Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

EU vs SECO: Remediation after a sanctions breach compared

A Swiss-headquartered trading group with EU-based subsidiaries discovers, during an internal audit, that a series of payments passed through an account linked to a designated entity. The EU subsidiary processed the transactions. The Swiss parent authorised them. Two competent authorities – the European Commission's relevant enforcement structures and Switzerland's State Secretariat for Economic Affairs (SECO, the authority responsible for Swiss sanctions enforcement) – may now have an interest. Which authority leads? What disclosure obligations apply? And does remediation under one regime satisfy the other?

Remediation after a sanctions breach under EU sanctions and SECO's regime follows meaningfully different tracks. Under EU sanctions, enforcement sits with member-state competent authorities acting under Council regulations, with the European Commission playing a co-ordination role; voluntary disclosure reduces exposure but the process and weight given to it vary by member state. SECO administers a centralised Swiss regime under the applicable Swiss sanctions ordinances; it operates with a degree of procedural consolidation that the EU's fragmented enforcement structure cannot replicate. As of March 2026, both regimes treat proactive, well-evidenced disclosure more favourably than a failure to report – but the timelines, documentation standards, and cross-border sequencing differ enough to require a deliberate, co-ordinated strategy.

This analysis examines the governing authorities, the procedural steps, the key divergences, and the risk flags a cross-border business must manage when remediating simultaneously across both regimes.

How Each Regime Governs Remediation: Authority and Legal Basis

The governing authority for EU sanctions enforcement is not a single body. The relevant Council regulations confer competence on each member state to investigate, enforce, and impose penalties within its territory. The European Commission has a co-ordinating and monitoring function; it does not itself prosecute individual breaches. This structure means that a business with operations in, say, France and Germany faces the prospect of parallel national investigations governed by national procedural law, even though the underlying prohibition flows from the same Council regulation. The concept of a single EU remediation procedure is, practically speaking, a fiction.

SECO presents a different architecture. Switzerland's sanctions ordinances are adopted by the Federal Council and administered centrally by SECO. Enforcement is concentrated: SECO investigates potential breaches, refers criminal matters to the relevant federal prosecutorial authority, and operates as the primary interlocutor for businesses seeking to remediate. A business facing a SECO matter does not need to co-ordinate across multiple internal domestic authorities in the way an EU-wide breach demands.

One practical consequence is sequencing. In our experience, businesses that discover a cross-regime breach almost always benefit from engaging Swiss counsel and EU counsel simultaneously rather than sequentially. A disclosure made to one authority without reference to the other can create evidentiary complications that narrow the available remediation routes.

What Does Voluntary Disclosure Mean Under Each Regime?

Voluntary self-disclosure – a VSD (a proactive disclosure to the regulator of an apparent violation, made before the authority independently identifies it) – is a recognised mitigating factor under both the EU framework and the SECO regime, but the mechanism and the weight given to it differ substantially.

Under EU sanctions, the value of a VSD depends heavily on the member state handling enforcement. Some member states have codified guidance indicating that a timely, complete, and credible VSD will be treated as a significant mitigating factor in any penalty assessment. Others apply a more discretionary standard, and the absence of a harmonised EU-wide VSD procedure means that a business remediating across multiple jurisdictions may receive inconsistent credit for the same disclosure. The member state of the competent authority receiving the VSD is therefore a material variable, not a background fact.

SECO's approach is more consolidated. A disclosure made directly to SECO, accompanied by a factual account of the violation, the goods or funds involved, and the steps taken to halt the conduct, enters a process managed by a single authority. SECO has published guidance indicating that co-operation and proactive disclosure are considered in its enforcement decisions. The Swiss criminal referral threshold is a relevant consideration: where conduct crosses into the criminal domain, the matter shifts to federal prosecutors, and the value of SECO-level co-operation, while not eliminated, is reconfigured.

For a cross-border business, the question is therefore not simply whether to disclose, but to whom, in what order, and with what package of evidence. Disclosing to SECO before any EU member-state authority has opened a file does not insulate the EU entities from investigation. But a well-timed, co-ordinated disclosure – drafted to satisfy the evidential expectations of both regimes – can preserve mitigating-factor credit across both tracks.

The position above covers the standard case. Your facts – the transaction type, the jurisdictions of the entities involved, the nature of the designated counterparty, and the volume of the breach – change the analysis materially. For an initial assessment of your exposure under both regimes, contact Calder & Vance at info@caldervance.com.

The Remediation Procedure Step by Step: A Comparative Sequence

Effective remediation under either regime requires a structured sequence; running the steps out of order, or conflating the two regimes, is a common source of avoidable exposure.

The first step, common to both regimes, is an internal fact-finding review. The purpose is to establish what happened, who authorised it, what was transacted, and whether the conduct is continuing. Speed matters. A continuing breach – where prohibited funds are still held or a prohibited relationship is ongoing – creates an immediate obligation to cease and, in most EU member states and under SECO guidance, to freeze or suspend the relevant assets or transactions. A remediation plan built on an incomplete factual record is unlikely to satisfy either authority.

The second step is legal privilege assessment. In our practice, we routinely advise clients to conduct the internal review under legal professional privilege from the outset. The question of whether communications and documents generated during an internal investigation are privileged against disclosure to the competent authority is governed by national law in the EU and by Swiss law in the SECO context. The rules are not identical. Structuring the review to preserve privilege under both legal systems requires deliberate attention at the start, not as an afterthought.

The third step is drafting the disclosure package. For the EU track, the package must address the specific requirements of the relevant member-state authority. For SECO, it must meet the documentary expectations set out in SECO's published guidance. Both will expect: a factual narrative of the violation; the identity of the goods, funds, or services involved; a description of the business's compliance programme at the time of the breach; the corrective measures already taken; and the prospective remediation steps. A single document drafted to satisfy both sets of expectations is achievable but requires careful drafting; the two authorities are not the same audience.

The fourth step is submission and engagement. The timing and channel of submission differ. EU member-state authorities may have specified reporting windows or statutory notification requirements under the relevant national implementation legislation. SECO operates under its own procedural timetable. Critically, neither regime's remediation track is self-executing: submission does not close the matter. Both authorities will typically engage with the business, request supplementary information, and assess the adequacy of the remediation programme before deciding whether to issue a penalty, a warning, or a closure.

Where Do the Regimes Diverge Most Sharply on Remediation?

The most significant divergences sit in four areas: the role of member-state discretion, the criminal exposure threshold, the treatment of compliance-programme adequacy, and the extraterritorial dimension.

Member-state discretion is the EU's defining structural feature in this context. When a breach involves entities in multiple EU member states, the competent authorities of each state may investigate and penalise independently. There is no formal mechanism that consolidates the matter into a single EU-level proceeding. The result is that a business operating across several member states may face multiple parallel investigations, each applying national procedural law and each with its own penalty regime. Co-ordinating these in parallel – while managing the SECO track – is a demanding exercise that requires a clear cross-border strategy from day one.

Switzerland's criminal exposure threshold is a key variable. Under the applicable Swiss ordinances, certain sanctions violations carry criminal liability rather than purely civil or administrative consequences. The threshold at which SECO refers a matter to federal prosecutors is not a fixed formula, but it turns on factors including the volume of the violation, whether the conduct was deliberate or reckless, and the quality of co-operation offered. In our experience advising on Swiss enforcement matters, the distinction between an administrative resolution and a criminal referral is the single factor that most drives the urgency of early legal engagement. Have you assessed whether your facts sit above or below that threshold?

The EU's approach to compliance-programme adequacy as a mitigating factor is less standardised than SECO's. Several EU member states with significant enforcement activity have published guidance indicating that the existence of a well-designed sanctions compliance programme at the time of the breach, and its enhancement as part of the remediation, will be treated as mitigating. Others treat programme quality as relevant but give it less weight. SECO's guidance, while not exhaustive, addresses the quality of internal controls more directly as a factor in its assessment of co-operation credit. A business that has invested in its programme has a stronger narrative before SECO than it may have before an EU member-state authority in a jurisdiction with less developed enforcement guidance.

Extraterritoriality adds a fourth dimension. Both the EU regime and the SECO regime have extraterritorial features: they can catch conduct by non-EU or non-Swiss entities where the relevant nexus to the jurisdiction is present. A parent company seated outside both jurisdictions may nonetheless face exposure if it authorised or facilitated the breach by the EU or Swiss subsidiary. The analysis of which entities are caught, and by which authority, is fact-specific. For a business also touched by OFAC or OFSI, the cross-regime picture becomes significantly more complex, and the sequencing of disclosures across all active regimes requires careful co-ordination.

If a transaction has already been flagged or an internal investigation has surfaced an apparent breach, an early review can preserve options that narrow quickly with time. Write to us at info@caldervance.com for a confidential assessment.

Risk Flags That Complicate Remediation

Several patterns consistently create difficulty in cross-regime remediation, and recognising them early changes the outcome.

The first is continuing conduct. A business that has identified a breach but has not yet ceased the relevant transactions or frozen the relevant assets is, in most cases, still violating the prohibition. Both EU member-state authorities and SECO treat a failure to halt ongoing conduct as a serious aggravating factor. Speed of cessation is therefore a key variable in the penalty assessment, not merely a procedural step.

The second is incomplete ownership-and-control mapping. A breach that arises from a failure to identify that a counterparty was owned or controlled by a designated person – the ownership and control test (the test under EU and Swiss law for whether a non-listed entity is caught through a listed person) – will attract scrutiny of the screening programme that failed to identify the connection. If the programme was inadequate, the remediation package must address the gap with specificity. A generic assertion that controls have been improved is unlikely to satisfy either authority.

The third is document preservation. Internal communications created during or immediately after discovery of a breach are routinely requested by investigating authorities. In our practice, we have seen cases where informal messaging – produced before any legal structure was put around the internal review – significantly complicated the business's position. Preserve everything; instruct counsel to advise on privilege before any document is shared externally.

The fourth is parallel proceedings risk. Where the same breach engages both EU enforcement and a SECO investigation, the risk of inconsistent factual representations made to two separate authorities – even inadvertently – is real. Disclosures should be co-ordinated so that the factual narrative is consistent across both tracks. Inconsistency, once identified by an authority, damages credibility and can convert a co-operative remediation into a contested enforcement matter.

A fifth risk flag is the interaction with financial-institution obligations. Where the business is a regulated entity – a bank, a payment firm, or a virtual-asset service provider – the breach will likely engage separate reporting obligations to the prudential or financial-crime regulator, in addition to the sanctions authority. Those obligations run on their own timetables and are not suspended because a sanctions remediation is in progress.

Common Misunderstanding: Is a Single Remediation Package Sufficient?

A prevalent assumption among businesses encountering a cross-regime breach for the first time is that a single, well-prepared disclosure package submitted to one authority will effectively resolve the matter across both regimes. This assumption is incorrect, and acting on it is among the most consistently costly errors we see in cross-border enforcement work.

The EU regime and the SECO regime are distinct legal instruments administered by separate authorities. A resolution with SECO does not bind any EU member-state competent authority, and vice versa. A disclosure made to a French authority does not constitute notice to SECO. A company that obtains a favourable administrative resolution from SECO still faces potential action from the relevant EU member-state authorities if those authorities independently identify the same breach or receive information about it.

The reverse is equally true. An EU member state closing a file does not close the Swiss track. And where the breach also engages OFAC – for instance because US-dollar transactions were involved, or because US-origin goods were shipped – a third concurrent track may apply. The cross-regime picture is additive, not substitutive: each regime must be addressed on its own terms.

What a co-ordinated strategy can achieve is the use of a common factual core across multiple disclosure packages, drafted to meet each authority's specific expectations, submitted in a sequence that maximises mitigating-factor credit across all active tracks. This is not a single document; it is a managed process. The distinction matters.

In a recent matter, a manufacturing business with subsidiaries in two EU member states and a parent in Switzerland discovered, following a compliance review, that it had transacted with entities linked to a designated person over a period of several months. We conducted a privilege-protected internal review, mapped the full ownership and control chain of the counterparties, and prepared co-ordinated disclosure packages for the relevant EU member-state authorities and SECO. The matter proceeded through the administrative resolution track in each jurisdiction, and the business was able to demonstrate a materially enhanced compliance programme as part of the remediation. No criminal referral was made in the Swiss track.

When to Involve Counsel – and What to Do First

The threshold for involving external sanctions counsel in a potential breach is lower than most compliance teams initially assume. The decision to conduct an internal review without external advice is understandable; it is also the decision most likely to generate complications that could have been avoided.

The considerations that should trigger immediate external advice include: a breach involving assets or transactions above a material value; a breach involving a counterparty directly on the relevant consolidated list rather than caught only through the ownership test; a breach where the conduct may have been deliberate or reckless rather than negligent; any situation where multiple regimes are simultaneously engaged; and any situation where the business is also a regulated entity with parallel regulatory reporting obligations.

What should be done first, before counsel is even engaged, is preservation and cessation: preserve all relevant documents and communications, and cease any ongoing prohibited conduct. These two steps are independent of legal advice and should not await it. Everything else – the scope of the internal review, the privilege structure, the disclosure strategy, the sequencing – should be designed with counsel.

Our practice at Calder & Vance covers apparent-violation assessment, remediation strategy, internal-review management, disclosure drafting, and enforcement-defence representation before EU member-state competent authorities and SECO. We also co-ordinate with local counsel in the relevant jurisdiction where national enforcement law requires specialist in-country representation. For matters that engage OFAC or OFSI alongside EU and Swiss enforcement, our cross-border structure provides coverage across those regimes under one engagement.

Related practices

Frequently asked questions

Where do the regimes diverge on remediation after a sanctions breach?
The deepest divergence is structural: the EU operates through multiple member-state competent authorities applying national procedural law under the same Council regulation, producing a fragmented enforcement picture. SECO is a single, centralised authority with consolidated oversight of the Swiss sanctions ordinances. The two regimes also diverge on the criminal exposure threshold, the standardisation of voluntary-disclosure credit, and the procedural expectations for a remediation package. A cross-regime breach requires a strategy that addresses each regime's requirements separately, not a single submission to one authority.
Which regime is stricter on remediation after a sanctions breach?
Neither regime is uniformly stricter; the relevant variable is the specific member state conducting EU enforcement. Some EU member states apply a demanding penalty and disclosure standard with well-developed enforcement guidance; others operate with less procedural certainty. SECO offers greater procedural consolidation, but its criminal referral pathway – where applicable – carries consequences that exceed purely administrative EU penalties. The correct question is not which regime is stricter in the abstract, but which facts and jurisdictions are engaged in your specific matter, and what the applicable procedural and penalty standards are in each of those jurisdictions.
What should a cross-border business do about remediation after a sanctions breach?
Cease any ongoing prohibited conduct immediately and preserve all relevant documents. Do not make any disclosure to any authority before taking legal advice on privilege, sequencing, and the evidential expectations of each competent authority in play. Engage sanctions counsel with cross-regime coverage as early as possible: the remediation strategy should address each active regime simultaneously, not sequentially. Where the breach also engages OFAC, OFSI, or other regimes, the sequencing of disclosures across all active tracks must be co-ordinated to maximise mitigating-factor credit and avoid inconsistent representations.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.