Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · SECO

Crypto and VASP sanctions compliance under SECO: a practical guide

A Swiss-regulated virtual-asset service provider runs a batch of wallet-address checks before processing a withdrawal. One address resolves to an entity listed in a SECO ordinance. The compliance officer pauses the transaction. Good. But what happens next? What records must be kept, which licensing route applies, and how does Switzerland's position compare with OFAC's or the EU's? These questions matter – and getting them wrong carries consequences that run well beyond the original transaction.

Crypto and VASP sanctions compliance under SECO – Switzerland's State Secretariat for Economic Affairs – is governed primarily by the Swiss Embargo Act and the associated implementing ordinances, which impose asset-freezing, prohibitions on making funds available, and reporting duties on all persons and entities in Switzerland, including virtual-asset service providers (VASPs – firms that offer exchange, custody, transfer, or brokerage of cryptoassets). Switzerland maintains its own autonomous sanctions regime, which tracks but does not replicate EU measures, and SECO administers and enforces it.

This guide works through the regime step by step: the legal basis, the screening and due-diligence obligations, the treatment of wallets and on-chain flows, cross-regime divergence, common risk flags, and when to instruct sanctions counsel. As of July 2026, the regime continues to evolve in response to the broader global convergence of crypto-asset regulation and sanctions enforcement.

Step 1 – Understand the legal basis and who enforces it

Swiss sanctions obligations for VASPs flow from the Embargo Act and the implementing SECO ordinances, supplemented by the Anti-Money Laundering Act, which governs financial intermediaries – a category that expressly includes VASPs. The Embargo Act empowers the Swiss Federal Council to enact ordinances that mirror, track, or diverge from UN Security Council measures and from the EU's Council regulations. SECO drafts and administers those ordinances; it also issues guidance, receives mandatory reports of frozen assets, and refers enforcement matters to the relevant federal authority.

The Swiss Financial Market Supervisory Authority (FINMA) sits alongside SECO. FINMA supervises VASPs holding a licence under Swiss financial-market law and can take supervisory action, including licence revocation, for sanctions failures. In our cross-border practice, clients frequently underestimate this dual-authority exposure: a VASP that fails a SECO screening obligation may face both a SECO-referred enforcement proceeding and a parallel FINMA supervisory review. Both need managing on their own track.

The UN Consolidated List – produced by Security Council committees – provides a floor of obligations that Swiss ordinances reflect. Where the Swiss Federal Council adopts autonomous measures beyond that floor, the stricter Swiss prohibition governs for persons and entities in Switzerland.

Step 2 – Map the screening perimeter: wallets, counterparties, and ownership chains

Effective VASP sanctions screening under SECO covers three distinct layers simultaneously: the counterparty identity, the wallet or address associated with the transaction, and the ownership and control chain behind both. Missing any one layer creates a gap that an enforcement review will find.

For counterparty screening, VASPs should screen every customer at onboarding and on an ongoing basis against the SECO sanctions lists, the UN Consolidated List, and – given the extraterritorial reach of US measures – the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Does your screening tool refresh against all three list sources, or only one? This is one of the first questions we ask when reviewing a VASP's programme.

Wallet-level screening adds a layer not present in traditional financial-institution compliance. Blockchain-analytics tools can associate a wallet address with a listed person or with an address cluster that OFAC or another authority has identified. Swiss law does not yet mandate a specific blockchain-analytics standard by name, but SECO's guidance and FINMA's supervisory expectations converge on the view that a VASP performing no on-chain analysis has an inadequate control environment. The prudent position is to screen deposit and withdrawal addresses before settlement, not only at onboarding.

Ownership and control matters more in crypto than many practitioners expect. The ownership and control test under Swiss ordinances – which aligns closely with the EU position – means that an entity is caught where a listed person owns or controls it, even without a separate listing for that entity. A wallet held by a company in which a listed person holds a controlling stake is treated as falling within the prohibition. Tracing beneficial ownership through corporate layers before processing a significant transaction is not optional; it is the minimum expected of a compliant VASP.

Step 3 – Manage a screening hit: freeze, report, and document

When a match against the SECO list or a linked ordinance arises, the immediate obligation is to freeze the relevant assets and to refrain from making any further funds or economic resources available to the listed person. The freeze applies at the moment of identification; it does not await confirmation from SECO.

Reporting follows the freeze. VASPs must notify SECO of frozen assets within the statutory window set by the relevant ordinance. The window is short – verify the current position before relying on it, as ordinance-specific timelines vary – and SECO expects a clear, factual report identifying the asset, the basis for the freeze, and the estimated value. A report that is late, incomplete, or inaccurate is itself a compliance failure.

Documentation must be preserved. Swiss financial-intermediary rules require records sufficient to reconstruct the transaction and the compliance decision. In our experience, VASPs that lack a clear documented rationale for a freeze decision – or that fail to record why a near-miss was cleared – are the most exposed in a subsequent supervisory review. Maintain a complete contemporaneous record: the screening result, the analyst's assessment, the decision taken, and the senior sign-off.

Two practical points on the freeze mechanics. First, for on-chain assets, the freeze may require suspending or reversing a transaction that is in progress. A VASP's technical architecture should allow this. Second, where a transaction has already settled before the match was identified, the frozen-asset obligation attaches to whatever equivalent value the VASP holds. Instruct counsel promptly if there is any doubt about the scope of the obligation.

Step 4 – Apply the cross-regime test: how does SECO differ from OFAC, OFSI, and the EU?

For a VASP with cross-border operations or a global customer base, understanding where the Swiss position diverges from other major regimes is operationally critical. The differences are real, and a programme calibrated only to one regime will have gaps in another.

OFAC and the 50 percent rule. Under OFAC's rules, an entity owned 50 percent or more in the aggregate by blocked persons is itself treated as blocked, even without a separate listing. This test is mechanical: ownership is the trigger, not control or direction. Swiss ordinances adopt an ownership and control test that is structurally closer to the EU position – where control without majority ownership can also capture an entity. A VASP serving US persons or processing transactions that touch the US financial system faces both standards simultaneously, and the stricter prohibition governs each leg of the transaction.

OFSI and the UK approach. OFSI – the UK's Office of Financial Sanctions Implementation – similarly applies an ownership and control test. The UK regime post-dates Brexit and is now autonomous; UK designations are not automatically replicated in Swiss ordinances, and vice versa. A VASP operating in both jurisdictions must run parallel screening against both lists.

EU regulations. Switzerland is not an EU member, but it tracks many EU measures through autonomous ordinances. The tracking is not automatic. Where the EU introduces new designations or amends a programme, SECO publishes a corresponding ordinance amendment – but the timing and exact scope may differ. In a recent matter, a VASP that assumed Swiss measures matched the EU position precisely missed a delta between the two lists. Always check both independently.

Travel rule implications. The travel rule – the obligation to pass originator and beneficiary information with a virtual-asset transfer – applies in Switzerland under FINMA guidance and mirrors the Financial Action Task Force standard. Receiving a travel-rule message that includes a listed originator triggers the freeze obligation. Sending institutions that comply fully with the travel rule can inadvertently give the receiving VASP the information it needs to detect a prohibited transaction; from a compliance standpoint, that is the rule working correctly. Where travel-rule data is absent or masked, the risk of processing a prohibited transaction rises sharply.

For a comparison of how the Australian Autonomous Sanctions regime approaches similar crypto compliance questions, see our guide to sanctions compliance audit and testing under the Australian regime. The Singapore treatment of VASPs is set out in our crypto and VASP sanctions compliance guide for Singapore.

Step 5 – Licence applications and derogations under Swiss ordinances

Not every transaction involving a connection to a listed person is necessarily prohibited without recourse. Swiss ordinances typically include a derogation mechanism – an authorisation process through which a VASP or other person may apply to SECO for permission to conduct a specific transaction that would otherwise fall within the prohibition.

The derogation is not a general licence; it is a case-by-case decision by SECO. Applications must be submitted in writing and must set out the legal and factual basis for the derogation, including the identity of the parties, the nature of the transaction, and the grounds on which the applicant contends that the authorisation should be granted. SECO has discretion to impose conditions. Processing times vary by complexity; build the application timeline into any transaction schedule.

In our cross-border practice, we advise VASPs to assess the derogation route before a transaction is committed, not after a freeze has been applied. A derogation application made after assets have been frozen is harder to frame and may signal to SECO that the VASP's pre-transaction controls were inadequate. Early assessment is the better path.

Where a VASP believes a customer has been incorrectly associated with a listed person through a false positive – name coincidence, address overlap, or data error – the appropriate step is to document the analysis clearly and apply to SECO for guidance or, where necessary, for a formal confirmation. Do not simply clear the hit and proceed. The audit trail matters.

Step 6 – Build and test the compliance programme

A VASP's sanctions compliance programme should meet what practitioners describe as a five-element standard: (1) management commitment and senior accountability; (2) a risk assessment that identifies the VASP's specific exposure by product, customer, and geographic corridor; (3) internal controls, including screening, transaction monitoring, and travel-rule compliance; (4) testing and audit of those controls; and (5) training calibrated to role and risk.

Management commitment is the foundation. Without explicit senior-level ownership of the sanctions compliance function – backed by adequate resource and a clear escalation path – the other four elements tend to atrophy. SECO's supervisory interest in VASP compliance has increased, and a programme that looks complete on paper but lacks genuine senior engagement is one of the patterns that regulatory scrutiny tends to reveal.

Risk assessment must be specific to the VASP's business model. A peer-to-peer exchange serving retail customers in high-risk geographic corridors faces a materially different sanctions risk profile from an institutional custodian serving regulated counterparties. A generic risk assessment that does not capture that distinction will produce controls of the wrong calibre. We regularly advise VASPs that discover, during a compliance review, that their screening tool is well-matched to one part of their business and entirely mismatched to another.

Testing is the discipline most often deferred. Controls that have never been tested under realistic conditions have unknown effectiveness. Red-team exercises – simulated hits, false-positive clearances, travel-rule gap scenarios – surface failure modes before a regulator does. Testing outcomes should be recorded and the programme adjusted accordingly. For an assessment of how compliance audit and testing operates in a related jurisdiction, see our guide to compliance audit and testing.

Training must reach the front line. A customer-onboarding team that does not understand what a SECO list hit requires them to do, or a technical operations team that has never considered what freeze mechanics mean at the blockchain level, is a compliance gap regardless of how good the written policy is.

Common risk flags and the myth of blockchain anonymity

Certain patterns recur in VASP sanctions-compliance failures. Recognising them in advance is more effective than responding to them after the fact.

Layered wallet structures. Transactions routed through multiple intermediate wallets – mixing services, chain-hop patterns, or high-frequency micro-transactions – are a recognised methodology for obscuring the origin or destination of funds. A VASP that cannot see through these patterns in its transaction monitoring has a visibility gap. This is a compliance detection challenge, not a description of legitimate technique.

Incomplete beneficial-ownership data at onboarding. A VASP that accepts customers without adequate beneficial-ownership information cannot run a meaningful ownership and control analysis. FINMA's know-your-customer expectations are clear; SECO's sanctions obligations require that the ownership chain be known well enough to apply the control test.

Stale screening. A customer cleared at onboarding against a list from six months ago may not be clean against today's list. Designations are added without notice. Ongoing screening – run at a cadence that reflects the risk level of the customer and the product – is required, not optional.

Travel-rule data gaps at receipt. Where a receiving VASP accepts a transfer without full originator information, it cannot screen the sender. The gap may be caused by a counterparty VASP that is non-compliant, that operates in a jurisdiction with no travel-rule obligation, or that is deliberately withholding information. Each of these scenarios carries a different risk level and requires a different response. Bulk-clearing gaps without analysis is not a defence.

The myth that blockchain transactions are anonymous – and therefore undetectable – is one we encounter regularly in VASP compliance discussions. Blockchain analytics have materially eroded that assumption. OFAC and other regulators have demonstrated repeatedly that on-chain analysis can attribute wallet clusters to listed entities with sufficient confidence to support enforcement action. A VASP that operates on the premise that on-chain activity is unattributable is building its compliance programme on a false foundation. The question is not whether attribution is possible, but whether the VASP's own analytics are strong enough to detect it first.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis. For an early-stage assessment of your VASP's exposure under the SECO regime or any of the parallel regimes discussed here, contact Calder & Vance at info@caldervance.com.

For a broader view of how VASP sanctions compliance operates in a related Asia-Pacific jurisdiction, our crypto and VASP sanctions compliance guide for Singapore sets out the parallel obligations and the points of divergence.

Related practices

Frequently asked questions

What are the steps to manage crypto sanctions exposure under SECO?
Managing crypto sanctions exposure under SECO requires five sequential steps: (1) map your legal obligations under the Embargo Act and the relevant ordinances; (2) screen counterparties, wallets, and ownership chains against the SECO lists, the UN Consolidated List, and – where US-nexus exists – the OFAC SDN List; (3) on a hit, freeze the relevant assets immediately and report to SECO within the statutory window; (4) document every screening decision with a contemporaneous record; and (5) test and audit the controls on a regular cycle. Each step has operational dependencies; a gap in any one creates exposure in the others.
What is the most common mistake in crypto and VASP sanctions compliance?
The most common mistake is treating sanctions screening as a point-in-time onboarding check rather than an ongoing obligation. Designations are added without notice; a customer who was clean at onboarding may be listed six months later. VASPs also frequently screen only the named customer, missing the ownership and control layer that catches entities held by listed persons. Both errors are avoidable with a programme designed around ongoing screening and full beneficial-ownership visibility.
How does SECO differ from other regimes here?
SECO administers an autonomous Swiss regime that tracks but does not automatically replicate EU or UN measures. Timing and scope differences between Swiss ordinances and EU designations mean the two lists are not identical at any given moment. Switzerland also applies an ownership and control test – not a purely mechanical 50 percent rule as OFAC does – meaning that a listed person's de facto direction of an entity can be sufficient to engage the prohibition even without majority ownership. VASPs with EU and US exposure must manage three sets of list obligations simultaneously; the stricter prohibition governs each leg.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.