Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · SECO

How to assess criminal export-control exposure under SECO

A Swiss-incorporated trading company ships specialised components to a distributor in a third market. Weeks later, SECO initiates an inquiry. The compliance team asks: were the goods dual-use? Was a licence required? Who in the company knew? That question – whether the company and its personnel face criminal rather than purely administrative consequences – is the one that demands immediate, careful analysis.

Criminal export-control exposure under the Swiss regime administered by SECO (State Secretariat for Economic Affairs, Switzerland's primary export-control and sanctions authority) arises when goods, technology, or software subject to control are exported, brokered, or transited without the required authorisation, and when the intent or negligence element required by Swiss law is present. The governing instruments are the applicable Swiss federal laws on export controls and economic sanctions, implemented through SECO's ordinances. As of March 2026, SECO enforcement activity has increased in line with the broader tightening of Swiss autonomous sanctions and export controls.

This guide walks through the assessment in seven steps: identifying the controlled item, mapping the legal basis for the prohibition, testing the intent standard, comparing SECO's approach with those of OFAC, OFSI, and the EU, flagging common errors, setting out what cross-border businesses must do once exposure is identified, and explaining when counsel should be engaged.

Step 1: Identify whether the goods, software, or technology are controlled

The first step in any criminal exposure analysis is to confirm whether the item in question falls within a controlled category under Swiss law. SECO administers dual-use export controls through the relevant federal ordinance on the control of dual-use goods and specific military goods. Items are classified against an export control list that broadly mirrors the international control regime lists – the Wassenaar Arrangement, the Nuclear Suppliers Group, the Australia Group, and the Missile Technology Control Regime – but Swiss national categories can differ at the margin.

Does the item appear on the Swiss control list? If yes, a licence was required unless an exception applied. If the item does not appear on the list, the analysis does not end there. A catch-all clause – analogous to the end-use or "catch-all" controls in the EU dual-use regime – may apply where the exporter knew, or had grounds to suspect, that the goods were intended for a prohibited end-use or end-user. That suspicion-based trigger is the source of much criminal exposure in export-control cases, because it catches shipments that passed a mechanical list check.

In our experience, the first error companies make is relying on a product classification that was obtained for a different export destination or a different customer. Classification is destination-sensitive and end-user-sensitive under Swiss law, not solely a product-level determination.

Step 2: Map the legal basis – what prohibited conduct looks like under SECO's rules

Criminal liability under the Swiss regime attaches to the exporter, the broker, the transit operator, and – critically – to natural persons within those entities who authorised, directed, or negligently failed to prevent the prohibited act. Swiss law operates a dual-liability structure: the legal entity faces sanctions under the corporate liability provisions; responsible individuals face criminal charges under the penal provisions of the federal export-control law.

The prohibited conduct falls into several categories. Exporting a controlled item without authorisation is the core offence. Brokering the sale of controlled goods between two non-Swiss parties without a licence, where Swiss law requires one, is a distinct offence. Providing technical assistance for a controlled end-use – a category that has grown in practical importance – is separately covered.

The legal basis for each category is found in the relevant federal ordinances and the Goods Control Act. Crucially, unlike some administrative regimes, Swiss law does not require wilful intent for all offences. Negligence is sufficient for a number of the lesser criminal charges, meaning that a compliance officer who should have known the goods were controlled, but did not act, may personally face criminal exposure. That distinction between the wilful and the negligent route drives the severity of sanction that follows.

For a comparison of how EU enforcement treats apparent violations in similar dual-use matters, our team's analysis at apparent violation assessment – EU covers the EU General Court practice and Commission referral route.

Step 3: Apply the intent test – wilful conduct versus negligence

How serious is the criminal exposure? The answer turns substantially on the intent standard that applies to the conduct identified in Step 2. Swiss criminal law distinguishes between wilful export-control violations (direct or conditional intent) and negligent violations. The former carries significantly heavier consequences, including custodial sentences for individuals. The latter carries fines and, in some circumstances, lighter custodial penalties.

Conditional intent – the Swiss law concept of accepting a risk rather than positively willing it – is the most important category for compliance practitioners. It means that a decision-maker who recognised a risk of prohibited export but pressed ahead regardless may be treated as having acted wilfully, even if they did not affirmatively know the export was prohibited. SECO investigators look closely at internal email trails, escalation records, and the results of screening reviews when assessing whether conditional intent can be established.

Negligence charges most often arise where a company had a compliance programme in name, but the programme was inadequate in practice: list-check software not updated, no catch-all review, or an end-user certificate obtained but never assessed for plausibility. We regularly advise businesses on how to show that the programme was substantively operative, not merely documented, at the time of the shipment.

One critical point: the intent analysis must run at the individual level, not just at the entity level. SECO enforcement actions name officers, compliance personnel, and in some instances sales staff, as well as the legal entity. Assessing exposure therefore means assessing who within the company knew what, and when.

How does SECO's criminal exposure standard differ from OFAC, OFSI, and EU enforcement?

Businesses with operations across multiple jurisdictions frequently assume that passing an OFAC screen or an EU dual-use review settles the Swiss question. It does not. SECO operates an autonomous sanctions and export-control regime that is calibrated to Swiss foreign policy objectives, which may diverge from EU positions at any given point.

Consider three specific points of divergence. First, the 50 percent ownership rule used by OFAC (which treats an entity as blocked when blocked persons own it 50 percent or more in aggregate) has no direct equivalent in the Swiss autonomous sanctions ordinances. SECO's approach to ownership and control of sanctioned parties is closer to the EU's test, which examines both ownership and effective control, but it is applied through Swiss administrative and criminal procedure, not through OFAC's civil enforcement mechanism.

Second, under the UK regime administered by OFSI (Office of Financial Sanctions Implementation), the licensing and enforcement functions are separated from export-control licensing, which falls to ECJU (Export Control Joint Unit). In Switzerland, SECO combines economic sanctions enforcement and export-control licensing within a single administrative structure. That integration means that a SECO inquiry may span both a sanctions question and an export-control question simultaneously – a fact-pattern that requires concurrent analysis.

Third, EU enforcement under the relevant Council regulation relies on member-state competent authorities to prosecute export-control violations. The criminal thresholds and prosecution policies differ across EU member states, and there is no single EU criminal enforcement standard. Switzerland, by contrast, applies a unified federal standard. For cross-border transactions that touch the EU as well as Switzerland, it is entirely possible that a shipment attracts administrative enforcement in an EU member state and criminal investigation in Switzerland at the same time.

For companies with Singapore operations facing equivalent questions, the comparative analysis in our guide on criminal export exposure – Singapore covers the strategic goods framework and prosecutorial practice in that jurisdiction.

What are the common risk flags in SECO export-control investigations?

Several patterns appear repeatedly in SECO export-control matters and are worth identifying proactively. The presence of any one of them does not establish criminal liability, but each escalates the urgency of legal review.

  • Red-flag orders proceeding to shipment. Where pre-transaction due diligence raised a concern – an unusual end-use, a customer whose stated activity was inconsistent with the goods ordered, a shipping route through a transshipment hub associated with diversion – and the order proceeded without documented resolution of that concern, SECO will treat this as evidence bearing on intent.
  • End-user certificates that are generic, short-form, or not verified against public information about the end-user. Swiss law places the burden of verification on the exporter; the certificate alone is not a safe harbour.
  • Goods reclassified downward shortly before export, without a written classification rationale from a qualified person. SECO investigators review the internal classification history.
  • A catch-all notification received from a prior regulator (for example, from an EU competent authority) that was not assessed against the Swiss transaction. Notification by one regulator does not automatically constitute a SECO red flag, but knowledge of a third-party concern will almost certainly be treated as relevant to the conditional intent analysis.
  • Repeated low-value shipments to the same destination that individually fall below licence thresholds but collectively suggest a structured transaction. Disaggregated shipments designed to stay below a threshold are viewed by SECO – as by other export-control regulators – as a structural red flag.

Have you reviewed your company's internal escalation records for any of these patterns? If a SECO inquiry has commenced, that review is urgent, and its findings should be assessed with counsel before any response is filed.

What must a business do when it identifies potential SECO criminal exposure?

Identification of potential criminal export-control exposure does not require immediate voluntary disclosure, but it does require an immediate and structured internal response. The steps below reflect the standard protocol we advise for businesses that have identified a potential issue.

  1. Preserve relevant documentation. All shipping records, classification decisions, end-user certificates, internal compliance approvals, and communications concerning the shipment must be preserved immediately. Do not delete, archive off-site, or summarise in a manner that could be construed as destruction of evidence.
  2. Scope the incident. How many transactions are potentially affected? Over what period? Which legal entities and which individuals were involved? This scoping exercise sets the parameters of legal exposure and determines whether the issue is isolated or systemic.
  3. Assess the voluntary disclosure option. A VSD (voluntary self-disclosure to a regulator) is available in Swiss procedure. Whether to file one, and when, is a strategic decision that depends on the strength of the evidence, the intent standard, and the anticipated enforcement posture of SECO. In our experience, a premature or incomplete VSD can be more damaging than none at all. The decision requires qualified legal advice.
  4. Identify and protect individual personnel. If specific individuals within the company may face personal criminal exposure, they require separate legal representation. The company's lawyers cannot represent both the entity and the individuals without a conflict of interest in most circumstances.
  5. Assess the cross-border dimension. Does the same transaction trigger potential exposure in an EU member state, the UK, or the US? If BIS has jurisdiction because US-origin technology was involved, an EAR (Export Administration Regulations) violation may be concurrent. A cross-regime exposure map is essential before any regulator is contacted.

If a SECO inquiry has already been opened, the window for shaping the narrative is short. Early engagement with the authority, if it occurs, must be managed carefully. Statements made before legal counsel has reviewed the file can narrow options significantly.

For businesses with UAE dimensions to the same transaction, the guide on criminal export exposure – UAE covers the parallel obligations under UAE export-control law.

When should external counsel be engaged – and what should you ask them?

The question of when to involve external sanctions and export-control counsel is not merely procedural. It is a strategic one, and delay is almost always more costly than early engagement.

Counsel should be instructed at the point when any one of the following conditions is present: a SECO inquiry or request for information has been received; internal investigation has identified a potential violation; a transaction is on hold because a red flag cannot be resolved; or a business is considering a VSD and needs to assess the risk-benefit calculus.

When instructing counsel, the most productive initial instruction is not "tell us whether we violated the law." It is: "tell us what SECO will be looking for, who is exposed, what our disclosure obligations are, and what preserves our options." Those four questions structure the preliminary analysis and allow the business to make informed decisions about the steps that follow.

A common myth in this space is that criminal export-control exposure is primarily a concern for large defence contractors or technology exporters. In our practice, a significant proportion of SECO-related exposure we review involves mid-sized industrial businesses, trading companies, and freight forwarders who did not consider themselves to be in the export-controls business. The catch-all provisions and the negligence standard mean that any business that exports goods – particularly goods with dual-use potential – carries latent exposure that requires periodic review.

The position above covers the standard framework for assessing criminal exposure. The specific facts of your transaction – the classification of the goods, the identity of the end-user, the internal records, and the regime interactions – determine how the analysis lands.

If you have identified a potential issue or received a SECO inquiry, contact Calder & Vance at info@caldervance.com for a confidential initial review.

Related practices

Frequently asked questions

What are the steps to assess criminal export-control exposure under SECO?
Start by confirming whether the goods, software, or technology are controlled under the Swiss export-control list or catch-all provisions. Then map the specific prohibited conduct and identify the individuals involved. Apply the intent test – wilful or negligent – and assess the cross-border dimension, including any concurrent OFAC, BIS, or EU exposure. Preserve all relevant documentation before any regulator contact, and assess whether voluntary self-disclosure is appropriate with qualified legal counsel before filing anything.
What is the most common mistake in criminal exposure in export-control cases?
The most common mistake is treating a passed list-check as a full compliance clearance. Swiss law's catch-all provisions capture shipments where the exporter had reasonable grounds to suspect a prohibited end-use, regardless of whether the item appeared on the control list. A second common error is failing to assess exposure at the individual level. SECO enforcement actions name responsible officers and compliance personnel, not only the legal entity, and individual exposure requires separate, conflict-free legal representation.
How does SECO differ from other regimes here?
SECO combines economic sanctions enforcement and export-control licensing within a single administrative authority, unlike the UK (where OFSI and ECJU are separate) or EU member states (which apply the EU dual-use rules through distinct national authorities). Switzerland's autonomous sanctions ordinances may diverge from EU positions at any point. SECO's criminal liability standard covers both wilful and negligent conduct, and the negligence threshold means that inadequate compliance programmes – not only deliberate evasion – generate personal criminal exposure for responsible individuals.
About the author
Claire Dubois advises on EU sanctions, including Council-regulation analysis, ownership-and-control questions, and annulment actions before the EU General Court. Her practice extends to cross-border export-control matters involving Swiss, EU, and UK regime interactions. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.