Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · SECO

Internal sanctions investigations under SECO: procedure and pitfalls

A Swiss trading company routes a commodity shipment through a correspondent bank in Zurich. Weeks later, the bank's automated screening flags a name match in the ownership chain. The compliance team must now decide: is this a genuine hit, a false positive, or something that requires a formal internal investigation under Swiss sanctions law? The answer – and how quickly the company acts – will shape every conversation it subsequently has with the State Secretariat for Economic Affairs (SECO), Switzerland's competent authority for sanctions implementation and enforcement.

An internal sanctions investigation under SECO is a structured, legally informed review of whether a company has conducted, facilitated, or been exposed to a transaction that breaches Swiss sanctions ordinances. SECO administers Switzerland's autonomous and UN-aligned sanctions regime under the Embargo Act, and it holds inspection and reporting powers that make the quality of an internal investigation directly relevant to any subsequent enforcement outcome. As of March 2026, Swiss sanctions exposure increasingly arises from cross-border transactions that simultaneously attract OFAC, OFSI, and EU scrutiny – meaning that an investigation scoped only to Swiss law often misses the fuller risk picture.

This guide walks through the procedure for an internal SECO sanctions investigation in six stages, flags the pitfalls that most commonly derail it, and explains when external counsel should be brought in.

Step 1: Scope definition – what triggers a SECO internal investigation?

A SECO internal investigation is triggered whenever a company identifies a potential breach of a Swiss sanctions ordinance – or a credible indicator that one may have occurred. The trigger does not have to be a confirmed hit; a well-designed compliance programme treats the following as presumptive triggers requiring a scoping decision: a name match against the Swiss SECO list during transaction screening, a payment routed through a sanctioned jurisdiction's correspondent, an allegation from a whistleblower or a counterparty, or a direct enquiry from SECO itself.

Scoping is the most consequential decision in the investigation. Too narrow, and the review fails to capture the full exposure. Too broad, and it generates document volume that makes a future voluntary disclosure unwieldy. In our cross-border practice, we recommend framing scope around three axes: the relevant sanctions ordinance or ordinances, the transaction population that falls within the relevant period, and the individuals and entities whose conduct is under review.

One practical discipline that firms often neglect at this stage is the parallel scoping question: does the same set of facts potentially breach OFAC regulations, EU Council regulations, or OFSI requirements? Switzerland's autonomous regime does not always replicate US, UK, or EU designations precisely. A counterparty may be designated under an EU regulation but not yet under a Swiss ordinance – or vice versa. Establishing the multi-regime map at the outset prevents a later finding that the investigation answered the Swiss question but left the OFAC exposure unaddressed.

Step 2: Evidence preservation and document hold

Once the scope is defined, the investigation team must immediately secure the documentary record before any routine deletion, archiving, or modification can occur. Under Swiss law, document and record-keeping obligations exist across the banking, financial intermediary, and trading sectors; the investigation team should map those obligations before issuing a hold notice.

The hold notice must be specific enough to be actionable but broad enough to capture all potentially relevant material. It should cover payment instructions, SWIFT messages, counterparty onboarding files, beneficial-ownership records, internal approvals, and any communications that touch the flagged transaction or the named counterparty. Email, instant messaging platforms, and shared drives all fall within scope if they were used in relation to the conduct under review.

A cardinal error at this step is issuing a hold that is confined to the compliance department. In our experience, the most material evidence in a SECO investigation frequently sits in the business unit that executed the transaction: a relationship manager's notes, a trader's instruction, or a credit officer's sign-off. Have you extended the hold to every team that touched the deal, or only to those who initially raised the flag?

Cross-border document-hold complications arise when relevant evidence sits in group entities in other jurisdictions. EU data-protection rules, local bank-secrecy laws, and US discovery considerations can all bear on how evidence is collected, transferred, and reviewed. These tensions should be mapped before collection begins, not after.

Step 3: Fact-gathering and witness engagement

Fact-gathering in a SECO investigation proceeds through document review, data analysis, and, where appropriate, interviews with employees and relevant third parties. The sequence matters. Documents should be reviewed before interviews: witness accounts are most valuable when they are tested against the documentary record, not generated in advance of it.

Interview preparation requires clarity on the status of the individual being interviewed. An employee who may be personally implicated in a potential breach occupies a different position from a witness with no personal exposure. In Switzerland, employment-law protections and data-protection obligations constrain how interviews are conducted and how the contents are recorded. A verbatim transcript may be appropriate in some cases; a structured memorandum of interview in others. The choice has implications for privilege and for potential future use of the record.

Legal professional privilege – specifically, the question of what communications in the investigation are protected from disclosure to SECO or to other authorities – is a point where Swiss practice diverges from UK and US approaches. Switzerland recognises privilege for advice given by an admitted Swiss attorney. Communications with in-house lawyers and with foreign-qualified lawyers operating in Switzerland may attract more limited protection. This is not a reason to exclude in-house counsel from the investigation, but it is a reason to be deliberate about which communications are routed through external Swiss counsel and which are not.

How does the SECO regime differ from OFAC, OFSI, and the EU on internal investigations?

SECO does not operate a formal voluntary self-disclosure programme equivalent to OFAC's VSD (voluntary self-disclosure) framework, which can lead to a significant reduction in the base civil penalty. That does not mean proactive engagement with SECO carries no benefit – it does – but the mechanics and the degree of mitigation credit are handled differently. Understanding this distinction is essential before a company decides how and when to approach the authority.

OFAC's VSD process involves a written submission setting out the apparent violation, a self-assessment against OFAC's enforcement factors, and – where appropriate – a request for a no-action letter. OFAC publishes its enforcement guidelines, and the framework creates a relatively structured pathway. In our practice advising clients across both regimes, the structured nature of the OFAC VSD often provides a useful template for what information SECO will expect to see in a proactive disclosure, even though the Swiss authority does not operate the same formal framework.

OFSI in the United Kingdom imposes a statutory reporting obligation on persons who know or have reasonable cause to suspect they hold frozen funds or that a sanctions breach has occurred. The reporting window is short, and failure to report is itself a breach. SECO's reporting obligations arise under the Embargo Act and the applicable ordinance and are not identical in scope or timeline to OFSI's. This difference catches Swiss-based financial institutions that assume the UK model applies universally.

The EU regime, administered through Council regulations and implemented by member-state competent authorities, operates yet another set of rules. An entity subject to both Swiss and EU sanctions – for example, a Swiss bank with a Luxembourg branch – must map its disclosure and reporting obligations across both regimes simultaneously. We regularly advise on exactly this intersection: ensuring that the internal investigation produces a single coherent factual record that can be tailored to the requirements of each authority, rather than requiring a separate investigation for each regime.

For further analysis of how a parallel investigation works under EU rules, see our EU apparent violation assessment service.

Step 4: Legal analysis and gap assessment

Once the factual record is assembled, the investigation moves to legal analysis: do the facts establish a breach of the relevant Swiss sanctions ordinance, and if so, under which prohibition? This stage requires a clear mapping of the conduct identified against the specific prohibitions in the applicable ordinance – asset-freezing obligations, transaction prohibitions, and, where relevant, circumvention prohibitions.

The legal analysis should also address: who within the corporate group bears legal exposure, whether that exposure is civil or potentially criminal under Swiss law, and what aggravating or mitigating factors would be relevant to a SECO enforcement assessment. Aggravating factors in Swiss enforcement practice typically include concealment, repetition, and senior-management involvement. Mitigating factors include proactive disclosure, remediation, and the demonstration of a strong compliance programme.

The gap assessment runs in parallel with the breach analysis. Even where the investigation concludes that no breach occurred, it should identify the compliance weaknesses that allowed the potential breach to go undetected for as long as it did. SECO, like OFAC and OFSI, looks not only at whether a breach occurred but at the adequacy of the controls that surrounded the relevant activity. A gap assessment that produces a concrete remediation plan is itself a mitigation factor.

The position above covers the standard path through the legal analysis. Your facts – the specific ordinance, the counterparty's ownership structure, the transaction type, and the involvement of non-Swiss group entities – change the analysis significantly. If you are at this stage of an investigation, an early external review can clarify the exposure before a disclosure decision is made. Contact Calder & Vance at info@caldervance.com.

Step 5: Remediation and the disclosure decision

Remediation and the disclosure decision run concurrently and are connected: the credibility of a proactive approach to SECO is strengthened when the company can demonstrate, at the point of contact, that it has already implemented concrete fixes rather than merely promised them.

Remediation measures will typically include: updating screening lists and parameters, revising counterparty-onboarding procedures, retraining relevant business-line staff, and – where a compliance-programme gap contributed to the breach – restructuring the compliance function. Each measure should be documented with an implementation date and a responsible owner. SECO, like other enforcement authorities, gives weight to remediation that is specific, timed, and verifiable, not to general assurances of improvement.

The disclosure decision requires legal judgment. Where a clear breach has occurred, proactive engagement with SECO is generally in the company's interest, but the form, content, and timing of the disclosure require careful preparation. An incomplete or inaccurate initial disclosure is worse than a well-prepared later one. In our experience, the companies that fare best in SECO enforcement interactions are those that present a coherent factual narrative, a clear legal analysis, and a documented remediation plan in a single structured communication – not those that disclose first and think later.

Where the investigation reveals cross-regime exposure, the disclosure strategy must coordinate across jurisdictions. A disclosure to SECO that inadvertently contains information that could be used by OFAC in a parallel enforcement context is a genuine risk, and one that requires experienced multi-regime counsel to manage.

If a transaction has already been flagged by SECO or by a correspondent bank, or if a filing has been questioned, an early review of your position can preserve options that narrow with time. Write to us at info@caldervance.com to discuss a confidential review.

Step 6: Investigation closure, documentation, and lessons learned

An internal investigation closes when the factual record is complete, the legal analysis has been signed off, remediation has been implemented or is on a documented timeline, and the disclosure strategy has been executed. The investigation report – the formal document that records all of this – is a critical output.

The report should be drafted with the recognition that it may ultimately be reviewed by SECO, by another enforcement authority, or in a judicial or arbitral proceeding. That does not mean it should be defensive or incomplete: a report that clearly sets out what happened, what the legal position is, and what has been done in response carries far more credibility with enforcement authorities than a document that hedges every finding. The report should be prepared under external legal supervision, and the privilege status of each section should be clearly understood before the document is finalised.

Record-keeping obligations apply to the investigation itself as much as to the underlying transaction. SECO and the applicable Swiss law impose record-keeping requirements on regulated entities and on sanctions-related activity. In our cross-border practice, we maintain a discipline of ensuring that every investigation produces a document set that is organised, indexed, and held in a form that can be produced to an authority on short notice.

The lessons-learned exercise is not optional. It is the mechanism by which the investigation produces lasting compliance value rather than merely closing a specific exposure. The lessons should be documented, reviewed by senior management, and incorporated into the next cycle of the company's compliance programme review.

Common pitfalls and risk flags in SECO internal investigations

Several recurring mistakes distinguish investigations that resolve cleanly from those that generate secondary exposure. Recognising them at the outset is cheaper than correcting them after the fact.

  • Premature closure. Investigations that close before the full transaction population has been reviewed frequently miss related conduct that surfaces later, often in a more damaging context.
  • Single-regime scoping. Confining the investigation to Swiss ordinances when the facts engage OFAC, OFSI, or EU regulations creates a gap that other authorities may later fill. Switzerland does not operate in a sanctions vacuum.
  • Privilege mismanagement. Treating all investigation communications as privileged without mapping the applicable rules creates a false assumption that is exposed when a disclosure is made. Equally, routing everything through in-house counsel without engaging external Swiss-qualified counsel may leave the most sensitive communications unprotected.
  • Disclosure without preparation. A proactive approach to SECO that is not supported by a complete factual record and a clear legal narrative can create more questions than it answers.
  • Remediation as afterthought. Beginning remediation only after SECO has made contact signals that the company's compliance culture is reactive rather than preventive. Starting remediation during the investigation is the stronger posture.
  • Inadequate senior-management involvement. Internal investigations that remain within the compliance function, without appropriate board or audit-committee oversight, are more likely to be under-resourced and more likely to generate governance findings.

A common misconception deserves direct correction here: some compliance teams believe that because Switzerland operates a largely autonomous sanctions regime – distinct from the EU's member-state framework – SECO enforcement is inherently softer or less consequential than OFAC or OFSI action. This is a myth. SECO holds meaningful inspection and penalty powers under the Embargo Act, and Swiss courts have demonstrated willingness to give those powers effect. The risk of underestimating SECO's enforcement posture is that it shapes an investigation that is under-resourced and under-documented – precisely the condition that makes an enforcement outcome worse.

Related practices

Frequently asked questions

What are the steps to run an internal investigation under SECO?
A SECO internal investigation proceeds through six stages: trigger identification and scope definition; document hold and evidence preservation; fact-gathering through document review and interviews; legal analysis and gap assessment against the applicable ordinance; remediation and the disclosure decision; and formal investigation closure with a documented lessons-learned exercise. Each stage should be supervised by qualified legal counsel, and the investigation record should be prepared with the recognition that it may be reviewed by SECO or another enforcement authority.
What is the most common mistake in internal sanctions investigations?
The most common mistake is scoping the investigation solely to the Swiss sanctions ordinance when the same facts engage OFAC, OFSI, or EU regulations. A counterparty may be designated under an EU Council regulation but not under the equivalent Swiss ordinance, or vice versa, and a single-regime investigation leaves that exposure unaddressed. The second most common mistake is disclosing to SECO before the factual record is complete – an incomplete initial disclosure is harder to recover from than a well-prepared later one.
How does SECO differ from other regimes here?
SECO does not operate a formal voluntary self-disclosure programme equivalent to OFAC's VSD framework. Its reporting obligations under the Embargo Act and the applicable ordinances differ in scope and mechanics from the statutory reporting duty under OFSI in the United Kingdom. Swiss privilege rules for in-house and foreign-qualified lawyers are narrower than their US or UK equivalents, which affects how investigation communications should be routed. These differences make it important to engage counsel with cross-regime experience rather than applying a single-regime investigation template to a Swiss matter.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.