Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · SECO

Sanctions compliance programmes under SECO: what businesses must know

A Swiss-based trading company finalises a distribution agreement with a counterparty in a third market. A week before signing, the group's compliance officer asks a simple question: does Switzerland require a formal sanctions compliance programme? The answer shapes not only that transaction, but every deal the business does from Geneva or Zurich going forward.

Switzerland maintains an autonomous sanctions regime administered by the State Secretariat for Economic Affairs ("SECO"), operating under SECO ordinances enacted pursuant to the Federal Act on the Implementation of International Sanctions. SECO's regime imposes prohibition-based obligations on Swiss-nexus businesses, and those obligations are meaningless without a programme designed to detect, prevent, and report relevant exposures. As of July 2026, SECO's enforcement posture has sharpened, and businesses that have treated Swiss sanctions as a lighter-touch alternative to OFAC or EU rules are being corrected by experience.

This guide walks through how to design a sanctions compliance programme suited to SECO's requirements, where that regime converges with and departs from OFAC, OFSI, and the EU Council regulations, and what risk flags a compliance team should address before the programme goes live.

Step 1: Understand the governing regime and SECO's legal authority

SECO administers Switzerland's autonomous sanctions regime on the basis of federal legislation and implementing ordinances, each of which is programme-specific and addresses a defined set of target-country or thematic measures. SECO does not operate from a single consolidated list in the way that OFAC publishes the SDN List (OFAC's list of Specially Designated Nationals and blocked persons); instead, each ordinance carries its own annex of listed persons and entities, and the scope of prohibitions varies by programme.

The practical implication is significant. A compliance programme designed around a single consolidated screening database may not catch a SECO-listed party if that party appears only in one ordinance's annex and the screening tool has not been configured to ingest all active ordinances. In our cross-border practice, we regularly see Swiss-nexus businesses that screen against OFAC and EU lists with care, but whose SECO coverage has gaps at the ordinance level. That gap is not academic: Swiss criminal and administrative law imposes liability on natural persons, not only on legal entities.

The position above covers the standard configuration. Your facts – the sector, the transaction types, and the counterparty geographies you work with – change how comprehensively you need to map SECO ordinances to your screening architecture.

For a preliminary assessment of your SECO screening coverage, contact Calder & Vance at info@caldervance.com.

Step 2: Map the scope – who and what the SECO regime reaches

SECO's measures apply to persons and entities with a Swiss nexus: Swiss nationals wherever they are, persons and legal entities domiciled or incorporated in Switzerland, and conduct occurring on Swiss territory. The key prohibitions across SECO ordinances follow a standard structure: asset freezing of listed persons, prohibitions on making funds or economic resources available, and sector-specific trade restrictions.

Scope mapping is the foundation of programme design. A business must answer four questions before it can determine what controls to build:

  • Which SECO ordinances are live and relevant to the sectors and geographies the business operates in?
  • Does the business handle funds, economic resources, or goods that could trigger a making-available prohibition?
  • Are there Swiss-domiciled subsidiaries, branches, or personnel whose activities are captured by Swiss-nexus rules even when the transaction is booked abroad?
  • Do any group entities outside Switzerland face obligations under their own regimes that interact with SECO measures – particularly where OFAC or EU rules are stricter on the same target?

That last point matters more than many compliance teams acknowledge. Where OFAC or the EU Council imposes stricter prohibitions on the same counterparty or sector than SECO does, the stricter prohibition governs the group's conduct in the relevant jurisdiction. A compliance programme that maps SECO in isolation, without cross-checking against the group's OFAC and EU exposure, produces a false sense of coverage. We advise clients to run a cross-regime mapping exercise before finalising scope.

Step 3: Design the core programme elements – screening, escalation, and record-keeping

A well-designed programme under SECO covers five operational elements: risk assessment, screening controls, escalation and decision procedures, record-keeping, and training. Each element must be calibrated to the business's actual risk profile, not to a generic template.

Risk assessment. The starting point is a written assessment of where the business is most likely to encounter a SECO-listed party or a SECO-prohibited transaction. High-risk indicators include: operating in sectors subject to SECO trade restrictions; having counterparties or beneficial owners in jurisdictions that are the subject of SECO ordinances; and providing financial, logistics, or professional services to clients who may themselves have exposure. The risk assessment drives the depth of due diligence required at each counterparty tier.

Screening controls. Screening must cover SECO ordinance annexes as well as the EU Consolidated List and, for any entity with US touchpoints, the OFAC SDN List. Screening should be applied at onboarding and on an ongoing basis. The frequency of ongoing screening should reflect the volatility of the lists in question: SECO ordinances are updated periodically, and a counterparty that is clean at onboarding may appear on an annex three months later. Automated screening tools require human-reviewed escalation logic; an automated "no-match" result is not a compliance decision.

Escalation and decision procedures. When screening produces a potential match, the programme must have a documented procedure for who reviews it, on what timeline, and with what authority to approve, decline, or hold a transaction. That procedure should include a route to external counsel for borderline cases – particularly where a match involves a partial name, a close-transliteration variant, or a counterparty with opaque ownership.

Record-keeping. SECO and related Swiss legal obligations require businesses to retain transaction records and compliance documentation for a defined period. Verify the current period requirement under the applicable rules before relying on any summary; the position should be confirmed with reference to the specific ordinance and any sector-specific regulation in force at the time.

Training. Programme documentation that staff have not read and do not understand is not a compliance programme. Training must be role-specific: the front-line relationship manager needs to recognise a screening alert; the compliance officer needs to understand the legal basis for a hold; management needs to understand the personal liability dimension of Swiss law.

Step 4: Address the ownership and control question – where SECO, OFAC, and the EU diverge

The question of whether a non-listed entity is caught because of its relationship to a listed person is where the major regimes diverge most sharply, and where a compliance programme must be most precise.

Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical: if listed persons own the entity in aggregate at or above that threshold, the entity is blocked regardless of management, purpose, or intent. Aggregation across multiple listed persons counts toward the threshold.

Under the EU Council regulations, and under OFSI in the UK, the test adds a control limb alongside ownership: an entity owned or controlled by a listed person may be caught even where ownership sits below the 50 percent level. "Control" in the EU and UK sense covers the ability to exercise decisive influence over the entity's decisions. That means a listed party with a 35 percent stake and board representation may still bring a non-listed entity within the prohibition.

SECO's position under its ordinances draws on the EU approach in many respects, given the close alignment between Swiss autonomous measures and EU designations. In practice, SECO-implementing ordinances use a making-available test that covers funds or economic resources provided for the benefit of listed persons, which extends the effective reach beyond the named entity. Businesses with group structures involving EU, UK, and Swiss legal entities must map the ownership and control question across all three regimes simultaneously. A structure that is clean under OFAC's 50 percent rule may still be caught under OFSI's control test or SECO's benefit-of analysis.

Have you mapped the full ownership and control chain of your key counterparties across each regime your business touches – or only screened the named legal entity against a consolidated list?

Step 5: Identify the risk flags and common failure points

In our experience, the compliance programmes most likely to fail under SECO scrutiny share recognisable characteristics. Understanding these failure patterns helps a business prioritise what to fix first.

Reliance on a single consolidated list. Businesses that screen against one aggregated database without confirming that it accurately reflects all active SECO ordinance annexes will produce false negatives. SECO updates its ordinances at different intervals from the EU and OFAC, and the timing gaps create windows of undetected exposure.

No beneficial ownership verification beyond the first layer. A compliance programme that checks the named counterparty but does not look behind it to identify beneficial owners misses the ownership-and-control dimension entirely. This is the single most common gap we identify in programme reviews across Swiss, EU, and UK-regulated entities.

Stale risk assessments. A risk assessment completed at programme launch and not revisited when the business adds a new product, enters a new market, or takes on a new customer segment is a snapshot, not a control. The risk assessment should be a living document, reviewed at defined intervals and whenever a material change occurs.

No clear escalation authority. Programmes that require any potential match to be resolved by the same individual who manages the relationship are structurally conflicted. The escalation path must be independent of revenue incentives. Absence of a documented escalation chain is also one of the first things SECO or a Swiss cantonal prosecuting authority will ask to see in an investigation.

Disconnect from group-level controls. Swiss subsidiaries of multinationals sometimes operate compliance programmes that are entirely separate from group-level screening, with no mechanism to share adverse findings or to apply group-level decisions locally. That creates a group with inconsistent controls, and it creates personal liability for Swiss-based officers who hold fiduciary duties under Swiss law.

If a transaction has already been flagged or a potential breach has been identified, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

Step 6: Interaction with adjacent regimes – secondary-sanctions risk and the extraterritorial dimension

A SECO-compliant programme does not automatically address the secondary-sanctions exposure that arises when a Swiss-nexus business transacts in US dollars, uses US financial institutions as correspondents, or involves US persons in a deal. OFAC's secondary sanctions (measures targeting non-US persons who conduct significant transactions with designated parties) can reach a Swiss business whose transaction has no direct US nexus, in certain programmes. The threshold for "significant" is not defined by a fixed figure; it is assessed on a multi-factor basis including the size, frequency, and nature of the transaction.

The practical implication for programme design is this: a Swiss business in the financial or trading sector cannot design a SECO-only compliance programme and consider its US exposure addressed. The programme must include a layer of analysis that asks whether any transaction – even one that is entirely Swiss in legal form – could attract OFAC attention through correspondent-banking channels, through a US counterparty's exposure, or through the involvement of a US person.

The EU Blocking Regulation adds a further complication for Swiss businesses with EU operations. Where an EU entity within the same group is subject to EU blocking rules, it faces constraints on complying with certain OFAC measures that extend to third-country persons. A compliance programme that does not address the interaction between the EU Blocking Regulation and OFAC's extraterritorial reach will produce irreconcilable compliance positions at the group level.

For businesses with operations across Switzerland, the EU, and the United Kingdom, the programme design question is ultimately a multi-regime engineering problem. The controls must satisfy each regime without causing the business to breach another. In our cross-border practice, we build compliance architectures that identify the hierarchy of obligations and flag where regimes genuinely conflict, so that management can make informed decisions about where to operate and how.

Step 7: When to involve external counsel – and what to do when something goes wrong

A compliance programme is not a set-and-forget control. There are defined moments when external counsel adds value that internal resources cannot replicate.

The most straightforward is at programme design or redesign. A counsel-led programme review tests the screening logic, maps ownership and control, identifies ordinance gaps, and produces a documented basis for management sign-off. That documented basis matters if the programme is later scrutinised.

The second moment is when a potential breach is identified. Swiss law, like UK and EU law, recognises that early disclosure and co-operation are relevant to enforcement outcomes. A voluntary self-disclosure ("VSD") – proactive disclosure to a regulator before it identifies the issue independently – typically receives more favourable treatment than a violation discovered through investigation. The window in which a VSD is viable closes quickly once a regulator is aware of the conduct. Instructing counsel immediately preserves the option.

The third moment is on a material corporate change: an acquisition, a new market entry, a new product line, or a change in beneficial ownership of a group entity. Each of these events may alter the risk profile of the programme, bring new SECO ordinances into scope, or create a new ownership-and-control question that the existing programme was not designed to handle.

What is the myth here that deserves correction? It is the assumption that a compliance programme designed for OFAC or the EU will automatically satisfy SECO. The regimes overlap in many designations, but SECO's ordinance structure, its making-available test, the interaction with Swiss criminal liability for natural persons, and the gaps in consolidated-list coverage mean that a transplanted programme will almost certainly have structural weaknesses. A programme must be built for the SECO regime, not adapted from another.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under SECO?
Designing a SECO compliance programme requires five sequential steps: (1) map which SECO ordinances apply to your sector and counterparty geographies; (2) build screening coverage across all active ordinance annexes, not only a consolidated list; (3) design escalation and decision procedures with documented authority and independence from revenue functions; (4) establish record-keeping to meet the applicable retention requirements; and (5) deliver role-specific training. Each step should be documented and signed off at an appropriate management level, and the programme should be reviewed annually and after any material change to the business.
What is the most common mistake in sanctions compliance programmes?
The most common mistake – across SECO, OFSI, EU, and OFAC programmes alike – is screening only the named legal-entity counterparty without looking through to beneficial owners and controllers. A compliance programme that stops at the first layer of ownership will miss the making-available and ownership-and-control exposure that the major regimes impose. The second most common failure is a risk assessment that was written once and never updated. Both errors are structural, and both are relatively straightforward to correct with a properly scoped programme review.
How does SECO differ from other regimes here?
SECO differs from OFAC principally in structure: SECO operates through separate, programme-specific ordinances rather than a single consolidated list, so a business must actively track which ordinances are live and relevant rather than screening against one database. SECO's making-available test aligns more closely with EU and UK approaches than with OFAC's mechanical 50 percent ownership rule, which means control relationships – not only direct ownership – are relevant. Swiss law also imposes personal criminal liability on natural persons for sanctions breaches, which gives the enforcement dimension a different character from a US civil penalty framework.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.