A Swiss-based trading house receives a payment instruction. The counterparty name is unfamiliar. A compliance officer runs the name through the firm's screening tool and finds a partial match against an entry on the SECO list – Switzerland's sanctions list maintained by the State Secretariat for Economic Affairs. What happens next? Who decides whether to freeze, block, or proceed? And how long does the firm have before a failure to act becomes a legal problem?
Escalation and reporting procedures under SECO govern exactly this sequence: the internal decision path once a potential match is identified, the statutory obligation to report to SECO, and the requirement to freeze assets or suspend a transaction where a designated person or entity is involved. The Swiss ordinance-based regime operates independently of OFAC and OFSI, though extraterritorial exposure means a single missed step can trigger scrutiny in more than one jurisdiction.
This guide sets out the procedure step by step, identifies the most common points of failure, and explains where legal counsel adds material value before a matter escalates to the regulator.
Step 1: Understanding the SECO Regime and Its Legal Basis
SECO administers Switzerland's autonomous sanctions regime under the Embargo Act (Embargogesetz), which authorises the Federal Council to issue ordinances that implement restrictive measures against specific countries, entities, or individuals. Each country-specific or thematic ordinance sets out the prohibited acts, the asset-freeze obligations, and the reporting requirements that apply to persons and entities subject to Swiss jurisdiction.
The scope of persons covered is broad. Swiss-domiciled companies, Swiss branches of foreign firms, and any person conducting business within Switzerland or using Swiss financial infrastructure are within the regime's reach. That reach has practical implications for multinational groups: a transaction routed through a Swiss treasury centre or a payment cleared through a Zurich correspondent bank can bring the entire group within SECO's remit, even if the contracting parties themselves are incorporated elsewhere.
SECO publishes a consolidated list of sanctioned persons and entities. The list is drawn partly from UN Security Council resolutions – which Switzerland implements under its international-law obligations – and partly from autonomous Swiss measures. The two layers are legally distinct. UN-derived measures bind Switzerland as a matter of international law; autonomous measures reflect Swiss foreign and economic policy. From an operational standpoint, the practical obligations (freeze, report, do not deal) are equivalent, but the channels for challenging or seeking relief differ substantially. Understanding which layer applies to a given designation is, in our experience, the first thing a compliance team needs to establish before deciding on an escalation path.
As of July 2026, SECO's consolidated list is publicly accessible and updated on a rolling basis. Any firm relying on periodic batch screening rather than continuous or near-real-time monitoring runs the risk of acting on a list that is already out of date. That gap – between a new designation and the moment the compliance system reflects it – is a recurring source of exposure across all regimes, not only SECO.
Step 2: Identifying a Potential Match – What Triggers the Escalation Duty?
The escalation duty arises the moment a firm identifies a plausible match between a counterparty, beneficial owner, or transaction participant and an entry on the SECO list. The trigger is identification of the potential match, not confirmation of it. Waiting for certainty before escalating is one of the most consequential errors we see in practice.
Screening systems vary in sophistication. A name-matching algorithm that checks only exact strings will miss transliterated names, variant spellings, and aliases. SECO list entries often carry multiple aliases and variant name forms; the relevant ordinance entries reflect this. A compliance officer who receives an alert must therefore treat the alert as the beginning of an investigation, not the end of one.
What should the escalation trigger look like in practice? At a minimum:
- Any positive match against the SECO consolidated list, whether exact or partial above the firm's defined confidence threshold.
- Any match against the underlying UN Security Council Consolidated List, given that Switzerland implements those measures.
- Any indicator that a counterparty is owned or controlled by a listed person, even if the counterparty itself does not appear on the list – the ownership and control test (the principle that a non-listed entity may be caught if a listed person owns or controls it) applies under Swiss ordinance law in a manner broadly comparable to the EU position.
- Any transaction structuring that appears designed to avoid the screening system, or any instruction from a counterparty to change payment routes in a way that removes traceability.
The last point bears emphasis. The escalation procedure is not limited to list hits. A pattern of behaviour that suggests an attempt to work around controls is itself a compliance event requiring internal escalation and, depending on the facts, potential reporting. We regularly advise clients on the distinction between a genuine match investigation and a red-flag-based suspicious-activity review; the two are often concurrent rather than sequential.
Step 3: The Internal Escalation Path – Who Decides, and How Fast?
Once an alert is raised, the internal escalation path determines whether the firm responds in an orderly way or makes the matter worse through delay or miscommunication. A well-designed escalation procedure assigns decision authority at each level, sets time limits, and preserves a clear audit trail.
In our cross-border practice, the internal escalation path for a potential SECO match typically runs through three stages:
- First-level review (compliance analyst level): The analyst confirms the nature of the match, gathers available counterparty information, and applies the firm's false-positive testing protocol. This stage should be completed quickly – within the same business day if the transaction is live or imminent.
- Second-level review (compliance officer or sanctions specialist): If the first-level review cannot clear the alert as a false positive, the matter moves to a senior compliance officer. At this stage, the transaction or payment is typically suspended pending resolution. Legal privilege considerations become relevant here; involving counsel early preserves options.
- Third-level decision (General Counsel or equivalent, with external counsel input as appropriate): A confirmed or near-confirmed match triggers a decision on freezing, blocking, and reporting. This is the level at which the reporting obligation to SECO crystallises as a live question.
Time is not a neutral factor. Swiss ordinance obligations typically require prompt action once a firm has grounds to believe a transaction involves a designated person or blocked assets. The statutory window for reporting is not open-ended. Although the precise deadline in any particular ordinance requires verification at the time of the matter – because deadlines can vary by measure and are subject to revision – practitioners treat the reporting window as short and manage accordingly. Where there is doubt, earlier is always safer.
Have you tested your internal escalation path under real conditions? A tabletop exercise that runs through a plausible SECO alert is more diagnostic than any written procedure.
Step 4: Freezing Assets and Suspending Transactions – The Immediate Obligation
Where a match is confirmed, or where the facts are sufficiently strong that a reasonable compliance officer would treat the match as confirmed, Swiss ordinance law imposes an immediate obligation to freeze assets and refrain from making funds or economic resources available to the designated person or entity.
The freeze obligation applies to all assets of the designated person that are within the reach of Swiss jurisdiction at the moment of designation. It is not limited to funds already under management; it extends to any asset or economic resource over which the firm has control or custody. For a bank, this means account balances, securities positions, safe custody assets, and pending transactions. For a trading company, it extends to inventory, receivables, and contractual rights where the designated person has a beneficial interest.
Critically, the freeze obligation is self-executing. A firm does not wait for a formal instruction from SECO before freezing. The ordinance creates the obligation directly. SECO issues subsequent communications to regulated entities, but the duty to freeze pre-dates any such communication.
Equally important is what is prohibited beyond the freeze: making funds or economic resources available to a designated person, whether directly or indirectly. A payment to a third party that will foreseeably be passed on to a designated person is caught. A service rendered under a contract that benefits a designated person as beneficial owner is caught. The prohibition is purposively construed, not confined to direct dealing.
The cross-regime comparison matters here. Under OFAC, the 50 percent rule means that an entity owned 50 percent or more by blocked persons is itself treated as blocked. Under EU Council regulations, the ownership-and-control test captures non-listed entities where a listed person exercises decisive influence. The Swiss position applies an analogous ownership and control analysis, though the precise standard under a given ordinance may differ in application. A transaction team that is OFAC-proficient but unfamiliar with the Swiss variant of this test can underestimate the reach of the Swiss prohibition. We have acted for clients who discovered this gap only after a transaction had proceeded.
Step 5: Reporting to SECO – Procedure, Content, and Timing
The reporting obligation is distinct from the freeze obligation. Freezing stops the asset from moving; reporting tells the regulator what has been frozen and why. Both are mandatory. Treating them as alternatives is an error that can produce a regulatory response from SECO even where the freeze itself was properly executed.
Reports to SECO must typically include:
- The identity of the designated person or entity to whom the frozen assets relate.
- A description of the assets frozen, including their nature, location, and estimated value.
- The legal basis for the freeze – the relevant ordinance and the list entry.
- The date on which the firm identified the match and the date on which assets were frozen.
- Any additional information the ordinance requires, which may include details of the transaction or contractual relationship through which the firm came into contact with the designated person's assets.
SECO's reporting channel is its dedicated sanctions unit. Contact information and submission procedures are published on SECO's official website. The report should be in writing, and firms should retain a copy of the report together with the full record of the screening alert, the escalation path, and the decision-making documentation. Swiss law requires records to be maintained for a statutory period – the applicable retention period under the relevant ordinance should be verified at the time of the matter, as it may differ from the standard commercial retention period.
A second question arises in parallel: does the same event require reporting to a financial-intelligence authority, such as the Money Laundering Reporting Office Switzerland (MROS)? SECO reporting and anti-money-laundering reporting serve different statutory purposes and operate under different legal bases. They are not mutually exclusive, and in a case involving suspected illicit funds the two reporting obligations may be concurrent. Compliance teams in Swiss financial institutions need procedures that address both channels simultaneously, not sequentially.
The position above covers the standard reporting pathway. Your facts – the asset type, the counterparty structure, the regime layer (UN-derived or autonomous), and any cross-border elements – change the analysis materially. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.
Step 6: Cross-Border Dimensions – Where SECO Meets OFAC, OFSI, and the EU
Switzerland's autonomous sanctions regime does not operate in isolation. For any multinational group with Swiss operations, a SECO reporting event is almost certainly a multi-regime compliance event. Understanding the interaction between SECO and the major extraterritorial regimes is essential to managing the matter properly.
OFAC extraterritoriality means that a non-US firm dealing in US-dollar transactions, using US financial infrastructure, or involving a US person in a transaction faces OFAC exposure that is entirely independent of its SECO obligation. A Swiss bank clearing a US-dollar payment through a New York correspondent is subject to OFAC's jurisdiction for that transaction. A confirmed SECO match involving an SDN-listed person is therefore almost certainly also an OFAC compliance event. The two reporting obligations – to SECO and to any relevant OFAC requirement – are separate and both must be addressed.
The EU position is structurally closer to Switzerland's. EU Council regulations impose asset-freeze and no-dealing obligations in terms that are broadly comparable to the Swiss ordinance-based approach, and the ownership-and-control test under EU regulations has been extensively interpreted by the EU General Court. A Swiss entity that is part of a group with EU operations, or that transacts with EU counterparties, must map the EU exposure alongside the Swiss obligation. Where the EU and Swiss lists diverge – which happens, because Switzerland adopts autonomous measures on its own timeline and does not automatically mirror every EU designation – there can be situations where a person is listed under one regime but not the other. In those cases, the stricter prohibition governs for each jurisdictional footprint.
UK sanctions under OFSI follow a similar structure, with asset-freeze obligations and a reporting duty that runs parallel to, not as a substitute for, the Swiss obligation. The OFSI licensing regime and SECO's relief mechanisms operate independently; a general licence under OFSI does not authorise a transaction that Swiss ordinance law prohibits.
In our cross-border practice, the most effective approach is to run a simultaneous multi-regime assessment at the moment of escalation, rather than addressing each regime sequentially. Sequencing creates gaps. A decision taken on SECO grounds that fails to account for OFAC secondary-sanctions risk can leave the firm exposed in a jurisdiction it did not consider at the decision-making stage.
Step 7: Common Pitfalls and Risk Flags
Risk flags in SECO escalation and reporting procedures cluster around four recurring patterns. Identifying them early is materially more effective than managing them after a regulatory inquiry has opened.
Pitfall one: treating the ownership chain as someone else's problem. Compliance teams that screen the named counterparty but do not look through to the ultimate beneficial owner miss the cases that matter most. The designated person is rarely the one whose name appears on the invoice. A beneficial owner holding a 50 percent or more stake in an intermediary entity can bring the entire transaction within the freeze obligation, even if the intermediary itself is unlisted. This applies under Swiss ordinance law in the same way it applies under OFAC's 50 percent rule and the EU ownership-and-control test.
Pitfall two: conflating false-positive clearance with compliance clearance. Clearing an alert as a false positive – because the name match relates to a different person of the same name – is a specific technical determination. It does not amount to a general compliance clearance on the transaction. A transaction that passes the name-screening stage can still present other sanctions risk indicators (jurisdiction, goods category, payment routing, end-use) that require separate assessment.
Pitfall three: incomplete or delayed reporting. A report submitted late, or submitted without the required information, does not satisfy the obligation. SECO expects timely, complete reports. Firms that send an initial notification and then fail to follow up with the required asset detail are in breach of the reporting obligation for the period of the gap. Build the complete reporting template into the escalation procedure from the outset.
Pitfall four: failing to manage the information barrier between the compliance team and the business. Once an escalation is live, the persons handling the transaction on the business side must be kept at arm's length from the investigation. Tipping off a counterparty that it is the subject of a sanctions investigation is itself a legal risk. The compliance procedure must include a clear instruction on who may – and who may not – communicate with the counterparty once a screening alert has been raised.
A fifth and frequently overlooked risk: the interaction between the SECO reporting obligation and legal professional privilege. Where a firm involves external counsel in the escalation procedure, the legal advice generated is potentially privileged. That privilege can be waived inadvertently if the advice is shared too widely within the organisation or disclosed in correspondence with third parties. We regularly advise clients on structuring the escalation procedure to preserve privilege without impeding the internal decision-making process.
If a transaction has already been flagged, or a report has been submitted but the position is unclear, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
When to Involve External Sanctions Counsel
External counsel adds material value at specific points in the escalation procedure – and relatively little value if engaged only after a regulatory inquiry has commenced. The right time to involve a sanctions lawyer is before a decision is taken that cannot be undone.
The decision points where counsel engagement is most critical:
- Before freezing or releasing assets where the ownership analysis is uncertain – for example, where a listed person holds a stake below the ownership threshold but may still exercise control.
- Before making a report to SECO where the facts are complex, where the counterparty has assets in multiple jurisdictions, or where concurrent reporting obligations (SECO, MROS, OFAC) need to be managed simultaneously.
- When a counterparty challenges the freeze and the firm needs to assess its legal position before responding.
- Where a voluntary self-disclosure – VSD (a proactive disclosure of an apparent violation to the regulator, intended to demonstrate good faith and mitigate penalty exposure) – may be appropriate.
- Where the group faces multi-regime exposure and needs a co-ordinated approach across SECO, OFAC, OFSI, and EU requirements.
A common misconception is that Swiss firms are insulated from the more aggressive enforcement posture of OFAC and OFSI simply by virtue of operating under a different jurisdiction. That perception is incorrect. A Swiss entity with US-dollar exposure or a US-person connection can face OFAC enforcement on the same underlying facts that triggered its SECO reporting obligation. The jurisdictions do not grant each other immunity.
Related practices:
- Sanctions compliance audit and testing – stress-testing screening logic and escalation procedures against real-world scenarios
- Escalation and reporting under UN sanctions – parallel obligations and reporting channels at the UN level
- The 50 percent rule and ownership under the EAR – how the US ownership threshold interacts with BIS export-control obligations