A Swiss-based trading house wins a commodity contract routed through three jurisdictions. Its compliance officer screens the counterparty, flags a possible match against the SECO consolidated list, and then asks: does our programme actually tell us what to do next? For many cross-border businesses operating under Swiss sanctions rules, that question has no clear answer – because the programme was never built to answer it.
Sanctions compliance programmes under SECO (the State Secretariat for Economic Affairs, Switzerland's primary sanctions authority) must map the full scope of Swiss embargoes, establish ownership and control analysis, and set out a documented response procedure for every prohibited-transaction trigger. As of July 2026, Switzerland maintains autonomous sanctions that increasingly mirror EU Council designations, but the legal basis and the administrative enforcement path differ in material ways from EU, OFAC, and OFSI regimes.
This guide walks through the seven practical steps required to build, test, and maintain a SECO-compliant programme, with cross-regime comparisons at each stage where they change the design.
Step 1: Understand the scope of Swiss sanctions and the authority behind them
A SECO sanctions compliance programme begins with a clear understanding of which legal instruments apply, because the Swiss embargo regime does not derive from a single consolidated statute in the same way OFAC draws authority from IEEPA or OFSI from SAMLA.
Switzerland enacts sanctions through ordinances adopted under the Embargogesetz (the Federal Act on the Implementation of International Sanctions), which authorises the Federal Council to issue binding measures. SECO administers those measures and publishes the applicable ordinances and the corresponding lists of designated persons and entities. The United Nations Consolidated List forms the mandatory floor; Switzerland then layers autonomous measures that, in recent years, have tracked EU Council designations closely – but not identically.
Why does this matter for programme design? Because the Swiss list and the EU list diverge on specific designations, dates of listing, and identifying information. A business that screens only against the EU list will miss entries that appear exclusively on the Swiss list, and vice versa. In our cross-border practice, we regularly advise clients who run a single EU-based screening feed and assume it covers Switzerland. It does not. The programme must pull from the SECO-published source directly.
The key instruments to identify at the outset are the applicable Federal Council ordinances for each programme relevant to the business – typically covering specific country regimes, thematic designations, and the transposition of UN measures. Understanding which ordinances apply determines the scope of the prohibited-transaction analysis in every subsequent step.
Step 2: Map your business activities to SECO's prohibited-transaction categories
Once the applicable ordinances are identified, the next step is a structured mapping of the business's activities against SECO's prohibited-transaction categories, because Swiss embargoes prohibit different things under different ordinances and the scope of the activity-level prohibition determines what controls are needed.
Swiss sanctions ordinances typically prohibit: making funds or economic resources available to designated persons or entities; engaging in transactions related to listed goods or technologies; and providing financial, brokering, or technical assistance in connection with prohibited conduct. The precise scope varies by ordinance. Some measures include sectoral restrictions that apply without a designation trigger. Others focus narrowly on listed persons.
The mapping exercise should produce a register of every business activity category – payments, trade finance, physical goods movements, services, treasury operations, intermediary arrangements – matched to the applicable prohibition type. Activities that fall outside the scope of the relevant ordinances are noted as such, but not ignored: SECO's scope can expand on short notice when new Federal Council ordinances are adopted.
Compare this with the EU position. Under EU Council regulations, the prohibition categories are set at the regulation level and apply uniformly across member states. SECO's prohibitions, by contrast, are set ordinance by ordinance. A business that trades goods under both EU and Swiss obligations must map both sets of prohibitions separately and design controls that satisfy both. Where the Swiss prohibition is stricter, the stricter rule governs across the group.
Step 3: Build the ownership and control analysis into the programme
Knowing who is directly designated is only part of the exposure picture; the programme must also capture entities and individuals that SECO treats as within the scope of a prohibition because of their relationship to a listed person.
Swiss sanctions ordinances do not contain the same explicit mechanical 50 percent rule that OFAC publishes under IEEPA guidance, treating entities owned 50 percent or more by blocked persons as themselves blocked. The Swiss position instead requires an analysis of whether a transaction in substance makes funds or economic resources available to a designated person – which means that effective ownership or control of the counterparty by a listed individual can engage the prohibition even absent a direct designation.
In our experience, this functional approach is harder to operationalise in a screening programme than OFAC's bright-line threshold, because it requires a qualitative judgment about the relationship between the counterparty and the listed person. The programme should set out a clear decision tree: what ownership threshold triggers enhanced due diligence, what information is required before a transaction proceeds, and who in the organisation has authority to clear a flagged item.
The EU test – which includes both an ownership limb and a control limb – offers a useful parallel. Under the EU position, an entity can be caught through control even where the listed person's shareholding falls below a majority stake, if that person directs or otherwise controls the entity's conduct. Building an EU-equivalent control analysis into the SECO programme provides a more conservative and legally defensible position than a bare ownership check. Where the business is also subject to EU sanctions, the combined test is already required.
Document the ownership-and-control methodology explicitly in the written programme. The documented methodology is the primary evidence of due diligence if SECO or a Swiss enforcement authority examines a transaction.
Step 4: Design the screening architecture and data inputs
Screening is the operational engine of a SECO compliance programme, and the design of that engine – what lists are screened, against what data fields, at what frequency, and with what matching logic – determines whether the programme actually detects exposure.
At minimum, the programme must screen against the SECO consolidated list (published and updated by SECO directly), the UN Consolidated List (as adopted by Switzerland), and any relevant sector- or country-specific lists under the applicable Federal Council ordinances. For businesses also subject to EU obligations, the EU consolidated list is a parallel mandatory input. For those with US nexus – dollar clearing, US-person employees, goods of US origin – the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the Entity List maintained by BIS are also required inputs.
Frequency is a design choice that must be documented and justified. Batch screening of counterparty databases at regular intervals is a minimum. For high-value or high-risk transactions, real-time screening at the point of transaction initiation is the stronger position. Payment firms and financial institutions handling high volumes have different requirements from exporters processing a smaller number of large contracts – the programme must reflect the actual transaction profile.
Fuzzy matching is the most consequential technical parameter. Name variants, transliteration differences, and aliases all require a matching algorithm that catches likely equivalents without generating an unmanageable volume of false positives. There is no single correct threshold. What the programme must do is document the chosen threshold, the rationale, and the testing results that support it. An undocumented matching algorithm is a compliance gap – not because it necessarily produces wrong results, but because it cannot be demonstrated to produce right ones.
Step 5: Establish the escalation and decision process for flagged transactions
Screening generates alerts; the programme must prescribe what happens next, because the speed and quality of the response to a flagged transaction is where enforcement scrutiny most often focuses.
The escalation process should distinguish three alert states. First, an alert that resolves quickly as a false positive through documented false-positive analysis – the name match is not the same person; the identifying information differs materially. Second, an alert that cannot be resolved without further information from the counterparty or a third-party source. Third, an alert that confirms or strongly suggests a match with a designated person. Each state requires a defined next step, a responsible function, and a time limit.
For confirmed or near-confirmed matches, the process must address: whether the transaction is prohibited, whether any licence or exemption could authorise it, whether a voluntary self-disclosure (VSD, the practice of self-reporting a potential violation to the regulator before being contacted) is appropriate, and whether any pre-existing funds or assets are subject to a freezing obligation. The programme should not leave these questions to case-by-case improvisation. The answers should be pre-structured by reference to the applicable ordinances and SECO's published guidance.
Cross-regime considerations are important here. Under OFSI in the United Kingdom, reporting obligations for financial institutions are specific and carry statutory force; failure to report knowledge or suspicion of a breach within the required window is itself a violation. SECO's reporting regime operates differently. The programme must be calibrated to whichever reporting obligation is strictest for the jurisdiction in which the relevant entity sits. Where the business has both a Swiss entity and a UK entity, both reporting tracks must be serviced.
Step 6: Set governance, training, and record-keeping standards
A SECO compliance programme that is well-designed but poorly governed degrades quickly. Governance, training, and record-keeping are the structural elements that keep the programme effective over time.
Governance requires a named owner of the programme – typically the Head of Compliance or General Counsel – with clear authority and reporting lines to the board or the executive committee. The programme should specify how often the regime ordinances are reviewed for updates, who is responsible for that review, and how changes are cascaded into screening logic and staff procedures. This is not a formality. SECO and the Federal Council can and do update the list of designated persons and the scope of ordinances at relatively short notice, particularly when Swiss autonomous measures are adjusted in response to international developments.
Training must cover the categories of staff who interact with counterparties, transactions, or the screening system. The scope and depth of training should be proportionate to the role. Front-office staff in trade finance need to understand the transaction-level prohibition categories. Compliance analysts running the screening platform need a more detailed understanding of the matching logic, the escalation threshold, and the decision criteria. Senior management need sufficient literacy to ask the right questions at the right time.
Record-keeping is often the area where programmes that perform well in substance fail in examination. The programme should specify the categories of records to be retained – screening outputs, false-positive analyses, escalation decisions, licensing applications, correspondence with SECO, training records – and the retention period. Qualitatively, sanctions regulators across jurisdictions typically expect records to be retained for a period of years sufficient to cover the limitation period for enforcement action; verify the applicable SECO expectation before setting the specific figure for your programme.
Step 7: Test the programme and plan for review
A compliance programme that has never been tested against realistic conditions does not actually demonstrate compliance; it demonstrates intention. Testing converts intention into evidence.
Testing should operate at two levels. First, periodic transaction testing: a structured sample of completed transactions is reviewed against the programme's own requirements to check whether screening was performed, alerts were handled correctly, and records were created. This is the minimum and catches the most common operational failures – screening that was bypassed, alerts that sat unresolved, escalation that never reached the required authority. Second, scenario testing: the programme is run through hypothetical fact patterns – a layered ownership structure where a listed person holds interests through two intermediary entities, a payment cleared before the list was updated, a service contract where the counterparty's beneficial owner subsequently appears on the SECO list. Scenario testing identifies gaps in the written procedure before an actual event exposes them.
We regularly advise clients at the point where a transaction has already been flagged or a filing has been refused. In every such engagement, the businesses that have the best outcomes are those with documented testing and review records, because those records demonstrate a programme that was functioning and active, not a policy document sitting on a server.
Review cycles should be at least annual, and triggered also by material changes: a new Federal Council ordinance, a significant change in the business's counterparty population, a merger or acquisition bringing in a new entity, or a near-miss alert that revealed a gap. Link the review explicitly to the testing results: what did the test find, what was changed, and by when?
For comparison: the five-element standard that OFAC articulates for an effective compliance programme – management commitment, risk assessment, internal controls, testing and auditing, and training – maps well onto the SECO context, even though SECO does not prescribe a programme standard in the same explicit form. Using that structure as an organising reference gives the programme a defensible and internationally recognisable architecture.
The position above covers the core design sequence. Your organisation's specific activities, counterparty profile, and multi-regime exposure will change the precise controls required. To discuss a tailored assessment of your SECO compliance programme, contact Calder & Vance at info@caldervance.com.
Common mistakes and risk flags in SECO programme design
The most persistent mistake in SECO sanctions compliance programme design is treating Switzerland as an EU look-through jurisdiction – assuming that full compliance with EU sanctions automatically satisfies Swiss obligations. It does not.
The Swiss and EU lists are maintained separately, updated on different schedules, and reflect different designation decisions. The legal basis differs. The enforcement path differs. Swiss firms that manage their sanctions exposure through an EU-based group compliance function, without a Switzerland-specific control layer, routinely carry gaps they are unaware of. The same applies in reverse: non-Swiss businesses with Swiss subsidiaries or Swiss-franc payment flows must address SECO directly, not as a derivative of their EU or OFAC compliance posture.
A second common failure is narrow screening coverage. Programmes that screen only at customer onboarding, without periodic re-screening and transaction-level controls, miss the most common real-world trigger: a counterparty that was clean at onboarding and was subsequently designated. The programme must define the re-screening frequency explicitly and document its basis.
A third failure is inadequate documentation of the escalation process. When SECO or a Swiss enforcement authority examines a transaction after the fact, the question is not whether the business intended to comply, but whether the programme required a specific action and whether that action was taken and recorded. An undocumented decision – even the correct decision – is functionally invisible in an enforcement review.
Does your programme distinguish clearly between an OFAC-style mechanical ownership test and the functional approach that Swiss and EU rules require? If not, it is likely undercalling exposure in exactly the counterparty structures where risk concentrates.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
Cross-regime considerations: where SECO, EU, OFAC, and OFSI diverge
For any business with operations or transactions touching more than one jurisdiction, the SECO compliance programme does not stand alone – it must interact with parallel obligations under EU Council regulations, OFAC's IEEPA-based regime, OFSI's SAMLA-derived powers, and potentially others.
The critical divergence points for programme design are as follows. First, the 50 percent rule: OFAC's bright-line threshold treats an entity as blocked if listed persons own 50 percent or more in the aggregate. EU and UK rules add a control limb. SECO requires a substantive assessment of whether a transaction makes economic resources available to a designated person. A programme that applies only the OFAC threshold will miss cases that the EU, UK, and Swiss approaches would catch.
Second, licensing. OFAC issues general licences – standing authorisations for defined categories of transactions – and specific licences on a case-by-case basis. OFSI issues both types under SAMLA. The EU licensing regime operates through member state competent authorities. SECO issues licences and exemptions under the applicable Federal Council ordinances. The application processes, timelines, and criteria differ. A transaction requiring authorisation under multiple regimes needs parallel applications structured to each authority's requirements.
Third, enforcement posture. OFAC's civil penalty base can be substantial; the OFAC enforcement framework and its guidance on penalty mitigation are well-documented in OFAC's published materials. OFSI's enforcement powers under SAMLA include civil monetary penalties and criminal referral for the most serious cases. SECO's enforcement path runs through Swiss administrative and criminal law. For a business facing potential violations under more than one regime, the interaction between these tracks – including whether a VSD under one regime is seen and used by another – requires careful coordination.
Singapore, the UAE, and Japan maintain their own sanctions regimes with distinct list-maintenance and enforcement structures. For trading businesses with supply chains touching these jurisdictions, the SECO programme must be designed with awareness of those parallel obligations, even if it does not purport to satisfy them directly. We advise on the interaction between Swiss obligations and those of other jurisdictions as a standard part of our SECO programme engagements.
Related practices
- Sanctions compliance audit and testing – Australia – testing-focused compliance review under the Australian autonomous sanctions regime.
- Sanctions compliance programme design – Singapore – practical guide to MAS-aligned programme architecture for cross-border businesses.
- Sanctions compliance programme design – UAE – building controls under the UAE Executive Office regime and cross-border exposure management.