A trading company with offices in Frankfurt and Geneva ships a batch of industrial sensors to a distributor in a third market. Customs flags a discrepancy between the declared end-use and the buyer's profile. Both the EU and Switzerland claim jurisdiction. Two sets of criminal prosecutors could, in principle, open a file. Which regime bites first – and what does that mean for the individuals who signed the export documents?
Criminal exposure in export-control cases under the EU and Swiss SECO regimes arises from distinct legal bases, administered by different authorities, with divergent thresholds for individual liability. The EU's dual-use rules create obligations that member states enforce through their own criminal codes, producing significant variation in sentence ranges and prosecutorial practice across the bloc. Switzerland's export-control regime, administered by SECO (the State Secretariat for Economic Affairs, Switzerland's export-control and sanctions authority), is a single, federal criminal code – more uniform in application but no less serious in consequence.
This analysis maps the two regimes side by side, identifies where the risk of criminal liability is highest, and sets out what cross-border businesses operating in both jurisdictions must do before a compliance failure becomes a criminal matter.
The legal architecture: how each regime creates criminal liability
Criminal liability in EU export-control cases flows from the EU's dual-use rules – the directly applicable EU regulations that list controlled goods and require licences – but the criminal enforcement mechanism itself is embedded in each member state's national criminal law. This is the defining structural feature of the EU regime and the source of its most significant complexity for cross-border businesses.
At the EU level, the applicable Council Regulation defines prohibited conduct: exporting controlled dual-use items without the requisite authorisation, making a false declaration to obtain a licence, diverting goods in breach of end-use conditions, and failing to report knowledge of a prohibited end-use. That regulation is binding in all member states. What it does not do is specify penalties. The criminal consequences – whether a violation is a misdemeanour or a felony, whether it carries one year of imprisonment or ten, whether corporate entities bear criminal liability or only civil sanctions – are set by each member state individually.
The practical result is uneven. A shipment cleared through Hamburg may expose the responsible individual to a longer custodial sentence than the same shipment cleared through a port in another member state. Prosecutors in certain jurisdictions have developed specialist export-control units; in others, criminal cases remain rare. In our cross-border practice, this variation means that the identity of the clearing jurisdiction is itself a material factor in the criminal-risk assessment – a point that internal compliance programmes rarely address.
Switzerland's regime operates differently. SECO administers a single federal instrument governing the export of controlled goods, including dual-use items and war materiel. Criminal offences – including wilful export without authorisation and negligent violations – are defined in that federal instrument and carry criminal penalties set at the federal level. There is no equivalent of the EU's member-state patchwork. A violation in Basel faces the same criminal standard as a violation in Zurich. This uniformity makes the Swiss regime more predictable, though predictability does not mean leniency.
Where does individual liability attach in the EU?
In EU member states, individual criminal liability for export-control breaches typically attaches to the person who signed or authorised the export documentation, the compliance officer who certified the classification, and – in some jurisdictions – the director or senior manager who approved the transaction at board level.
The central question in any criminal exposure analysis is knowledge. Did the individual know that the goods required a licence? Did they know, or have reason to know, that the stated end-use was false? EU dual-use rules impose a positive obligation on exporters to exercise due diligence. Where a red flag was present – an unusual payment route, an atypical end-user, a destination inconsistent with the buyer's stated business – and the exporter proceeded without escalating the question, prosecutors in several member states have treated that as wilful blindness sufficient for criminal intent.
What constitutes a red flag is not defined with precision in the applicable Council Regulation. It draws on guidance issued by the European Commission and the export-control practice of national authorities. In our experience, the gap between what a compliance officer understood to be a red flag and what a prosecutor later characterises as one is one of the most contested issues in EU export-control criminal proceedings.
Corporate criminal liability exists in most – but not all – member states. Where it does, a company can face criminal conviction alongside its individual employees. Where it does not, the pressure on individuals is correspondingly higher, because they bear the full weight of enforcement without the corporate entity sharing it. A business operating through subsidiaries in multiple EU jurisdictions should map which of its entity-level structures sit in corporate-criminal-liability jurisdictions before a problem arises.
How does SECO criminal liability compare?
Under Switzerland's federal export-control instrument, criminal liability arises for both wilful and negligent violations, and both natural persons and legal entities can face criminal prosecution. This dual exposure – individual and corporate simultaneously – is a feature that distinguishes the Swiss regime from several EU member states where corporate criminal liability is absent or limited.
The standard for negligence under the Swiss regime is meaningful. A business that fails to implement adequate internal controls – classification procedures, end-use checks, red-flag screening – can face criminal liability even if no individual employee specifically intended a breach. In our practice, this negligence standard represents the sharpest divergence from the EU approach: in most EU jurisdictions, criminal conviction requires proof of intention or at minimum wilful disregard. The Swiss position brings negligent systemic failures within the criminal perimeter.
SECO as the administering authority has investigative powers and works in close co-operation with Swiss federal prosecutors. Investigations tend to be thorough and document-intensive. The authority can request transaction records, correspondence, and classification documentation going back over a material period. Businesses operating in Switzerland should assume that SECO can reconstruct the decision-making chain for a contested shipment and will do so if it identifies grounds for investigation.
Is there a mitigating path? Switzerland's federal criminal process does recognise co-operation and self-disclosure as factors in determining the ultimate penalty. This is not a formal voluntary-self-disclosure programme equivalent to OFAC's VSD mechanism, but proactive engagement with SECO before a formal investigation is opened has, in practitioner experience, produced more favourable outcomes than reactive compliance. Timing matters: the window for productive engagement closes once an investigation is formally commenced.
A side-by-side comparison of the key divergences
The most significant divergences between the EU and SECO criminal regimes fall across five dimensions. Each is material to a compliance programme designed to operate in both jurisdictions.
Uniformity of criminal standard. SECO applies a single federal standard across all Swiss territory. The EU creates obligations through a directly applicable regulation but delegates criminal enforcement to twenty-seven national systems. A business with export operations in multiple EU member states faces multiple criminal standards simultaneously, not one.
Negligence as a criminal gateway. Switzerland criminalises negligent violations of export-control obligations. Most EU member states require intent or wilful disregard for criminal liability to arise. This means that a compliance programme that would protect individuals from criminal exposure in Germany or France may leave those same individuals exposed to criminal prosecution if the relevant shipment was cleared through a Swiss entity.
Corporate criminal liability. Both Switzerland and most major EU jurisdictions now provide for corporate criminal liability in export-control matters, but the precise mechanics differ. Swiss law treats the legal entity as directly liable where adequate internal organisation would have prevented the offence. EU member-state law varies: some require that the offending individual held a managerial role; others use a broader attribution test. A holding structure with entities in multiple jurisdictions should be assessed against each applicable national standard.
Jurisdictional reach. EU dual-use rules, by their structure as directly applicable regulations, follow the goods: a company established in one member state that routes a shipment through another can face enforcement action in either. Switzerland applies its own instrument to conduct involving Swiss-established entities or Swiss territory. Where a transaction has meaningful connections to both the EU and Switzerland – a common pattern in high-value industrial goods – both sets of criminal authorities can claim jurisdiction. That is not a theoretical concern. In a recent matter, a precision-engineering firm with a Swiss parent and a German trading subsidiary found its directors fielding simultaneous enquiries from Swiss federal prosecutors and German customs investigators. Managing those parallel processes required a carefully sequenced engagement strategy.
Penalty ranges. Without citing specific figures not on the verified registry, it is accurate to say that both regimes carry custodial sentences for serious wilful violations. The EU member states with the most active enforcement history have imposed sentences measured in years, not months, for the most serious cases. Switzerland's federal instrument provides for criminal fines and imprisonment at the federal level. In terms of headline severity, the regimes are broadly comparable for wilful breaches; Switzerland's negligence gateway means that the effective risk surface is wider for businesses with systemic compliance failures.
Cross-border extraterritorial considerations: where US controls intersect
No analysis of criminal exposure in EU and Swiss export-control cases is complete without addressing the US dimension. The EAR – the US Export Administration Regulations, administered by the Department of Commerce Bureau of Industry and Security (BIS) – carries its own extraterritorial reach. Items that originate in the US, contain a threshold proportion of US-origin content, or are produced using US technology can be subject to EAR requirements even when re-exported by a non-US entity.
The relevance to EU and Swiss exporters is direct. A European company that re-exports or transfers a controlled item with US-origin content without the requisite EAR authorisation faces potential BIS administrative action and, in serious cases, referral to the US Department of Justice for criminal prosecution. The US criminal standard for export-control violations under the Export Control Reform Act is a wilful standard, but US prosecutors have interpreted wilfulness broadly in export-control cases, particularly where red flags were present and ignored.
The intersection produces a layered exposure. A single mis-classified shipment of dual-use goods from a Swiss entity through an EU subsidiary to a third-market buyer could, depending on the content of the goods, engage: Swiss federal criminal liability under SECO's instrument; criminal liability in the EU member state of export under that state's implementation of EU dual-use rules; and BIS/DOJ criminal exposure if US-origin content or technology is present. These are not alternative risks – they are concurrent. Managing them requires a co-ordinated legal strategy across all three systems, because a disclosure made in one jurisdiction can be used as evidence in another.
In our practice, we regularly advise clients who have encountered this layered exposure and are seeking to sequence their response in a way that does not inadvertently prejudice their position in any one jurisdiction. The order of engagement with regulators – and the content of any initial communications – is often the most consequential decision in the entire response strategy.
For a detailed assessment of how US export-control criminal risk interacts with the EU and OFAC sanctions programmes, see our analysis at criminal export exposure: OFAC and OFSI compared.
Risk flags: when criminal exposure is highest
Certain fact patterns substantially elevate the probability that a regulatory inquiry will escalate to a criminal referral. A compliance programme designed to operate under both the EU and SECO regimes should treat these as priority control points.
Deliberate mis-classification. Where evidence shows that a company actively classified controlled goods in a lower control category to avoid licensing requirements, prosecutors on both sides have found this the strongest basis for wilful-intent findings. Internal correspondence that records a debate about classification and then records a decision to proceed without a licence is, in every prosecutor's hands, the clearest possible evidence of intent.
End-use diversion. A declared end-use that is falsified to obtain a licence is treated as fraud in most EU jurisdictions in addition to the export-control offence. Under Switzerland's federal instrument it similarly engages the most serious penalty tiers. End-use diversion cases have historically attracted the longest custodial sentences across both regimes.
Red-flag override without documentation. The absence of documentation is not protection. Prosecutors treat the absence of any record that a red flag was assessed – where the flag is apparent from the transaction file itself – as evidence that the flag was ignored. Where there is a record, and that record shows the flag was noted but not escalated, the liability question moves to whether the escalation process itself was adequate.
Repeated low-level violations. Both EU member-state prosecutors and SECO look at patterns. A series of apparent administrative errors that produce a consistent outcome – goods reaching a restricted destination through slightly varying methods – is treated as evidence of systemic intent rather than systemic carelessness. The line between the two is more important for criminal exposure than for administrative penalty purposes.
Non-co-operation with initial enquiries. In both the EU and Switzerland, an entity that delays response to information requests, provides incomplete records, or fails to preserve documents once an enquiry is foreseen faces aggravated treatment. Obstruction can itself constitute an additional criminal offence in certain EU jurisdictions. The duty to preserve documentation arises the moment an enquiry is reasonably foreseeable – not when it is formally commenced.
When should counsel be instructed?
The answer is earlier than most businesses assume. Criminal exposure in export-control cases is typically identified at the point of a customs query, a regulator's information request, or an internal audit finding. By that stage, documents have been produced, individuals have spoken to investigators, and positions – sometimes inconsistent ones – have already been taken. Each of those steps has consequences that are difficult to reverse.
Counsel should be instructed at the point of first contact from any regulatory authority – customs, SECO, a national export-control authority, or, in the layered scenario, a foreign authority making a mutual legal assistance request. Equally important: where an internal audit, a whistleblower report, or a compliance review identifies a potential violation before any regulatory contact, the question of whether and how to make a voluntary disclosure is one of the most consequential decisions the business will face.
Voluntary disclosure – making a proactive report to the relevant authority before being contacted – is treated differently across the EU member states and under Switzerland's federal process. In some EU jurisdictions, proactive disclosure is a significant mitigating factor and can redirect a matter from the criminal track to an administrative one. In Switzerland, as noted above, early engagement with SECO before formal investigation opens a different set of options than engagement after. Timing is not just a tactical consideration; it is often the determinative factor in whether individuals face criminal exposure at all.
The myth worth correcting here is that criminal enforcement of export-control rules is reserved for arms dealers and state-sponsored actors. In our experience, the majority of criminal investigations in EU and SECO export-control matters involve legitimate businesses – manufacturers, distributors, trading companies – that allowed compliance failures to accumulate without a structured response. The legal perimeter around export controls has tightened materially over the past several years. Enforcement activity by EU member-state prosecutors and SECO has increased to match. The question for a cross-border business is not whether the risk is theoretical; it is whether the controls are adequate.
The position above covers the standard fact pattern. Your specific circumstances – the goods, the end-user, the jurisdiction of export, the presence of US-origin content, and the conduct of the individuals involved – change the analysis materially.
For a confidential review of a potential breach or an apparent violation under the EU or SECO regime, contact Calder & Vance at info@caldervance.com. For a structured assessment of your exposure before a regulatory enquiry begins, see our apparent violation assessment service for EU matters.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss next steps.
Related practices
- Apparent violation assessment – EU – structured assessment of criminal and administrative exposure for EU export-control matters
- Criminal export exposure: OFAC and Canada compared – parallel analysis of criminal liability under US and Canadian export-control regimes
- Criminal export exposure: OFAC and OFSI compared – practitioner analysis of criminal exposure across the US and UK regimes