Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · SECO

Apparent-violation assessment under SECO: a compliance guide

A Swiss commodity trader receives a wire-transfer query from its bank. The bank flags a potential match: a counterparty in a recent shipment appears connected to a listed entity. The trader's compliance officer is now looking at what may be an apparent violation of Swiss embargo law. What happens next, and who needs to know?

An apparent-violation assessment (a structured internal review to determine whether a transaction or relationship may breach the applicable sanctions regime) under Switzerland's embargo regime is governed by the State Secretariat for Economic Affairs (SECO), which administers Switzerland's sanctions ordinances under the Embargo Act. The assessment matters because SECO retains the authority to investigate, impose penalties, and refer matters to prosecutorial authorities – and because the window for voluntary action narrows quickly once a potential breach is identified.

This guide walks through the assessment process step by step, compares key features of the Swiss approach with those of the EU, OFAC, and OFSI, and identifies the risk flags that most often turn a containable issue into a serious enforcement matter.

Step 1: Understand the governing authority and legal basis

SECO administers Switzerland's sanctions regime under the Embargo Act and the country-specific ordinances that give it force. Each ordinance implements – and, in some respects, goes beyond – the corresponding United Nations Security Council resolution or autonomous Swiss measures. Switzerland is not an EU member, which means it maintains its own distinct legal basis and its own list of designated persons and entities rather than defaulting to the EU Consolidated List or the UN Consolidated List.

The practical consequence is that a business covered by EU sanctions and operating through Switzerland faces two separate legal regimes. A counterparty that is not listed under EU regulations may nonetheless appear on a Swiss ordinance annex, and vice versa. We regularly advise clients on exactly this divergence – and on the compliance failures that arise when a business assumes Swiss coverage mirrors EU coverage automatically.

SECO's enforcement role includes both administrative measures and criminal referrals. Intentional violations may be referred to the Office of the Attorney General or cantonal prosecutorial authorities. The distinction between an administrative and a criminal pathway matters from the outset: it shapes how the assessment is conducted, who has privilege over the analysis, and what form any voluntary communication to the authority should take.

Step 2: Gather and preserve the facts – the evidence-mapping phase

Before any analysis can proceed, the facts must be locked down. Documents disappear, systems overwrite logs, and colleagues remember events differently as time passes. Immediate preservation of the transaction record – contracts, payment instructions, shipping documents, screening logs, and communications with the counterparty – is the first practical step in any apparent-violation assessment.

In our experience, the quality of the fact record at the point of assessment determines more about the eventual outcome than almost any other factor. A firm that can demonstrate it ran screening, reviewed the results, and acted on them in good faith is in a fundamentally different position from one that cannot reconstruct what it did or when.

The evidence map should answer four questions precisely.

  • What was the transaction (goods, funds, services, or technology)?
  • Who were the counterparties, and who ultimately benefited?
  • What was the applicable ordinance at the date of the transaction?
  • What screening or due-diligence steps were taken before the transaction was executed?

Record-keeping requirements under the Swiss regime are strict: verify the current obligation period with the applicable ordinance before relying on any assumed timeframe. Gaps in the record are read by regulators as gaps in the compliance programme.

Step 3: Apply the Swiss ownership-and-control test

Swiss sanctions ordinances follow the broad UN and EU model: prohibitions apply not only to listed persons but also to entities that listed persons own or control. The ownership-and-control test (the analysis of whether a non-listed entity is effectively caught because a listed person holds sufficient ownership or exercises determining influence) is central to any apparent-violation assessment where the direct counterparty is not itself listed.

This is where the Swiss approach has a notable feature. Unlike OFAC's mechanical 50 percent rule (under which any entity owned 50 percent or more in the aggregate by blocked persons is itself treated as blocked), the Swiss ordinances – like the EU regulations and OFSI's approach in the United Kingdom – incorporate a control dimension. A listed person who holds less than 50 percent of an entity but exercises effective control over its decisions may still bring that entity within the scope of the prohibition.

Have you mapped the full ownership and control structure, or only the direct shareholding? This question is rarely straightforward for commodity-trade counterparties, joint-venture vehicles, or entities in jurisdictions with nominee shareholder structures. The control analysis requires documentary evidence, not inference.

Where control is asserted on the basis of indirect evidence – board composition, signatory authority, economic dependency – the assessment must document that reasoning. SECO, like its EU and UK counterparts, does not simply ask "who owns the shares?" It asks "who calls the shots?"

Step 4: Assess the nature and seriousness of the apparent violation

Not every screening hit translates into a legal breach, and not every breach carries the same enforcement consequence. The assessment at this stage is two-dimensional: was there a prohibition at all, and if so, was it breached in a way that warrants formal reporting or remediation action?

Swiss enforcement guidance distinguishes between intentional conduct and negligence. Criminal liability under the Embargo Act requires intent. Administrative measures can follow from negligent breach. A compliance failure that arose from a deficient screening tool, inadequate ownership mapping, or poor training is assessed differently from conduct that involved deliberate concealment or wilful disregard of known designation status.

The seriousness assessment covers several dimensions.

  • Value and nature of the transaction – financial transfers, goods shipments, and service arrangements are treated differently, and some prohibited-goods categories carry heightened enforcement attention.
  • Whether the transaction was completed or only attempted or facilitated.
  • The degree to which the firm benefited economically from the transaction.
  • Whether the firm or individuals within it had actual or constructive knowledge of the designation.
  • Whether the compliance programme in place was adequate for the risk level of the business.

In our cross-border practice, the seriousness assessment is also where the interaction between Swiss rules and other regimes becomes most acute. A business subject to EU sanctions regulations faces EU Council regulation obligations in parallel with SECO; where the EU applies a stricter prohibition, the stricter prohibition governs the EU-side analysis. This regime divergence affects decisions on whether to approach SECO proactively, whether to disclose to EU authorities simultaneously, and how to frame the overall remediation plan.

The position above covers the standard case. Your facts – the counterparty, the goods or services, the route, the regime in play – change the analysis. For an assessment of your exposure under SECO, contact Calder & Vance at info@caldervance.com.

Step 5: Consider voluntary disclosure – and what it means under Swiss law

Voluntary disclosure is one of the most consequential decisions in the apparent-violation process. Under SECO's enforcement regime, as under OFAC's, OFSI's, and the EU regulatory framework, proactive and early self-disclosure is a mitigating factor in the authority's assessment of the appropriate response. The question is not only whether to disclose, but when, how, and what to include.

A voluntary self-disclosure (VSD) to SECO is a formal communication in which a business identifies a possible breach, sets out the facts as known, describes the steps already taken, and proposes a remediation plan. It is not an admission of liability in a legally conclusive sense, but it creates a record that the authority will weigh in any subsequent enforcement assessment.

The timing of the VSD matters. A disclosure made before the authority becomes aware of the issue through its own investigations or third-party reports is viewed materially differently from one made after SECO has already opened an enquiry. In our experience, the window for maximum mitigation benefit is significantly shorter than most compliance teams assume.

There is a cross-regime dimension here too. A business that operates through EU-regulated entities must consider whether the same facts require notification to EU competent authorities under the applicable Council regulation. The UK OFSI regime has its own reporting obligation structure, including a short statutory window for reporting knowledge or suspicion of frozen assets or designated-person dealings – verify the current obligation before relying on any assumed deadline. Coordinating disclosures across jurisdictions, in the right order, is a material part of the legal strategy at this stage.

If a transaction has already been flagged by a bank, a correspondent, or a counterparty – or if SECO has made a direct enquiry – early legal advice can preserve options that narrow rapidly with time. Contact Calder & Vance at info@caldervance.com to discuss your position.

Step 6: Remediate and strengthen the compliance programme

An apparent-violation assessment that leads only to a disclosure without structural remediation misses the point of the process. Regulators – whether SECO, OFAC, OFSI, or an EU competent authority – assess the quality of the compliance programme both as a mitigating factor in the current matter and as evidence of the risk that future violations may occur.

Remediation under a Swiss enforcement context typically involves several parallel workstreams.

  • Screening: testing the logic and list coverage of the firm's screening tools against the specific SECO ordinance annexes, not only the UN Consolidated List.
  • Ownership-and-control mapping: establishing a documented methodology for analysing beneficial ownership chains beyond the first-level shareholder register.
  • Training: ensuring that the individuals responsible for compliance, trade finance, and counterparty onboarding understand both the Swiss legal basis and the firm's own escalation procedures.
  • Record-keeping: aligning document-retention practices with the applicable ordinance requirement for evidence of due diligence.
  • Policy update: reflecting any regulatory developments since the firm last reviewed its embargo procedures, including any new SECO designations or ordinance amendments.

The five-element compliance standard (governance, risk assessment, internal controls, testing and auditing, and training) is recognised informally across the major regimes. Swiss authorities, like their counterparts elsewhere, assess whether a compliance programme is genuinely operational – not merely documented. A policy that exists on paper but was not followed at the time of the apparent violation provides limited mitigation value.

How does the Swiss assessment process differ from the EU and OFAC approaches?

The Swiss process shares structural similarities with both the EU and OFAC apparent-violation assessment procedures, but three differences are practically important for any business operating across multiple regimes.

First, autonomous Swiss designations. Switzerland implements UN Security Council measures and, following its own political process, certain autonomous measures that may mirror EU positions. But the timing and scope of Swiss autonomous measures do not always track the EU precisely. A firm that screens only against the EU Consolidated List may miss a Swiss-specific listing – or, conversely, may flag an EU listing that Switzerland has not adopted. For a business trading through Geneva or Zurich with counterparties in multiple jurisdictions, this divergence requires explicit list-coverage mapping.

Second, the criminal-referral pathway. OFAC in the United States operates primarily through civil penalties, with criminal referrals reserved for egregious intentional conduct. The Swiss Embargo Act provides a direct route to criminal prosecution for intentional violations. This changes the privilege and disclosure calculus from the outset of the assessment. Counsel involvement from an early stage is not a formality; it is the mechanism by which the assessment itself retains legal-professional privilege in the Swiss system.

Third, the VSD framework is less codified. OFAC publishes detailed enforcement guidelines, including specific mitigating factors and their relative weight, with quantified penalty ranges. SECO's enforcement posture is guided by the Embargo Act and practice, but the explicit published framework for self-disclosure mitigation is less granular than OFAC's. This means that the strategic framing of a VSD to SECO requires a different approach – one grounded in demonstrating good faith, programme adequacy, and concrete remediation steps, rather than mapping to a published scoring matrix.

For clients with EU-regulated entities in the same group, our practice works through the parallel considerations: EU notification obligations, the applicable Council regulation analysis, and whether actions taken in Switzerland are consistent with – or potentially in tension with – obligations in Brussels or Paris. Read more about how we approach the EU dimension of apparent-violation assessments: Apparent-violation assessment – EU service.

For businesses with operations or counterparties in Singapore or the UAE, the apparent-violation assessment process has further regime-specific features. See our guides on apparent-violation assessment in Singapore and apparent-violation assessment in the UAE.

When to involve external sanctions counsel

Many compliance teams run the early stages of an apparent-violation assessment internally. That is often appropriate, particularly where the screening hit is a clear false positive or the counterparty relationship is straightforward. But several situations signal that external counsel should be engaged before the assessment progresses further.

  • The potential violation involves a counterparty in a sector – financial services, arms, dual-use goods, or energy – that carries heightened SECO scrutiny.
  • The ownership or control analysis turns on indirect holdings or nominee structures in opaque jurisdictions.
  • A bank has already reported a transaction to SECO or a prosecutorial authority.
  • The same facts are potentially reportable in another jurisdiction – the EU, the UK, or the United States – and coordinated disclosure is required.
  • Key individuals within the business may themselves be implicated, raising questions about the scope of the privilege over the assessment.
  • The compliance programme has systemic gaps that the apparent violation has exposed, and remediation needs to be documented for regulatory purposes.

We have acted for businesses in commodity trading, financial services, and manufacturing that have identified potential breaches under Swiss ordinances. In a recent matter, a trading company identified that payments had flowed through an intermediary with an indirect connection to a listed entity. We mapped the ownership and control structure, assessed the Swiss and EU dimensions in parallel, prepared the voluntary disclosure to the relevant authority, and designed the remediation programme. The matter was handled without criminal referral.

That outcome is not guaranteed in any case. But early, legally privileged analysis – before the assessment produces conclusions that cannot be retracted – is consistently the best available position.

Common risk flags that escalate apparent-violation matters

Most apparent-violation matters do not escalate to criminal referral or significant penalty. But a predictable set of risk flags distinguishes those that do from those that are resolved efficiently.

Failure to act promptly is the most consistently observed escalating factor. Authorities across every regime treat delay between identification of a potential violation and notification as a signal of either institutional dysfunction or deliberate concealment. Prompt action – even if the full facts are not yet established – demonstrates good faith.

Inadequate screening coverage is the second most common issue. Firms that screen against the UN Consolidated List but not against SECO's own ordinance annexes, or that screen at onboarding but not on a periodic refresh basis, face a structural gap that the apparent violation typically exposes.

A third category is the absence of documented escalation. If the compliance officer who ran the screening noted a flag but the decision to proceed was taken without documented legal or senior management sign-off, the firm cannot demonstrate that the decision was a reasoned one. The documentation of escalation – including who reviewed the flag, on what basis, and with what outcome – is a material part of the programme-adequacy analysis.

Finally, cross-regime blind spots. A business that manages its OFAC exposure carefully but has not applied equivalent rigour to SECO ordinances is exposed in exactly the gap between the two regimes. This is a pattern we see frequently in European businesses that have invested in US-facing compliance programmes but have not updated their Swiss-specific procedures as SECO's autonomous measures have developed.

Related practices

Frequently asked questions

What are the steps to assess an apparent violation under SECO?
An apparent-violation assessment under SECO begins with immediate fact preservation – securing transaction records, screening logs, and counterparty documentation. The next step is a legal analysis of whether the applicable ordinance applied to the transaction and whether the counterparty falls within its scope, including through the ownership-and-control test. The assessment then evaluates the nature and seriousness of the potential breach, determines whether voluntary disclosure to SECO is warranted, and designs a remediation programme. Legal-professional privilege should be established over the assessment before conclusions are committed to writing, particularly where a criminal-referral risk exists.
What is the most common mistake in apparent-violation assessment?
The most common mistake is delay. Businesses that identify a potential violation but wait – for more information, for a clearer picture, or for the issue to resolve itself – consistently find that the delay itself becomes a material factor in the authority's assessment. A close second is screening only against the UN Consolidated List without verifying coverage against the specific SECO ordinance annexes that apply to the transaction. Swiss autonomous designations do not always mirror UN or EU listings, and the gap between lists is where many apparent violations originate.
How does SECO differ from other regimes here?
SECO differs from OFAC principally in two respects: the Embargo Act provides a direct criminal-referral pathway for intentional violations, and the published framework for voluntary self-disclosure mitigation is less granular than OFAC's explicit enforcement guidelines. Compared to the EU, the timing and scope of Swiss autonomous designations do not always align with Council regulation listings. Compared to OFSI in the UK, SECO does not operate a short-window statutory reporting obligation in the same form. Each of these differences affects how the assessment is structured, who is involved from the outset, and how any voluntary communication to the authority is framed.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.