A Swiss-based virtual-asset service provider onboards a counterparty routed through a non-custodial wallet. The transaction settles in seconds. Three days later, the compliance team realises the sending address maps to a sanctioned cluster. The funds are already on-chain. The legal question – whether a reportable asset freeze obligation has arisen, and whether the VASP has breached SECO's prohibitions – does not wait for the next compliance cycle.
Crypto and VASP sanctions compliance under SECO is governed by Switzerland's embargo legislation and implemented through ordinances that mirror, but do not identically replicate, the UN Consolidated List and selective autonomous measures. As of July 2026, SECO administers the Swiss sanctions regime through its Secretariat of State for Economic Affairs function; Swiss VASPs and crypto businesses must screen against the applicable Swiss ordinances, freeze assets without delay, and report to SECO – obligations that sit alongside, and in some areas diverge from, the OFAC, OFSI, and EU regimes that Swiss-domiciled actors frequently also face.
This guide sets out the procedure a Swiss VASP should follow, the key tests that determine whether an asset freeze is triggered, the cross-border overlay with OFAC and EU rules, and the risk flags that most commonly produce enforcement exposure.
Step 1: Understanding the SECO regime and who it catches
SECO administers Switzerland's sanctions obligations under the Federal Act on the Implementation of International Sanctions. The regime covers entities and individuals subject to UN Security Council measures adopted under Chapter VII, and autonomous Swiss measures applied on a case-by-case basis. Swiss VASPs – exchanges, custodians, over-the-counter desks, and staking-service providers holding client assets – fall squarely within scope.
The jurisdictional reach is territorial and functional. A VASP incorporated in Switzerland, or providing services from Switzerland, must comply regardless of where its counterparty sits. A non-Swiss VASP that routes transactions through Swiss-incorporated entities faces the same obligations. In our practice, the first mistake we see is the assumption that a VASP incorporated in a canton with lighter cantonal AML supervision somehow sits outside federal sanctions obligations. It does not. SECO's prohibitions are federal in character and override cantonal variation.
Importantly, the Swiss regime does not adopt EU Council regulations by direct reference. Switzerland runs its own list, published as annexes to the applicable ordinances. Where the UN Consolidated List and the Swiss list diverge – which happens in the timing of updates – a VASP must screen against both. Relying solely on EU list-checks is a documented source of compliance gaps that we regularly advise clients to close.
Step 2: Building a screening programme that works for on-chain activity
A VASP's screening obligation under SECO requires it to identify, without delay, whether any counterparty, wallet, or beneficial owner appears on the applicable Swiss sanctions list. The programme must cover customer onboarding, ongoing monitoring, and transaction-level screening for both fiat and crypto legs of a mixed transaction.
On-chain screening presents a structural challenge that fiat screening does not. A wallet address is not a name; it does not appear on the sanctions list by itself. The link between an address and a designated person or entity is established either through OFAC's published blockchain-address designations (where OFAC has designated a wallet), through proprietary blockchain-analytics data, or through the VASP's own customer-identification process. Swiss law does not prescribe a specific blockchain-analytics tool. It requires an effective outcome: the VASP must know whether it is dealing with a sanctioned party.
What does that mean in practice? It means a VASP that screens names but does not screen wallet addresses against available blockchain-analytics data has a visible gap. SECO's enforcement posture – while less publicly documented than OFAC's – follows the same logic as other regimes: if you could have detected the connection with a proportionate system and did not, the failure is yours. We advise clients to treat blockchain-address screening as a non-optional layer above name-matching, not a nice-to-have addition.
A well-constructed programme has four operational layers: (1) static name and entity screening at onboarding, run against the Swiss list and any overlapping UN list; (2) ongoing periodic re-screening as lists update; (3) transaction-level screening for each transfer, including wallet-address matching; and (4) an escalation path that reaches a compliance decision-maker within a defined window from alert generation. The last point matters because the obligation to freeze is immediate on identification, not at the conclusion of a quarterly review.
Step 3: What happens when a match is identified – the freeze and report sequence
When a VASP identifies a potential match, the obligation to freeze assets arises without delay. Under the Swiss regime, "without delay" is not a defined number of business days in the way that some other regimes specify windows; it operates as an immediacy standard. The account is immobilised; no further transactions are permitted; and the position is preserved pending the report and any subsequent SECO determination.
The report to SECO follows. The VASP provides the relevant facts: the identity of the counterparty, the nature and value of the frozen asset, and the grounds for the match. SECO then provides direction on whether the freeze is confirmed and how to treat the asset going forward. Importantly, the freeze obligation and the reporting obligation are sequential but both mandatory; a VASP that reports but fails to freeze pending the report does not satisfy the regime.
In our experience, the most consequential operational failure at this stage is delay in escalation. A compliance analyst who holds an alert in a queue for 48 hours while seeking a second opinion has, depending on the facts, already created a period of non-compliance. The internal escalation protocol should define a maximum time from alert generation to senior decision-maker review – and that window should be measured in hours, not days, for transactions in process.
One further point: the freeze obligation covers crypto assets in custody but also any fiat proceeds of a crypto transaction where those proceeds are still within the VASP's control. A VASP that converts a crypto asset to fiat and remits before identifying a sanction match has not merely frozen late; it may have transferred value to a sanctioned party. The sequence of screening relative to settlement is therefore critical to compliance design.
Related practices
- Compliance audit and testing (Australia) – programme-level review and gap identification for cross-border compliance teams
- Crypto and VASP sanctions compliance: Singapore – step-by-step guide to MAS-aligned screening obligations for digital-asset businesses
- Crypto and VASP sanctions compliance: UAE – CBUAE and FSRA obligations for virtual-asset service providers in the Emirates
Step 4: The cross-border overlay – where OFAC, OFSI, and EU rules compound the exposure
A Swiss VASP does not live in a single-regime world. Depending on its business model, it may simultaneously face obligations under OFAC (because it processes US-dollar transactions or serves US persons), OFSI (because it has UK-linked counterparties), and EU Council regulations (because it operates in or through EU member states or maintains euro settlement relationships). Each regime applies its own tests, and in several respects those tests differ materially.
The ownership-and-control question illustrates the divergence clearly. Under OFAC, the test for whether a non-listed entity is treated as blocked turns mechanically on whether sanctioned persons own it 50 percent or more in the aggregate. Under OFSI and the EU, a control test supplements the ownership threshold; an entity that a designated person controls – through board composition, contractual rights, or other means – may be caught even where the direct ownership stake falls below fifty percent. A Swiss VASP screening a counterparty must therefore apply the strictest applicable test, which in the control dimension may be the UK or EU standard rather than the Swiss one.
Secondary-sanctions risk adds a further layer. OFAC's secondary-sanctions authorities – operating under IEEPA and related statutes – can expose non-US businesses to US measures if they engage in defined categories of transaction with certain sanctioned parties. A Swiss VASP that processes a large crypto transaction for a non-US entity that is itself subject to US secondary-sanctions risk may acquire OFAC exposure even though no US person and no US dollar is directly involved in the transaction. We regularly advise Swiss and European VASPs that their SECO compliance programme is necessary but not sufficient; a separate OFAC risk assessment is a distinct requirement for many business models.
The EU Blocking Regulation adds a further complicating dimension for Swiss entities with EU affiliates or EU-person employees. It restricts compliance with certain US extra-territorial measures within the EU perimeter. The practical effect for a Swiss VASP with an EU subsidiary is that the two entities may face structurally incompatible obligations if the US and EU sanctions positions on a given counterparty diverge. Identifying and escalating that conflict early is the only way to manage it before the transaction settles.
The position above covers the standard multi-regime analysis. Your facts – the currencies involved, the nationality of the beneficial owners, the jurisdictions in which your entity holds licences or processes transactions – change the analysis materially.
If you are assessing a specific transaction or programme design, contact Calder & Vance at info@caldervance.com for a confidential review.
Step 5: Risk flags and the pitfalls most commonly seen in practice
Certain structural features of a VASP's business model create elevated SECO sanctions risk, and in our cross-border practice we see the same five patterns produce the majority of compliance failures.
Peer-to-peer and non-custodial transaction flows are the first. A VASP that facilitates transfers between non-custodial wallets – where it does not hold the private key – may argue it has no asset to freeze. That argument is weaker than it sounds. If the VASP is the access point for the transfer – providing the interface, the order-book, or the settlement mechanism – it has a functional role that Swiss law and most comparator regimes treat as creating an obligation. The absence of custody does not extinguish the screening duty.
The second is nested exchange relationships. A VASP that processes transactions on behalf of another exchange – where the upstream exchange's customers are the ultimate counterparties – faces a layered screening challenge. The VASP sees the upstream exchange on its books, not the end customer. Unless the upstream exchange's own screening is robust and contractually warranted, the downstream VASP has an unacceptable gap. We advise clients to require contractual representations on sanctions screening from correspondent and nested exchanges, and to conduct periodic due diligence on the upstream programme.
Third, stablecoin issuance and redemption flows are frequently underscreened. Stablecoin redemptions settle at par and look like routine fiat transactions to many screening systems. But the wallet address presenting for redemption may be sanctioned, and the redemption itself constitutes a transfer of value to the presenter. Stablecoin operations need wallet-address screening at redemption, not merely name-screening of the registered customer.
Fourth, DeFi protocol interaction creates a category of risk that most VASP compliance programmes have not fully resolved. When a Swiss VASP's customers interact with decentralised protocols, and when those protocols have received or processed funds from sanctioned sources, the question of whether the VASP has facilitated a prohibited transaction is live. The answer is not settled law in Switzerland or elsewhere; but the risk is real enough that a programme with no DeFi monitoring at all is difficult to defend.
Fifth, and most simply, list update lag. The Swiss list, the UN Consolidated List, and the OFAC SDN List update on different schedules. A VASP that pulls list updates weekly rather than daily creates a window in which a newly designated party can transact freely. Real-time or near-real-time list ingestion is the minimum standard for an active trading platform.
Step 6: Record-keeping, voluntary disclosure, and when to involve counsel
Swiss sanctions law requires records of compliance decisions – including screening records, match investigations, freeze decisions, and SECO reports – to be maintained for a defined period. The applicable period is set by the relevant ordinance; verify the current figure before relying on it, as it is subject to legislative revision. For planning purposes, apply a five-year retention standard as a conservative baseline drawn from aligned financial-services record-keeping norms, and confirm the current Swiss requirement with counsel.
When a VASP identifies a potential past breach – a transaction that should have been screened but was not, or a freeze that was delayed – the question of voluntary self-disclosure (VSD, the practice of proactively reporting an apparent violation to the competent authority before it identifies the breach independently) arises immediately. SECO does not operate a formal VSD programme with defined penalty-reduction parameters in the same way that OFAC does under its enforcement guidelines. However, the general principle that voluntary disclosure and co-operation are mitigating factors in regulatory enforcement applies across Swiss law. A VASP that identifies a historical breach and fails to disclose it takes the risk that SECO's own investigation – triggered by a counterpart report, a correspondent bank alert, or a routine supervisory review – surfaces the matter first.
When should counsel be involved? The short answer is: before the first report to SECO, not after it. The initial report shapes the enforcement posture. A report that is accurate, complete, and contextually framed – explaining the compliance programme, the detection mechanism, and the remediation already under way – generates a different SECO response than a bare notification followed by silence. Counsel familiar with SECO's approach can assist with the substance and sequencing of that communication.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position before the report is submitted.
A common myth: Swiss neutrality means lighter sanctions obligations
We encounter this assumption frequently, particularly from non-Swiss clients structuring transactions through Swiss entities. The myth runs as follows: Switzerland is politically neutral and not an EU member, so its sanctions obligations are less demanding and its enforcement less active. Both parts of this are incorrect.
Switzerland operates an autonomous sanctions regime that, since early 2022, has been substantially aligned with EU measures in scope and content – verify the current position before relying on that alignment, as it is subject to ongoing political decision-making. SECO's enforcement function has been active and has imposed penalties on financial institutions and trading entities. The Federal Act on the Implementation of International Sanctions provides a serious legal basis for enforcement, including criminal referrals in aggravated cases.
Swiss neutrality is a political posture. It is not a compliance exemption. A VASP that structures through a Swiss entity on the assumption that regulatory scrutiny will be lower than in the EU or the UK is taking a risk that our practice experience does not support.