Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · SECO

Payment-processing controls under SECO: what businesses miss

A Swiss-based payment processor routes a batch of transactions for a fintech client. One beneficiary sits two ownership layers beneath a listed entity. The processor's screening tool flags nothing. The transfer completes. Weeks later, a SECO inquiry arrives. At that point, the question is no longer whether the payment should have been stopped – it is whether voluntary disclosure can limit the damage.

Payment-processing controls under SECO are among the most frequently misread obligations in Switzerland's sanctions regime. Swiss ordinances require financial intermediaries and payment firms to freeze assets, refuse transfers, and report to SECO when a counterparty is designated – but the ownership-chain obligations, the interplay with FINMA supervisory expectations, and the divergence from OFAC and EU rules mean that a compliant screen at one layer can still leave a firm exposed. As of July 2026, SECO administers Switzerland's autonomous sanctions as well as measures implementing UN Security Council resolutions, both binding on Swiss-nexus payment flows.

This analysis maps the governing regime and authority, compares the Swiss position with OFAC and EU requirements, identifies the practical gaps that generate enforcement risk, and sets out what cross-border payment businesses should do before the next batch settles.

How does Switzerland's payment-sanctions regime work?

Switzerland's payment-sanctions controls flow from two parallel tracks: UN Security Council measures implemented through Swiss federal ordinances, and Switzerland's autonomous sanctions adopted by the Federal Council. SECO – the State Secretariat for Economic Affairs – administers both tracks, maintains the national sanctions list, and coordinates enforcement with FINMA where financial intermediaries are involved. This dual-track structure is the starting point that payment firms most often misunderstand.

The legal basis for freezing and refusing payments is the relevant thematic ordinance for each sanctions programme. Each ordinance defines the persons and entities whose assets must be frozen, the prohibitions on making funds available, and the reporting and record-keeping obligations that attach. The ordinances are directly applicable to any person or entity in Switzerland and to any business with a meaningful Swiss nexus – a branch, a booking centre, a correspondent account, or a clearing relationship that routes transactions through Swiss infrastructure.

SECO publishes its sanctions lists and provides updates when designations are added or removed. The baseline obligation for payment processors is straightforward: a payment must not proceed if a party to it – originator, beneficiary, or any intermediary holding the funds – appears on the applicable list or is owned or controlled by a listed person. The difficulty is in executing that obligation across layered ownership structures and high-volume, low-latency payment flows.

What is the practical scope? The prohibition on making funds "available" extends beyond direct transfers to cover any action that effectively puts funds at the disposal of a listed party. This includes settling a net position, releasing collateral, processing a currency conversion that forms part of a chain ending at a listed beneficiary, and – depending on the facts – intermediating a correspondent transaction where another bank's exposure is known. In our practice, the "funds available" question is where Swiss payment firms encounter the most ambiguity.

Where do ownership and control tests create exposure?

Switzerland's sanctions ordinances capture not only listed persons but also entities owned or controlled by them – and that extension is where payment processors routinely underestimate their exposure. The applicable standard under Swiss law looks at both ownership and control, which mirrors the EU approach rather than the more mechanical OFAC threshold. This distinction matters operationally.

Under OFAC's 50 percent rule (the rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked), the test is mathematical and ownership-focused. A firm can, in principle, reach a binary answer by tracing equity stakes. SECO's position, like the EU standard, introduces a control dimension: an entity that a listed person controls – through voting arrangements, contractual rights, board appointment powers, or de facto dominance – may be captured even where the equity threshold is not met.

For a payment processor, this creates a two-step obligation. First, screen for direct matches on the applicable lists. Second, assess whether any unmatched counterparty is owned or controlled by a listed person through a structure that a purely equity-based screen would not surface. Have you mapped the beneficial ownership chain of your top-volume counterparties beyond the first corporate layer?

In our experience, the control dimension is where Swiss payment firms carry the most residual risk. A payment firm that has invested in a first-class list-matching tool may still be exposed if that tool does not ingest beneficial-ownership registry data, corporate-structure filings, and adverse intelligence on governance arrangements. Screening technology and ownership intelligence are complements, not substitutes.

The divergence from OFAC is also practically significant for cross-border flows. A payment routed from a US correspondent through a Swiss processor to a European beneficiary may be assessed simultaneously against OFAC's 50 percent rule (at the US end) and SECO's ownership-and-control test (at the Swiss end). A counterparty that clears the OFAC threshold analysis may still be captured by SECO's control test. The stricter prohibition governs: where the two regimes produce different outcomes for the same counterparty, the processor must apply the more restrictive result.

What does the FINMA dimension add?

SECO sets the legal prohibitions; FINMA supervises the processes by which regulated financial intermediaries meet those prohibitions. For payment firms holding a banking or payment-institution licence under Swiss law, FINMA's expectations on sanctions compliance are embedded in its supervisory framework and audit practice – and they go beyond what the sanctions ordinances themselves specify.

FINMA expects regulated entities to maintain documented sanctions compliance programmes that include transaction-monitoring rules calibrated to sanctions risk, periodic testing of screening parameters, governance arrangements that assign clear accountability for sanctions decisions, and escalation procedures for potential matches. These expectations are articulated in FINMA's published guidance and in the findings of supervisory reviews. They do not create new legal prohibitions, but they determine whether a regulated firm's controls are adequate in the eyes of its principal regulator.

The practical effect is that a Swiss payment firm faces two accountability axes: SECO can pursue an administrative or criminal enforcement action for a substantive breach of a sanctions ordinance, and FINMA can take regulatory action – from a remediation order to a licence condition or, in serious cases, a licence revocation – for inadequate controls that allowed a breach to occur. Both risks are live simultaneously. A breach of a sanctions ordinance is simultaneously a compliance failure in FINMA's supervisory assessment.

The position above covers the standard case. Your facts – the counterparty mix, the payment rail in use, the jurisdictions of origination and receipt, the presence of a Swiss correspondent – change the analysis materially.

For a first assessment of your exposure under the Swiss regime, contact Calder & Vance at info@caldervance.com.

How does Swiss practice compare with OFAC and EU requirements?

The Swiss, US, and EU payment-sanctions regimes share a common structural purpose but diverge in their legal mechanics, enforcement posture, and extraterritorial reach – and those divergences generate real compliance asymmetries for cross-border payment processors.

OFAC's regime under IEEPA is notable for its extraterritorial reach through secondary-sanctions risk. Non-US persons that process payments involving certain designated persons – or involving parties to a programme to which secondary sanctions attach – risk exposure to US market access restrictions and correspondent-bank consequences, even without a direct US nexus. This extraterritorial dimension means that a Swiss payment firm processing a transaction with no direct US connection may still face OFAC risk if the transaction involves a party subject to a US secondary-sanctions programme. In our cross-border practice, this is the most frequently underweighted risk in Swiss-market compliance programmes.

The EU regime, implemented through Council regulations, applies to any person or entity within the EU and to any business that clears euro-denominated payments through EU infrastructure. For Swiss payment processors with EU correspondent relationships or euro-clearing arrangements, EU Council regulations create obligations that run in parallel with SECO ordinances. The EU General Court provides an annulment route for listed parties, a procedural avenue that differs from the administrative review available under Swiss law. Where an EU designation and a SECO designation cover the same counterparty, the processor must comply with both and apply whichever standard is stricter.

A comparison of the three regimes across the dimensions most relevant to payment processing:

  • Ownership and control test: OFAC applies the 50 percent rule (equity-based, mechanical). SECO and the EU apply an ownership-and-control standard that includes non-equity control mechanisms. A counterparty that clears the OFAC threshold can still be captured under SECO or the EU.
  • Extraterritorial reach: OFAC's secondary-sanctions programmes extend to non-US persons in defined circumstances. SECO's ordinances apply to Swiss-nexus activity; the EU Council regulations apply within the EU and to EU-infrastructure clearing. Swiss processors with US correspondent accounts face all three simultaneously.
  • Reporting obligations: SECO requires reporting of frozen assets and blocked payments within a short statutory window (verify the current position before relying on it). OFAC's reporting requirements attach within a defined period of discovering blocked property. EU regulations require reporting to national competent authorities. The windows and the recipients differ; a cross-border firm must track all three.
  • Supervisory overlay: FINMA's supervisory expectations add a process-adequacy dimension that has no direct analogue in OFAC's enforcement posture. OFSI in the UK provides the closest comparator, combining substantive sanctions enforcement with a supervisory interest in systems and controls.

The key operational implication: a Swiss payment processor cannot design its compliance programme for SECO alone. The programme must account for OFAC secondary-sanctions risk on US-dollar flows, EU Council regulation obligations on euro flows, and FINMA's process-adequacy expectations across all payment rails. These are not separate programmes – they are layers of a single, integrated compliance system.

What are the risk flags that payment processors most often miss?

Several recurring gaps generate enforcement risk for Swiss payment processors. Identifying them in advance is materially less costly than addressing them after a SECO inquiry or a FINMA supervisory finding.

Nested correspondent flows. A payment that arrives from a correspondent bank may carry an originator that the correspondent has screened against its own list – but not against SECO's list, which may differ. The Swiss processor cannot rely on the correspondent's screen; it must apply its own screening to the transaction data it receives. Where the MT message or ISO 20022 record carries insufficient originator information, the processor faces a choice: request the missing data, hold the payment, or return it. Proceeding without adequate information is a risk position, not a compliance position.

Stale beneficial-ownership data. A counterparty that was clean at onboarding may have a listed person acquire a controlling stake after the account was opened. Periodic refresh – not just onboarding screening – is an obligation under SECO's ordinances and a supervisory expectation under FINMA. In our experience, firms with strong onboarding screens but infrequent periodic reviews carry a latent exposure that they often do not identify until a regulatory examination surfaces it.

Currency conversion as a proxy for transfer. A firm that converts blocked funds into another currency and then returns them has effectively made those funds available in a new form. This is not an exception to the prohibition. The conversion step does not break the chain of liability. We regularly advise clients on structuring currency-risk management in a way that does not inadvertently engage this risk.

Threshold reliance without aggregation. Applying OFAC's 50 percent rule to a SECO analysis is a category error. Switzerland's control test does not operate at a fixed equity threshold. A firm that clears counterparties below 50 percent without further analysis may be missing entities that SECO would treat as captured.

Failure to report a frozen payment within the applicable window. Freezing the payment is the first obligation; reporting it to SECO within the relevant period is a separate, mandatory obligation. Missing the reporting window is itself a breach, independent of whether the freeze was executed correctly. Verify the current reporting window before relying on any specific figure.

If a transaction has already been flagged, or a filing has been refused, an early legal review can preserve options that narrow significantly with time. Contact Calder & Vance at info@caldervance.com.

A common misconception: "Our correspondent handles SECO screening"

The most persistent myth we encounter in Swiss payment-processing mandates is that a correspondent banking relationship transfers screening responsibility. It does not. The fact that a US or EU correspondent bank has screened a transaction against its own lists does not discharge the Swiss processor's independent obligation to screen against SECO's lists and to apply Switzerland's ownership-and-control test.

Each regime's obligations bind the regulated entity within that regime's jurisdiction. A Swiss payment firm is bound by Swiss ordinances regardless of what any other party in the payment chain has or has not done. Correspondent-bank confirmation that a payment has been screened is evidence of the correspondent's compliance position – it is not a safe harbour for the Swiss intermediary.

This misconception is particularly costly when it takes hold at the operational level. A compliance officer who believes the correspondent's screen is sufficient may not configure the firm's own screening parameters to ingest SECO list updates, may not apply the control test to ambiguous counterparties, and may not maintain the internal documentation needed to defend a decision if SECO later questions it. The result is a gap that looks like a systems problem but is actually a governance problem.

The correction is structural: written policies that explicitly state the firm's independent screening obligation; technology configurations that apply SECO lists regardless of what any correspondent has provided; and governance arrangements that require a documented internal decision for any payment flagged as potentially complex.

When should a payment processor involve sanctions counsel?

Sanctions counsel adds most value at four points in a Swiss payment processor's operational cycle: programme design, a significant transaction with ownership-complexity, a SECO or FINMA inquiry, and a voluntary self-disclosure decision.

At programme design, the objective is to build a compliance architecture that satisfies SECO's substantive obligations, FINMA's process-adequacy expectations, and the OFAC and EU requirements that attach to the firm's cross-border payment rails simultaneously. Getting this right at the outset is substantially less costly than retrofitting controls after a supervisory finding. We assist payment firms in testing their screening logic, mapping ownership-and-control coverage, and designing escalation and documentation procedures that will hold up under examination.

For a significant transaction involving counterparties with complex ownership structures – a cross-border M&A settlement, a large correspondent flow with an opaque originator, or a payment to a jurisdiction where secondary-sanctions risk is elevated – counsel can work through the ownership analysis, identify the applicable prohibitions across SECO, OFAC, and the EU, and advise on whether a licence application or a structural adjustment is needed before the payment proceeds.

An inquiry from SECO or a supervisory letter from FINMA is time-sensitive. The response window is typically short. Early involvement of counsel allows the firm to scope the apparent issue, assess whether a voluntary self-disclosure (VSD) is appropriate – a process of proactively reporting a potential breach to the regulator before it identifies the issue independently – and structure the response in a way that demonstrates co-operation and effective remediation.

The VSD route under Swiss law is not a guarantee of any outcome, but co-operation and early disclosure are factors that SECO and FINMA take into account in their assessment of an appropriate regulatory response. In our cross-border practice, VSD decisions are among the most consequential calls a compliance function will make. They are not decisions to be made without legal advice.

In a recent matter, a payment platform operating across Swiss and EU jurisdictions identified a historical series of transfers that had been routed through a counterparty with an indirect connection to a listed entity. We assessed the ownership chain, mapped the exposure against SECO's control test, evaluated the interaction with the relevant EU Council regulation, and advised on the appropriate disclosure posture. The matter proceeded through the disclosure process with a documented remediation plan already in place.

Related practices

Frequently asked questions

Where do the regimes diverge on payment-processing controls?
The principal divergence is in the ownership-and-control test and in extraterritorial reach. OFAC applies a mechanical 50 percent equity threshold; SECO and the EU apply an ownership-and-control standard that captures non-equity control mechanisms, such as voting agreements and board-appointment rights. OFAC also extends secondary-sanctions risk to non-US persons processing certain payments – a reach that SECO's autonomous ordinances do not replicate but that Swiss firms with US dollar flows cannot ignore. Reporting windows, list-update frequencies, and the supervisory frameworks that sit above the substantive rules (FINMA in Switzerland, OFSI in the UK, national competent authorities in the EU) also differ in ways that require jurisdiction-specific process design.
Which regime is stricter on payment-processing controls?
No single regime is uniformly stricter across all dimensions. OFAC carries the most consequential extraterritorial reach and the largest civil penalty bases. SECO and the EU are often stricter on the ownership-and-control test because they capture non-equity control structures that the OFAC 50 percent rule does not. FINMA's process-adequacy expectations add a supervisory layer that makes Swiss compliance obligations more demanding in practice than the black-letter ordinances alone suggest. For a cross-border payment firm operating across all three regimes, the operative rule is that the stricter prohibition governs on each point of the analysis: where regimes diverge, the more restrictive requirement applies.
What should a cross-border business do about payment-processing controls?
A cross-border payment business should, at a minimum, maintain compliance with the substantive sanctions obligations of each regime that attaches to its payment flows – SECO for Swiss-nexus activity, OFAC for US-dollar and US-person flows, EU Council regulations for euro flows and EU-infrastructure clearing. Beyond the legal baseline, FINMA's supervisory expectations require documented programme governance, periodic screening-parameter testing, and escalation procedures for potential matches. Beneficial-ownership data should be refreshed periodically, not only at onboarding. Any potential breach should be assessed promptly, with legal advice, to determine whether voluntary disclosure is appropriate and to preserve options before an enforcement timeline begins to run. For a confidential review of your payment-processing compliance programme, contact Calder & Vance at info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.