A Swiss-based commodity trader receives a payment-screening alert. A beneficial owner in the ownership chain of a counterparty shares a name with a person listed under a SECO ordinance. The compliance officer escalates it to the legal team – but there is no written procedure to follow, no clear timeline, and no agreed reporting threshold. The deal is paused. Time passes. The window to act narrows. How that gap between alert and decision is managed determines whether the firm faces a regulatory problem or avoids one entirely.
Setting up escalation and reporting procedures under SECO means designing a documented decision pathway that runs from the first alert through internal review, ownership verification, and – where a match is confirmed – to mandatory reporting to the relevant Swiss authority. The governing instruments are Switzerland's embargo ordinances, administered by the State Secretariat for Economic Affairs (SECO), the competent authority for economic sanctions enforcement in Switzerland. As of July 2026, Switzerland maintains autonomous sanctions that in some areas track, and in others diverge from, EU measures. That divergence makes the escalation design a technically distinct exercise from EU or UK compliance.
This guide walks through the six steps required to build a functioning escalation and reporting regime under SECO, compares the Swiss position with the OFAC, OFSI, and EU equivalents, and identifies where gaps in the procedure become enforcement risk.
Step 1 – Understand What SECO Requires and Why It Differs from the EU
SECO's authority derives from Switzerland's embargo legislation and the ordinances enacted under it. Switzerland adopts autonomous sanctions measures by Federal Council ordinance; it does not automatically mirror EU designations, and it is not a party to EU Regulations. In practice, many SECO measures align with EU programmes, but alignment is never automatic and the timing of updates differs. For a cross-border business managing both EU and Swiss relationships, that lag – or divergence in scope – is the first structural risk to address in any escalation design.
The practical consequence is that a person who is designated under an EU Council Regulation may not appear on the current SECO list at the same time, or the relevant restriction may be formulated differently. A compliance function that treats Swiss screening as a simple clone of its EU screening will miss this. In our cross-border practice, we see this mismatch most frequently in transactions that touch both EU-member-state counterparties and Swiss entities, where the team applies EU-trained screening logic to a SECO obligation without recalibrating the threshold or the ownership test.
SECO administers targeted financial sanctions – asset freezes and prohibitions on making funds available – alongside sector-specific trade restrictions under applicable ordinances. The scope of persons and entities covered, the definition of "funds", and the treatment of indirect control can each differ in detail from EU Regulation language. Before designing the escalation procedure, a compliance counsel needs to confirm exactly which Swiss ordinances apply to the firm's activities and counterparties. Starting from a generic template produces a generic procedure; it will not withstand a regulatory review.
Step 2 – Define the Trigger: What Generates an Escalation Event?
An escalation event under SECO is triggered when a screening check or a business-intelligence review generates a potential match against a person or entity covered by a Swiss embargo ordinance, or when the firm comes into possession of information suggesting that assets it holds or controls may be subject to a freezing obligation. The trigger is broader than a positive list hit: it includes a hit on a name, an alias, or an identifier that has not yet been confirmed or dismissed.
The definition of "trigger" inside the firm's written procedure matters because it sets the clock running. Once the procedure is triggered, all subsequent actions – ownership verification, escalation to senior compliance, potential blocking of a transaction, and reporting – must follow within defined internal timeframes. A poorly defined trigger either over-escalates (creating noise that dilutes real alerts) or under-escalates (missing genuine hits until they become a regulatory matter).
Practically, the procedure should distinguish between three categories of trigger event. First, a direct name match against a current SECO list entry. Second, an ownership or control link where a listed person is identified as a direct or indirect beneficial owner of a counterparty. Third, a transaction-pattern or information-led alert that does not produce a direct name match but generates a reasonable suspicion that a SECO-listed person is involved. Each category requires a different escalation path and a different evidentiary standard before the firm can clear or escalate it.
How does this compare with other regimes? Under OFAC, the trigger for freezing and reporting is typically a positive identification of a Specially Designated National or the satisfaction of the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). OFSI and the EU apply an ownership and control test that is broader than OFAC's mechanical ownership calculation: control through other means – board dominance, contractual power, or de facto direction – can trigger the obligation even below the 50 percent line. SECO's own instruments require careful reading on this point because the language of some Swiss ordinances tracks EU definitions more closely while others are drafted independently. This is precisely why a compliance counsel familiar with SECO's specific texts – not a generic EU compliance lawyer – should review the escalation trigger before it is finalised.
Step 3 – Map the Internal Escalation Pathway
A functioning escalation pathway names who receives the initial alert, who investigates it, who makes the clearance or escalation decision, and who holds authority to report to SECO. The pathway must be written, version-controlled, and tested at least annually. A verbal understanding between the compliance officer and the CFO is not a procedure; it is a gap that an enforcement reviewer will find.
The minimum pathway for a mid-sized business operating under SECO obligations typically runs as follows. The screening analyst or operations team member who identifies the potential match logs it immediately in a dedicated register and notifies the first-level compliance reviewer. That reviewer conducts an initial assessment – usually within a defined short window – to determine whether the match can be dismissed on the basis of available information (for example, a clear distinguisher in date of birth, nationality, or address) or must be escalated to senior compliance. If the first-level reviewer cannot dismiss the match, it moves to a second-level reviewer with access to enhanced ownership data and legal support. If that second-level review does not resolve the matter, or if it confirms a potential match, the matter reaches the Compliance Officer or General Counsel, who decides whether the transaction should be paused, the relevant asset frozen, and a report submitted to SECO.
Each stage must have a defined maximum response window. Leaving stages open-ended is a common procedural failure. We regularly advise clients to build explicit internal clocks into each escalation tier – short enough to preserve options, long enough to allow genuine investigation. Where the firm's structure involves multiple jurisdictions, the pathway must also specify which entity within the group holds the Swiss reporting obligation and how that entity is notified when the initial alert is picked up elsewhere in the group.
Consider this: what happens if the compliance officer is on leave when an urgent match comes in? Every escalation pathway needs a named deputy at each level and a standing authority for that deputy to act. Without this, the procedure stalls at the one moment it cannot afford to.
Step 4 – How Does SECO Reporting Work in Practice?
Once an escalation concludes that a match is substantiated and an asset freeze obligation is triggered, the firm is required to report to SECO. Reporting under Swiss embargo legislation is not optional and is not deferred until an internal investigation is complete. The obligation to freeze and to report arises at the point of identification. Acting after an unnecessary delay without a documented reason for the delay creates independent enforcement exposure.
The report to SECO must contain sufficient information for the authority to assess the position: the identity of the person or entity believed to be covered, the nature of the assets or funds involved, the basis for the identification, and the steps the firm has taken in response. SECO does not publish a standardised reporting form for all programme types; firms must work from the applicable ordinance and SECO's own guidance for the relevant programme. This differs from OFSI, which operates a more developed public guidance framework, and from OFAC, which has published detailed guidance on how to report blocked property. In our experience, firms encountering a Swiss reporting obligation for the first time often underestimate the precision required in the submission.
A further point: Switzerland has a domestic anti-money-laundering framework that runs alongside SECO sanctions obligations. In certain circumstances – particularly for financial intermediaries – a sanctions identification may give rise to concurrent reporting obligations under the Anti-Money Laundering Act (AMLA) and to FINMA, Switzerland's financial-market supervisory authority. A procedure that addresses SECO reporting but ignores the parallel AMLA reporting pathway is incomplete. Any compliance counsel advising on SECO escalation design should map both reporting routes from the outset.
In a recent matter, a financial institution with a Swiss booking centre identified a potential SECO match through its group-wide screening system. The initial alert was raised in a non-Swiss entity and took several business days to reach the Swiss compliance team, by which time the relevant transaction had already partially settled. We assisted the client in mapping the asset-freeze obligation, preparing the SECO report, and restructuring the cross-border escalation pathway so that future alerts with a Swiss nexus reach the Swiss compliance officer directly and within a defined short window. The matter settled without a formal enforcement response, but the delay in the initial escalation remained on the regulatory record.
Step 5 – Cross-Border Escalation: When SECO and Other Regimes Apply Together
Switzerland is not an EU member, but it maintains close economic ties with EU markets and shares many counterparties with EU-regulated businesses. A cross-border B2B transaction frequently engages SECO, an EU Council Regulation, and – where a US nexus exists through USD clearing, US-person involvement, or US-origin goods – OFAC requirements simultaneously. The escalation procedure must be designed to manage this overlap, not to resolve each regime sequentially.
The practical consequence of multi-regime exposure is that the strictest applicable prohibition governs the transaction. If OFAC blocks it, the fact that SECO does not yet list the relevant person is irrelevant to OFAC; the reverse is equally true. Where designations diverge – a person listed by SECO but not by OFAC or the EU, or listed by the EU but not yet by SECO – the escalation procedure must direct the analyst to apply the applicable regime's prohibition independently, not to clear an alert simply because one regime's list does not carry the name.
Reporting lines in a multi-regime matter must also be separated clearly. A report to SECO does not discharge a concurrent obligation to OFSI or to OFAC. Each regime has its own reporting destination, its own information requirements, and – if applicable – its own voluntary self-disclosure (VSD, a disclosure to a regulator to acknowledge a potential violation before it is discovered and to seek mitigation) pathway. The procedure should map each regime's reporting obligation separately and name the person responsible for submitting each report.
One design question that arises repeatedly in our practice is whether to build a single integrated escalation document for all regimes or separate regime-specific annexes attached to a common framework. We generally advise a common framework for the internal escalation pathway – same trigger, same log, same owner – but regime-specific annexes for the reporting step, since the content, format, and destination of each report differ materially.
Step 6 – Testing, Governance, and Ongoing Maintenance
A written escalation and reporting procedure is a live document, not a one-time compliance project. SECO ordinances are amended as measures evolve; the list of designated persons is updated; cross-border designations diverge and converge. A procedure that was adequate at the time of drafting may have material gaps six months later if it has not been reviewed against these changes.
Governance of the procedure requires a named owner – typically the Chief Compliance Officer or the Head of Sanctions – who holds responsibility for monitoring SECO list updates, reviewing the procedure against any material change in the applicable ordinances, and triggering a full review on a defined annual cycle. The procedure should itself specify the review cycle, the trigger events that require an off-cycle review (such as a new ordinance entering into force, a significant change in the firm's counterparty base, or a near-miss escalation that exposed a gap), and the format for recording that reviews have taken place.
Testing is distinct from review. A tabletop exercise – running a realistic scenario through the escalation procedure to see whether the pathway, the authorities, and the timeframes hold – should be conducted annually and after any material revision. The results of the test, including any gaps identified and the remediation steps taken, should be documented and retained. SECO, like other sanctions authorities, considers the quality of a firm's compliance programme when assessing its response to an apparent breach; a well-documented test record is evidence that the procedure is genuine, not decorative.
Record-keeping must support both the escalation process and any subsequent regulatory interaction. Every trigger event, every escalation decision, every report submitted to SECO, and every clearance should be documented with sufficient detail to reconstruct the decision-making process if the matter is later reviewed. How long records should be retained is specified in the applicable ordinances and in SECO's own guidance; a compliance counsel should confirm the current requirement for the firm's specific circumstances before setting a retention policy.
A common myth here is that SECO enforcement is less active than OFAC or OFSI and that a less detailed procedure therefore carries acceptable risk. That is not a sound basis for calibrating a compliance programme. Switzerland takes its embargo obligations seriously at a regulatory level, and the legal exposure for a firm that cannot demonstrate adequate procedures – even if no breach occurred – is real. The standard is the quality of the procedure, not whether a breach happened.
Related practices
- Sanctions compliance audit and testing – Australia – programme testing and audit methodology across the Australian autonomous sanctions regime.
- Escalation and reporting under SECO – advanced issues – detailed treatment of concurrent reporting obligations and group-level escalation design.
- Escalation and reporting under the UN Consolidated List – managing escalation obligations where a UN Security Council designation is the trigger.
The position above covers the standard case. Your specific facts – the counterparty's ownership structure, the applicable ordinances, the goods or services involved, and any concurrent US or EU nexus – change the analysis in ways that a generic procedure will not capture.
For an assessment of your escalation and reporting procedures under SECO, contact Calder & Vance at info@caldervance.com.