Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

EU vs SECO: Internal sanctions investigations compared

A Swiss commodity trader with EU-regulated subsidiaries flags an unusual payment routed through a correspondent chain. The compliance team suspects a sanctions connection. Two regulators are potentially in scope – the EU regime, enforced through national competent authorities, and SECO (the State Secretariat for Economic Affairs, Switzerland's autonomous sanctions authority). Each expects a different response. The question is not merely what happened, but how the investigation is structured, documented, and – where necessary – disclosed, and whether the two regimes require genuinely different approaches.

Internal sanctions investigations under the EU regime and under SECO share a common purpose – establishing whether a breach occurred, who bears responsibility, and what remediation is proportionate – but they differ materially in legal basis, reporting obligations, disclosure culture, and the weight placed on voluntary co-operation. As of early 2026, the EU regime has moved toward greater enforcement harmonisation across member states, while SECO retains a comparatively centralised, negotiation-oriented enforcement posture. Understanding both, and the points where they diverge, shapes every decision from scope to disclosure.

This analysis maps the two regimes criterion by criterion: governing authority and legal basis, the investigation process itself, disclosure and voluntary self-disclosure mechanics, the role of privilege and legal professional secrecy, risk flags specific to each regime, and the practical implications for a cross-border business running a single investigation that touches both.

Who administers internal sanctions investigations – and under what authority?

The EU regime does not have a single enforcement authority for economic sanctions. Enforcement is decentralised: each member state designates one or more national competent authorities ("NCAs") responsible for investigating apparent breaches of EU Council regulations. Those regulations impose directly applicable obligations across all EU member states, but the sanction for breach – whether administrative penalty, criminal referral, or both – is a matter of national law. That means the substance of what is prohibited is harmonised; the consequences of a breach are not.

In practice, an EU-connected internal investigation will often involve the NCA of the member state where the relevant entity is established or where the transaction was executed. For a German bank, that is BaFin and potentially the public prosecutor. For a Dutch trading house, the relevant NCA operates under Dutch law. The practical implications are significant. One internal investigation into a single apparent violation may run in parallel before two or more NCAs with different penalty ranges, different investigative powers, and different expectations about what a "co-operative" response looks like. We regularly advise businesses that underestimate this multiplicity at the outset of an investigation.

SECO operates differently. Switzerland has its own autonomous sanctions regime, legally independent from the EU regime, administered centrally by SECO under the relevant federal embargo legislation and implementing ordinances. When a Swiss-nexus transaction or entity is under scrutiny, SECO is the competent authority. There is no decentralisation within Switzerland. SECO runs its own investigation, may issue administrative enforcement measures, and can refer matters to federal criminal prosecution authorities where criminal thresholds are met. The single-authority model means a business knows with certainty who is watching – and who it needs to satisfy.

How does each regime structure the internal investigation process?

An internal sanctions investigation under either regime typically follows a common initial sequence: trigger identification, scope definition, evidence preservation, factual reconstruction, legal analysis of the apparent violation, and assessment of remediation options. Where the regimes diverge is in the weight each places on the business's own investigative output, the standard expected of that output, and the formality required in presenting conclusions to the authority.

Under the EU regime, the quality of an internal investigation directly affects the NCA's subsequent enforcement posture. Many NCAs have developed published guidance or enforcement policies that expressly reward comprehensive, well-documented internal investigations. The expectation – though not universally codified across all member states – is that a business will preserve relevant communications, reconstruct the decision chain, identify responsible individuals, and produce a findings memorandum. Where an NCA receives a well-prepared investigation report alongside a voluntary disclosure, it typically has a documented basis on which to calibrate penalty. Where it does not, it must conduct its own investigation, which lengthens timelines and removes the business's ability to shape the narrative.

SECO's approach is, in our experience, somewhat more iterative. SECO frequently engages with a business in correspondence before a formal investigation is opened, seeking initial explanations of the facts. This creates an early-stage dialogue that does not exist in most EU NCA processes. The advantage is that a business can test SECO's preliminary read of the conduct before committing to a formal disclosure posture. The risk is that preliminary responses to SECO's queries can narrow the factual space the business later has to work with, particularly if initial responses are made without adequate legal review. Early involvement of compliance counsel – before responding to any SECO query – is not optional.

One structural difference with direct practical consequences: the EU regime increasingly reflects the influence of the EU's push toward enforcement harmonisation, including guidance on cooperation and mitigation. SECO, while receptive to co-operation, does not operate within that broader harmonisation programme. Its expectations are shaped by federal practice and, in complex matters, by the posture of the Swiss federal criminal authorities.

What are the voluntary self-disclosure mechanics under each regime?

Voluntary self-disclosure (a proactive report by a business to the regulator before the regulator identifies the issue independently) is recognised as a mitigation factor under both regimes, but the mechanics, timing expectations, and weight given to disclosure differ substantially.

Under the EU regime, voluntary self-disclosure is not the subject of a single harmonised standard. Each member state's NCA – and, where criminal law applies, each member state's prosecutorial framework – applies its own criteria. That said, the general principle across EU enforcement is well-established: a business that discloses promptly, provides a complete and accurate account, and implements remediation can expect meaningful mitigation. What constitutes "prompt" is not universally defined, but a disclosure made within a short window after the business identifies the apparent violation – before the NCA becomes aware through other means – consistently draws better outcomes than a disclosure that follows a regulatory enquiry. Some member states have introduced statutory disclosure obligations that run in parallel with financial-crime reporting requirements, particularly for credit institutions.

SECO has a recognised practice of treating voluntary disclosure as a significant mitigating factor. Critically, SECO also has the ability to conclude administrative matters through negotiated resolution, which makes the quality and completeness of a voluntary self-disclosure document especially important. A well-structured VSD (voluntary self-disclosure to a regulator) package submitted to SECO – one that sets out the facts accurately, identifies the root cause, describes the harm, and proposes a remediation plan – gives SECO the tools it needs to close the matter at the administrative level without a criminal referral. Where a VSD package is poorly prepared, incomplete, or inconsistent with subsequently discovered facts, it can worsen rather than improve the outcome.

The cross-border complication is this. A business that decides to disclose to SECO must consider whether the same facts require simultaneous or sequenced disclosure to an EU NCA. The timing and content of each disclosure affects the other. A statement made to SECO may be available to EU NCAs through formal or informal co-operation channels. In our cross-border practice, we treat the two disclosures as a single integrated strategy – not two independent filings.

The position above covers the standard voluntary-disclosure scenario. Your facts – the counterparty, the transaction structure, which entities are in scope, and the interplay between your Swiss and EU operations – change the analysis materially. For an assessment of your exposure under the EU regime, contact Calder & Vance at info@caldervance.com.

How do legal professional privilege and professional secrecy operate in each investigation?

Legal professional privilege (the rule protecting confidential communications between a lawyer and a client for the purpose of obtaining legal advice) and its civil-law equivalent, professional secrecy, are critical to any internal sanctions investigation. They determine what the business can communicate to counsel freely, what documents may be withheld from a regulator, and how the investigation report itself should be structured to maximise protection.

Under the EU regime, the position on privilege in sanctions-related internal investigations is governed by the law of the relevant member state. EU law at the Council regulation level does not itself confer or restrict privilege; it is a procedural matter for national law. In most EU member states, communications with an admitted member of the national bar attract legal professional privilege or its civil-law equivalent. The practical complication arises with in-house counsel. In several major EU jurisdictions, privilege attaches more narrowly or not at all to advice given by in-house lawyers, even where those lawyers are qualified members of a bar. A business conducting an internal investigation that relies on in-house analysis, rather than external counsel, may find that the resulting materials are not protected from NCA inspection in the same way.

Under Swiss law, professional secrecy for admitted Swiss attorneys – Anwaltsgeheimnis – is well-established and broad. It attaches to the lawyer-client relationship and protects communications for the purpose of providing legal advice. For an internal investigation conducted under the supervision of qualified Swiss counsel, the core investigation materials – the findings memorandum, legal analysis, and strategy documents – should attract protection. Swiss in-house lawyers qualified and admitted as attorneys occupy a more complex position; the scope of their protection has been the subject of Swiss court scrutiny.

Why does this matter for the investigation design? Because the decision about which counsel leads the investigation, how the report is structured, and to whom it is addressed should be made before any significant interviewing or document review begins. Restructuring privilege protection retrospectively is difficult and sometimes impossible. In our experience, businesses that defer this question – treating it as a formality – sometimes find that their most sensitive factual findings are not protected at the moment they matter most. Have you confirmed, at the outset of the investigation, who holds the privilege and over which documents?

Where do the regimes diverge most sharply – a criterion-by-criterion comparison?

Set side by side, the EU regime and SECO present five clear points of divergence that a cross-border business must map before it designs the investigation.

Enforcement architecture. The EU is multi-jurisdictional at the investigation stage: the same apparent violation can trigger parallel NCA processes in multiple member states, each with its own powers, penalties, and timelines. SECO is a single authority. Multi-NCA exposure is the principal EU-specific complication; it does not arise under SECO.

Dialogue and iterative process. SECO's enforcement culture is more openly dialogic at the pre-disclosure stage. It is possible, in practice, to have a preliminary conversation with SECO about how the facts are characterised before a formal VSD is submitted. EU NCAs vary considerably on this point; some are receptive to preliminary engagement, others are not. A blanket assumption that "all EU NCAs behave like SECO" is a consistently observed mistake.

Criminal exposure pathway. Under the EU regime, criminal exposure is governed by each member state's penal law. Referral thresholds, available defences, and prosecutorial culture differ sharply between, say, France, Germany, and the Netherlands. Under the Swiss regime, criminal exposure runs through federal prosecutors under the relevant federal criminal code provisions. The pathway is single and known. For a business calculating litigation risk, this distinction is significant.

Harmonisation trajectory. The EU has, particularly since the conflict-driven acceleration of its sanctions programme from 2022 onwards, moved consistently toward greater NCA enforcement harmonisation, including guidance on penalty ranges, mitigating factors, and co-operation credits. SECO has not been part of this trajectory. Switzerland applies its own autonomous regime. The practical effect is that the mitigation framework under the EU regime is increasingly articulated and predictable in outline, while SECO's approach, though generally consistent in principle, is more discretionary in application.

Record-keeping and documentation standards. Both regimes expect a business to maintain adequate records of its screening, transaction monitoring, and compliance decisions. The precise standards differ. Under SECO's implementing legislation, documentation obligations are set by federal ordinance. Under the EU regime, documentation obligations are embedded in the relevant Council regulations and, for regulated entities, in sectoral requirements. A business should confirm, for each regime in scope, what must be retained, in what form, and for how long – before the investigation concludes, not after.

If a transaction has already been flagged or a regulatory enquiry has arrived, an early review can preserve options that narrow with time. To discuss a pending matter, contact info@caldervance.com.

What are the principal risk flags specific to each regime?

Risk flags in an EU-connected investigation cluster around four recurring patterns. First, multi-jurisdictional exposure that is not identified until after initial disclosures are made – at which point the business has already shaped the narrative in one jurisdiction without accounting for another. Second, reliance on in-house legal analysis that does not attract privilege, so that the internal investigation report becomes accessible to the NCA. Third, failures in the ownership-and-control analysis: the EU applies a combined ownership and control test (the rule under which a non-listed entity may be caught because a listed person exercises control, even without a majority stake), which is wider than OFAC's mechanical 50-percent ownership rule and requires active legal judgment. Fourth, delayed engagement of external sanctions counsel – particularly in businesses that treat the initial compliance review as the investigation, rather than as a trigger for a separate privileged inquiry.

Under the SECO regime, the characteristic risk flags differ. The most significant is a failure to appreciate SECO's scope. Switzerland's autonomous sanctions regime is not merely a replica of the EU regime; it has its own list of designated persons and entities, its own prohibited transactions, and – critically – its own exemption and authorisation pathways. A business that assumes alignment between EU and SECO designations may miss a SECO-specific exposure, or a SECO-specific exemption that the EU does not offer. Second, the early-correspondence risk: responding to SECO's initial enquiries without legal review, in the belief that a straightforward factual explanation will close the matter. Third, underinvestment in the VSD package: a thin or incomplete SECO disclosure that fails to give SECO the factual foundation for an administrative resolution, effectively transferring the investigative burden back to the authority.

One risk flag common to both regimes is the failure to consider secondary-sanctions exposure from a third regime. A transaction that triggers an EU or SECO investigation may also carry US secondary-sanctions risk – particularly where the underlying activity involves a US nexus, US-dollar clearing, or a US person in the supply chain. We regularly advise businesses that, having scoped their investigation for EU and SECO purposes, have not yet mapped whether the same conduct triggers a reporting or disclosure obligation under OFAC rules. The investigation scope should be set before significant work begins, not revised after the fact.

When should a cross-border business involve external sanctions counsel?

The answer, in practice, is earlier than most businesses do. The two most common points of failure in EU-SECO internal investigations are: engaging counsel only after a preliminary response has already been given to the regulator, and allowing the scope of the investigation to be defined by the compliance team rather than by a legal analysis of what the regimes require. Both compress the options available at the disclosure and remediation stage.

There is a widely held assumption that a well-run compliance department can conduct a sanctions investigation internally, involve external counsel only for the formal disclosure, and achieve a comparable outcome to a fully privileged, counsel-led investigation. In our experience, this is a myth. The legal analysis in a sanctions investigation – determining which regime applies, which prohibitions are engaged, what the ownership-and-control chain requires under the applicable test, what constitutes an apparent violation and what falls within an exemption – is substantive legal work. Delegating it to a compliance function, however well-resourced, without external legal oversight produces conclusions that are less defensible before an NCA and less reliable as a basis for disclosure decisions.

The practical question is not whether to involve counsel, but when and in what capacity. Counsel should be engaged to design the investigation structure – including privilege protection – before interviewing begins. Counsel should review the scope definition before significant document review is undertaken. And counsel should review any response to regulatory enquiries, whether from an EU NCA or from SECO, before it is submitted.

A micro-scenario from our cross-border practice: a financial institution with entities in two EU member states and a Swiss-licensed subsidiary identified, during routine screening, that a counterparty may have been connected to a designated person. The compliance team had already drafted a preliminary response to SECO before external counsel was engaged. We assessed the exposure under both the EU regime and SECO, identified that the preliminary response overstated the business's operational involvement with the counterparty, and worked with the client to prepare an accurate, complete, and privileged investigation report before a revised response was finalised. The matter was resolved at the administrative level. No outcome is guaranteed, but the timing of counsel involvement consistently affects the range of outcomes available.

Related practices

Frequently asked questions: EU vs SECO internal sanctions investigations

Where do the regimes diverge on internal sanctions investigations?

The principal divergences are enforcement architecture (EU is multi-jurisdictional across NCAs; SECO is a single authority), dialogue culture at the pre-disclosure stage (SECO is more openly iterative; EU NCAs vary widely), the criminal exposure pathway (multi-state penal law under the EU regime versus federal prosecution under the Swiss regime), and the trajectory of harmonisation (the EU is actively converging enforcement standards; SECO applies its own autonomous approach). These differences affect scope-setting, privilege design, disclosure timing, and the sequencing of remediation steps.

Which regime is stricter on internal sanctions investigations?

Neither regime is categorically stricter. The EU's decentralised NCA architecture can produce higher aggregate penalty exposure in multi-member-state matters, particularly where several NCAs investigate the same conduct under divergent national penalty laws. SECO's centralised model allows for administrative resolution of matters that might attract criminal referrals in some EU jurisdictions – but SECO's ability to refer to federal criminal prosecutors should not be underestimated. Strictness in practice depends heavily on the specific conduct, the jurisdiction mix, and the quality of the business's voluntary self-disclosure and co-operation.

What should a cross-border business do about internal sanctions investigations?

A cross-border business facing EU and SECO exposure should, as a first step, engage external sanctions counsel before responding to any regulatory enquiry and before the internal investigation scope is finalised. Counsel should assess which regimes are engaged, structure the investigation to maximise privilege protection, and design a co-ordinated disclosure strategy that treats both the EU NCA and SECO filings as a single integrated process. Remediation should be documented and, where possible, completed before disclosure. Early involvement consistently preserves options that are unavailable once initial responses have been given. For confidential advice on your matter, contact Calder & Vance at info@caldervance.com.

About Claire Dubois
Claire Dubois advises on EU sanctions, including Council-regulation analysis, ownership-and-control questions, and annulment actions before the EU General Court. She regularly advises multinationals and financial institutions on EU enforcement matters and cross-border investigations involving EU and non-EU regime overlap. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.