A Swiss-headquartered trading company discovers, during a post-acquisition compliance review, that a subsidiary has been processing payments routed through a counterparty whose ultimate beneficial owner appears on both an EU list and Switzerland's SECO ordinances. The transactions pre-date the acquisition. Two regulators. Two disclosure windows. Two very different procedural expectations. Which disclosure goes first – and does filing with one authority affect the other?
Voluntary self-disclosure (a proactive report by a business to its regulator that it has committed an apparent violation, made before the regulator discovers it independently) is available under both the EU sanctions regime and Switzerland's regime administered by SECO (the State Secretariat for Economic Affairs). The two regimes treat disclosure very differently: the EU leaves timing, format, and credit largely to Member State implementation, while SECO operates under a single federal framework with its own procedural expectations. Getting the sequencing wrong – or omitting facts that one regime requires and the other does not – creates avoidable enforcement exposure.
This analysis compares the two regimes across the decision points that matter most: the trigger for disclosure, the procedural requirements, the mitigating credit on offer, the cross-border interaction, and the risk flags that experienced practitioners see most often.
What governs voluntary self-disclosure under the EU sanctions regime?
The EU sanctions regime does not operate a single, centralised self-disclosure mechanism. EU Council regulations impose the substantive prohibitions; enforcement is a matter for each Member State. A business disclosing a potential violation of an EU sanctions regulation must therefore identify the competent national authority in each relevant Member State – which may be a financial intelligence unit, a central bank, a trade authority, or a dedicated financial-sanctions authority – and comply with that authority's procedural requirements.
This structural feature is the first thing many businesses miss. A company with operations in Germany, France, and Italy may face three different authorities, three different reporting formats, and three different expectations about what a disclosure must contain. The EU Council regulation defines the offence; the Member State defines the process for reporting it. In our experience, businesses that treat the EU as a single enforcement jurisdiction consistently under-prepare their disclosures.
The legal basis for the underlying prohibitions sits in the relevant EU Council regulation and the corresponding Council Decision. Enforcement guidance – to the extent it exists – is issued at Member State level, and its depth varies considerably. Some Member States have published detailed frameworks setting out how a disclosure will be assessed; others operate largely on regulatory discretion. That variability is not merely an administrative inconvenience. It directly affects how much mitigating credit a disclosure can realistically achieve.
What the EU regime does require consistently, at the Council-regulation level, is a reporting obligation when blocked funds or assets are identified: a business holding blocked property must report it to the relevant competent authority within a short statutory window. That obligation is separate from self-disclosure of a historical violation, but the two interact. A business that failed to report blocked property in real time and now wishes to disclose that failure must address both the underlying substantive violation and the reporting failure.
How does SECO's voluntary self-disclosure process differ?
SECO administers Swiss autonomous sanctions under the federal sanctions ordinances, which broadly mirror EU measures but are adopted independently and are not automatically synchronised with EU list updates. A single federal authority handles both the substantive assessment and the enforcement decision, which gives SECO's process a consistency and predictability that the multi-authority EU model cannot match.
Switzerland does not have a formal statutory self-disclosure programme in the way that OFAC's voluntary self-disclosure (VSD) process is codified. SECO's approach is grounded in general administrative-law principles: a proactive, cooperative approach is a recognised mitigating factor in penalty assessment, and the federal authorities have publicly acknowledged the relevance of disclosure timing and completeness. The practical effect is similar to a formal programme – disclosure before detection reduces exposure – but the framework is less prescriptive about format and timing than some other regimes.
One consequence of SECO's federal structure is that a business disclosing to SECO does not need to worry about identifying a patchwork of competent authorities. The submission goes to one place. That administrative simplicity can be misleading, however: SECO's substantive expectations for what a disclosure must cover are demanding. A bare notification that a violation occurred is insufficient. The authority expects a factual account of how the violation arose, what the business did when it discovered the issue, and what remedial steps have been or will be taken.
SECO also coordinates closely with Swiss financial intelligence and with FINMA in cases where the entity concerned is a regulated financial institution. A business that is FINMA-regulated and discloses a sanctions violation to SECO should expect the two authorities to communicate. In our practice, treating these as independent channels has caused clients to inadvertently create inconsistencies between regulatory filings – a problem that is both avoidable and serious.
Where do the regimes diverge on voluntary self-disclosure?
The divergence between the EU and SECO regimes runs along four fault lines: the identity of the receiving authority, the degree of procedural formalisation, the basis for mitigating credit, and the interaction with parallel criminal exposure.
First, authority identity. Under the EU regime, the receiving authority depends on the Member State. Under SECO, it is always SECO. For a business with a multi-jurisdictional footprint, the EU dimension typically requires a coordinated filing strategy across several national authorities, while the Swiss dimension is a single submission. The risk in the EU context is inconsistency: facts stated one way in Germany and differently in France will be noticed by sophisticated regulators and will damage credibility.
Second, procedural formalisation. OFAC, for comparison, publishes detailed guidance on what a VSD must contain. SECO's expectations are communicated through regulatory practice rather than published checklists. The EU Member States range from those with detailed published frameworks to those where the expectation is essentially informal. A business preparing an EU self-disclosure cannot assume that the format adequate for one Member State will satisfy another.
Third, mitigating credit. Both regimes recognise disclosure as a mitigating factor. The EU regime – because it is implemented by Member States – offers credit whose quantum varies considerably by jurisdiction. Some Member States operate penalty regimes that treat voluntary disclosure as producing a substantial reduction; others treat it as one factor among many with no prescribed weighting. SECO operates within a federal framework in which the mitigating effect of disclosure is recognised in principle but is not quantified in published guidance. The practical implication is that the value of a disclosure cannot be precisely predicted in advance under either regime, and counsel who represent it otherwise are overstating what can be known.
Fourth, criminal exposure. Sanctions violations in several EU Member States can give rise to criminal liability alongside administrative penalties. In Switzerland, intentional violations of the sanctions ordinances can also attract criminal prosecution under federal law. A business disclosing to SECO or to an EU Member State authority must assess, before filing, whether the disclosure could simultaneously constitute or trigger a criminal referral. Where criminal exposure is real, the self-disclosure strategy must be designed with criminal-defence considerations in mind from the outset – not retrofitted after the administrative submission has been made.
The position above covers the structural divergence. Your facts – the transaction type, the Member States involved, whether SECO's ordinances capture the same conduct as the EU regulation, and whether the violation is continuing – change the analysis significantly. If a transaction has already been flagged, or a potential violation has been identified, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your situation.
What are the risk flags practitioners see most often?
Cross-border businesses making their first voluntary self-disclosure under either regime consistently encounter the same set of avoidable problems. Understanding them in advance is the difference between a disclosure that achieves its purpose and one that creates additional exposure.
The first risk flag is delayed internal escalation. A compliance officer who identifies a potential violation and spends several weeks confirming it before escalating to legal counsel is consuming time that should be used to assess the disclosure strategy. Both the EU Member State authorities and SECO assess the speed of response after internal discovery as part of the overall picture of cooperation. A business that sat on a known issue for an extended period before disclosing will find that timeline scrutinised.
The second flag is incomplete scope. A self-disclosure that covers the transactions the business has already identified but misses others that a competent regulator would find through its own investigation is worse than no disclosure at all. It converts a cooperative business into one that has disclosed misleadingly. In our experience, the initial scope assessment consistently underestimates the full population of affected transactions. A systematic lookback – properly resourced and legally directed – is not optional if the disclosure is to be credible.
The third flag is parallel-filing inconsistency. Where the same conduct is caught by both the EU regime and the Swiss SECO ordinances, the two filings must be factually consistent. Different characterisations of the same transaction in two regulatory filings create the appearance of selective disclosure and attract closer scrutiny from both authorities. The factual narrative must be agreed centrally before any filing is made.
The fourth flag is underestimating remediation expectations. Both regimes expect a disclosure to be accompanied by a credible account of what the business is doing to ensure the violation does not recur. A disclosure that identifies the problem but does not address the root cause – the control failure, the screening gap, the approval-process deficiency – will not carry the same mitigating weight as one that pairs the disclosure with a defined remediation plan.
A fifth flag deserves particular attention for businesses holding ownership and control (the test for whether a non-listed entity is caught through a listed person's holding) positions that were not fully analysed at the time of the violation. If the original transaction was approved on the basis of a screening check that did not look through to the beneficial-ownership level, the disclosure must address why the ownership analysis was inadequate – not merely describe the resulting violation.
Which regime is stricter on voluntary self-disclosure?
Neither regime is unconditionally "stricter" than the other; the better question is which creates more unpredictability, and the answer is the EU regime, by a material margin. The Swiss federal structure means that SECO's expectations, while not precisely codified, are at least consistent: one authority, one set of regulatory expectations, one assessment process. The EU's Member State implementation model creates genuine divergence in penalty quantum, procedural expectation, and the weight given to mitigating factors.
That said, SECO is not a lenient authority. Switzerland's sanctions enforcement has become more assertive in recent years as the country has expanded its autonomous sanctions programme. The fact that Switzerland operates a single federal enforcement authority means that a decision by SECO to refer conduct for criminal prosecution – rather than to handle it administratively – is made by the same body that received the disclosure. In the EU context, the referral to a prosecuting authority is a separate step, often involving a different institution. In the Swiss model, the authority receiving the disclosure and the authority with the power to make a criminal referral are more directly connected.
For a business with exposure under both regimes, the practical implication is clear: SECO's consistency is an advantage in planning; the EU's variability requires a jurisdiction-by-jurisdiction analysis before any filing is made. Treating the EU as a single enforcement environment – or assuming that a disclosure format adequate for one Member State will transfer to another – is the single most common mistake we see in cross-border disclosure matters.
A cross-border disclosure scenario: what the analysis looks like in practice
In a recent matter, a logistics business with operations in three EU Member States and a Swiss parent entity identified, during an internal audit, a pattern of freight transactions that had moved goods through a routing arrangement whose ultimate beneficiary was associated with a listed entity under both EU Council regulations and the applicable SECO ordinance. The transactions spanned approximately eighteen months and involved multiple invoicing entities.
The first decision was whether to disclose at all. The conduct was not clearly intentional; the routing arrangement had been approved by a commercial team that had not escalated it to compliance; and the control failure – a gap in the counterparty-due-diligence process for freight intermediaries – was identifiable and remediable. Those factors pointed toward disclosure. The risk of the pattern being detected independently – through a financial intelligence submission by the correspondent bank, which was separately obligated to report – made non-disclosure untenable.
The second decision was sequencing. SECO was approached first, on the basis that the Swiss parent entity was the controlling entity and the Swiss filing could be made as a single, centrally coordinated submission. The EU Member State filings followed, calibrated to each national authority's procedural expectations, with a factual narrative that was deliberately consistent with the SECO submission. The remediation plan – a redesigned freight-intermediary due-diligence process and a revised approval workflow – was presented to all authorities simultaneously.
The matter resolved without criminal referral. The outcome was not guaranteed, and we do not represent it as reproducible in every case. What the scenario illustrates is that cross-border voluntary self-disclosure under these two regimes rewards early legal involvement, disciplined scope assessment, and a centrally managed filing strategy. Improvised, piecemeal disclosure – filing with one authority before the analysis is complete – consistently produces worse results.
What should a cross-border business do about voluntary self-disclosure?
A business that identifies a potential sanctions violation should move through a defined sequence. That sequence is not merely procedural; each step creates or preserves options that a later step may not be able to recover.
The first step is to establish legal privilege over the internal review. Work product generated before counsel is instructed may not be protected. A disclosure investigation that begins as an unprotected internal audit and only later involves counsel has already compromised the privilege position. Instruct counsel before the investigation begins, not after the facts are assembled.
The second step is a rapid scope assessment. The compliance team identifies the initial population of transactions; counsel directs a systematic lookback to identify the full population. These are different tasks, and conflating them – treating the initial identification as the completed scope – is a consistent source of incomplete disclosures.
The third step is a filing-strategy decision. Under which regimes is the conduct caught? Which Member States are relevant? What is the relationship between the EU filing and the SECO filing? What is the criminal-exposure profile in each jurisdiction? These questions must be answered before any filing is made.
The fourth step is a remediation plan. A disclosure without a remediation plan is a statement of a problem. A disclosure paired with a credible, costed, timeline-bound remediation plan is a demonstration of cooperative engagement. The difference matters, and regulators notice it.
The fifth step – too often treated as the last – is communication management. Who in the business knows about the disclosure? Who will manage communications with the regulatory authority during the review period? What is the plan if the authority asks for additional information? These questions, unanswered, have derailed disclosures that were otherwise well-constructed.
If a potential violation has been identified, or if you are unsure whether a transaction triggers a disclosure obligation under the EU regime, the SECO ordinances, or both, early advice is the most cost-effective step available. Contact Calder & Vance at info@caldervance.com for a confidential review.
A common misconception: disclosure is the same as settlement
One myth we encounter regularly, particularly among compliance officers dealing with their first apparent sanctions violation, is that voluntary self-disclosure is a form of pre-agreed settlement – that filing a disclosure commits the authority to a lighter outcome. That is not how either the EU Member State authorities or SECO operate.
Disclosure is an input to the enforcement assessment. It is a mitigating factor, and in some Member States it is a significant one. But it does not remove the authority's discretion to investigate further, to refer to a prosecuting authority, or to assess a penalty that reflects the seriousness of the underlying conduct. A business that discloses a large, systematic violation is not protected from a serious enforcement outcome by the act of disclosure alone. What disclosure does is demonstrate cooperation, remove the aggravating factor of concealment, and preserve options – including the ability to engage constructively with the authority's questions – that would not be available if the violation were discovered independently.
Understanding this distinction matters practically. A business that views disclosure as a settlement mechanism may construct its submission to minimise the apparent seriousness of the violation, rather than to provide an accurate and complete account. That approach routinely backfires. Regulators are experienced at identifying submissions that are technically complete but strategically minimised. In our experience, a straightforward, complete, and proactively cooperative disclosure consistently produces better outcomes than one that is technically adequate but tonally defensive.
Related practices
- EU Apparent Violation Assessment – scope, assess, and advise on apparent EU sanctions violations before they reach the regulator
- OFAC vs Canada: Voluntary Self-Disclosure Compared – how US and Canadian disclosure regimes diverge and what that means for cross-border businesses
- OFAC vs OFSI: Voluntary Self-Disclosure Compared – the US and UK disclosure frameworks side by side, including timing and credit differences