border groups maintain a combined screening architecture that pulls both list sets, with a flag for divergence. That architecture requires governance: someone must own the divergence queue and make a documented decision when the EU list and the SECO list are not identical for the same counterparty.

In a recent matter, a financial group operating in both Frankfurt and Zurich discovered that its screening platform was pulling the EU Consolidated List but had not been configured to include SECO annexes for the Swiss entity. The gap was identified during an internal audit. We assisted the group in mapping the uncovered exposure, adjusting the screening configuration, and documenting a retrospective risk review. The matter illustrated a pattern we see regularly: the technical fix is straightforward; the harder work is the documented governance around it.

Record-keeping, reporting, and the notification obligation

Both regimes impose record-keeping requirements on businesses that hold or encounter frozen assets or that identify a potential sanctions breach. The specific periods and triggers differ, and both should be treated as minimum floors rather than targets.

Under EU Council Regulations, entities that hold frozen funds or economic resources are required to notify their national competent authority. The obligation is not merely to freeze: it is to report. The timing and format requirements vary by Member State, because notification flows to the national competent authority, and national implementation differs. A group with subsidiaries in multiple Member States therefore needs a notification protocol that can activate the correct authority in each jurisdiction, with the correct local format, within the applicable local window. A single EU-level notification template does not suffice.

SECO requires notification of frozen assets under the Swiss ordinances, and there are reporting obligations in connection with suspicious transactions. The centralised Swiss structure means the notification goes to SECO directly. That single-destination reporting is administratively simpler, but it does not reduce the compliance burden: the analysis supporting the notification must be equally rigorous.

Record-keeping under both regimes must support an enforcement inquiry years after the event. A compliance programme should therefore retain screening records, decision logs, ownership analysis, transaction documentation, and notification correspondence. Qualitative standard: retain as if an enforcement authority will request production. The specific retention period applicable in each Member State and under Swiss law should be confirmed with local counsel before the programme is finalised.

Licensing: divergent routes for similar transactions

A transaction that is prohibited under both regimes may nevertheless be licensable – but the routes diverge substantially, and a programme must be designed to handle both.

EU licensing for asset-freeze exceptions and for prohibited transactions is administered at Member State level through national competent authorities. Each Member State has its own licensing form, its own assessment process, and its own timeline. There is no single EU licensing portal. The result is that a cross-border group seeking authorisation for a transaction that touches multiple Member States may need to run parallel applications in each relevant jurisdiction. The programme should include a licensing-triage function: which authority or authorities are relevant, what grounds for authorisation exist under the applicable Council Regulation, and what documentation is required by the local authority.

SECO licensing is centralised. An application for authorisation to conduct an otherwise-prohibited transaction goes to Bern, to a single decision-maker. The grounds for authorisation are set out in the applicable ordinance. The process is more predictable in terms of interlocutor, though not necessarily faster. The programme should include a SECO-specific licensing procedure with documented criteria for when to apply, what to submit, and how to manage the period between application and decision.

Where a transaction requires authorisation under both regimes – a common situation for a group with EU operations and a Swiss holding or financing entity – the group faces two parallel licensing tracks that may not move at the same speed. The programme should include a hold protocol: the transaction does not proceed until both authorisations are in place, regardless of which comes first.

How do the regimes interact with OFAC and the wider cross-regime picture?

EU and SECO compliance programmes do not operate in isolation. A cross-border group typically faces OFAC exposure as well, particularly if it has US-dollar transactions, US-person involvement, or products with US-origin content. OFAC's secondary sanctions risk (the risk of US sanctions being applied to non-US persons for conduct that touches a US-sanctioned programme) adds a layer that neither the EU programme nor the SECO programme covers.

The three regimes – EU, SECO, and OFAC – can and do diverge on list content and on the scope of prohibitions. Where they diverge, the stricter prohibition governs for the entity subject to it. A Swiss entity with a US-dollar clearing relationship is subject to SECO ordinances, to EU measures if it has EU subsidiaries, and to OFAC's secondary-sanctions posture if it touches US-nexus transactions. The compliance programme must be designed to apply the most restrictive applicable requirement to each transaction, not to average across regimes.

OFAC's five-element compliance framework – management commitment, risk assessment, internal controls, testing and auditing, and training – provides a useful structural template that can be adapted for EU and SECO purposes. It is not a legal requirement under either EU or Swiss law, but it represents a well-documented benchmark that enforcement authorities in multiple jurisdictions treat as evidence of a serious programme. We regularly advise groups to use the five-element structure as the architectural backbone of a multi-regime programme, adapting the content of each element to the specific requirements of each applicable regime.

For UK-regulated entities in the group, OFSI's approach adds yet another dimension. OFSI has published its own licensing and compliance guidance, and its enforcement posture – including its approach to monetary penalties – has evolved. A group that operates across EU, Swiss, and UK jurisdictions needs a programme architecture that can serve all three, with regime-specific modules plugged into a common governance structure.

The position above covers the structural standard. Your group's specific mix of entities, counterparties, goods, and financing arrangements changes the analysis materially. To discuss a cross-regime compliance review, contact Calder & Vance at info@caldervance.com.

Risk flags that undermine programme effectiveness

Across both regimes, five failure patterns appear repeatedly in the programmes we review. Each one is correctable, but each creates material enforcement exposure in the interim.

The first is list coverage that is incomplete. A programme configured to check only the EU Consolidated List for a group that includes a Swiss entity leaves the Swiss entity unscreened against SECO annexes. The fix is a screening architecture that explicitly maps each legal entity to each applicable list.

The second is ownership analysis that stops at the first layer. Both the EU control test and the SECO equivalent require tracing the full beneficial-ownership chain. A programme that screens the named counterparty but does not identify the ultimate beneficial owner against either list has a structural gap that will not survive an audit.

The third is a notification protocol that is generic rather than jurisdiction-specific. Because EU notification goes to Member State authorities and SECO notification goes to Bern, a single-template notification process will produce either the wrong format or the wrong recipient. The programme must route notifications correctly, automatically, based on the entity generating the obligation.

The fourth is a training programme that treats all sanctions as the same. EU and SECO rules differ in scope, timing, and enforcement mechanism. Staff in a Swiss entity who have been trained on EU measures only – and vice versa – will misidentify obligations. Training must be regime-specific for the entity population it serves.

The fifth is a governance structure that cannot escalate a cross-regime conflict. When EU and SECO positions diverge on a counterparty, someone in the group must own that decision and document the analysis. A programme without a named escalation owner for cross-regime divergences creates a vacuum that enforcement authorities will interpret unfavourably.

If a transaction has already been flagged against either list, or if a compliance programme has been audited and found deficient, early engagement with counsel can preserve remediation options. Contact us at info@caldervance.com for a confidential review.

Addressing the common misconception: one programme for both regimes

The most persistent myth we encounter in advising cross-border groups is that a single well-drafted programme – typically one built to the OFAC five-element standard or to a generic international compliance template – satisfies both EU and SECO requirements as written. It does not.

The misconception is understandable. The high-level architecture of any serious sanctions compliance programme is similar across regimes: governance, risk assessment, screening, controls, training, audit. The content of each element, however, is regime-specific. The EU control test is not the same as the SECO test. The EU notification route is not the same as the SECO notification route. The EU licensing authority is different for each Member State; SECO is one authority. A programme that treats these as equivalent produces systematic gaps in exactly the elements that enforcement authorities examine first.

A well-designed multi-regime programme is not four separate programmes running in parallel. It is one governance structure with regime-specific modules. The common elements – tone from the top, risk appetite statement, training calendar, escalation hierarchy – are shared. The operative elements – list coverage, ownership analysis methodology, notification templates, licensing procedures – are tailored to each applicable regime. That structure is achievable without the administrative overhead of maintaining entirely separate systems.

Related practices

Frequently asked questions

Where do the regimes diverge on sanctions compliance programmes?
The most significant divergences are in enforcement architecture, ownership-and-control guidance, list-update timing, and licensing procedure. EU enforcement is distributed across Member State competent authorities; SECO enforcement is centralised in Bern. EU guidance on the control test is more developed; Swiss businesses have historically relied more on independent legal analysis. The lists do not always update simultaneously, and licensing applications go to different authorities under each regime. A programme designed for one regime will have structural gaps when assessed against the other.
Which regime is stricter on sanctions compliance programmes?
Neither regime is categorically stricter across all dimensions. The EU regime carries broader geographic reach for entities operating in multiple Member States, and the distributed enforcement architecture can produce multi-jurisdictional exposure simultaneously. SECO's centralised structure provides a single point of contact, which can reduce administrative friction, but Swiss autonomous measures can diverge from EU measures in timing or scope. Where the two regimes apply to the same group, the stricter prohibition on any given transaction governs for the entity subject to that prohibition. That determination must be made transaction by transaction.
What should a cross-border business do about sanctions compliance programmes?
The first step is to map which regimes apply to each legal entity in the group, based on jurisdiction of incorporation, operations, and the nationality or residence of staff with decision-making authority. The second step is to audit the existing programme against the specific requirements of each applicable regime – not against a generic international template. The third step is to close the gaps: list coverage, ownership-analysis methodology, notification routing, licensing procedures, and training content. Where the group also has US, UK, or other-regime exposure, a fourth step is to design a governance layer that resolves cross-regime conflicts by applying the most restrictive applicable requirement. Engaging specialist cross-border sanctions counsel at the programme-design stage is materially cheaper than addressing enforcement exposure after the fact.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.