Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · SECO

Penalty defence and settlement under SECO: step by step

A Swiss-based trading house receives a formal inquiry from the State Secretariat for Economic Affairs. A shipment has been flagged. The compliance team has three days to assess what happened, who knew, and what to say. The instinct is to respond immediately. That instinct, unguided, is the first mistake.

Penalty defence and settlement under SECO – Switzerland's sanctions and export-control authority – follows a structured administrative process governed by Swiss domestic law. The authority has powers to impose civil and criminal penalties for breaches of Switzerland's embargo ordinances and export-control rules. Early legal assessment, careful evidence management, and a considered decision on whether to engage proactively are the three variables that most influence how a matter resolves.

This guide walks through the process step by step: from first notice to final resolution, with a cross-border comparison to OFAC, OFSI, and the EU enforcement models.

Step 1 – Understanding SECO's authority and the legal basis for enforcement

SECO administers Switzerland's autonomous sanctions ordinances and its embargo regulations, drawing authority from Swiss federal law on embargoes. The regime is independent of the EU but has historically tracked EU restrictive measures closely, with Switzerland adopting parallel measures through its own legal instruments rather than through EU Council regulations.

This distinction matters in practice. A business that has assessed its position solely against EU regulations may find that Swiss measures have a different scope, different listed persons, or different exemptions. Switzerland is not an EU member state. Its sanctions are legally autonomous, even where the policy objective is aligned.

SECO also administers Switzerland's export-control rules, including controls on dual-use goods under the applicable ordinance. An enforcement matter may engage both the sanctions and the export-control track simultaneously. In our cross-border practice, matters involving Swiss-domiciled entities frequently carry exposure across both tracks, and the procedural timelines on each can run concurrently.

Who within a business triggers SECO's attention? The triggers include: a bank flagging a transaction under Swiss anti-money-laundering rules, a customs authority identifying an irregular export declaration, a third-country authority sharing intelligence through official channels, or an internal disclosure by the business itself. The source of the inquiry shapes the early strategy.

Step 2 – What to do in the first 72 hours after a SECO inquiry

The first 72 hours are not for drafting the substantive response. They are for scoping, preserving evidence, and making an early legal assessment. A business that rushes to characterise its own conduct before it has mapped what happened risks locking in a narrative that does not hold.

Four actions should happen in parallel. First, issue a document-preservation notice to all relevant functions: trade finance, logistics, compliance, and any business unit that touched the transaction. Second, identify the specific shipment, counterparty, and ordinance that appears to be at issue. Third, assess whether parallel exposure exists under OFAC, OFSI, or the EU – a Swiss enforcement matter frequently sits alongside exposure in other regimes. Fourth, instruct external sanctions counsel before any substantive communication with SECO is sent.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the ordinance in play, and the involvement of any other jurisdiction – change the analysis materially. For a structured assessment of apparent-violation exposure across regimes, including the EU parallel, contact Calder & Vance.

Is the business obliged to respond by a fixed deadline? Swiss administrative process does impose response deadlines, but those deadlines are set out in the inquiry letter itself. They are not uniform across all matters. Counsel should assess the specific deadline before any filing is made.

Step 3 – Building the factual and legal case

The factual investigation and the legal analysis must proceed together, not sequentially. The facts determine which prohibitions were potentially engaged; the legal analysis determines what defences, exemptions, or mitigating circumstances apply.

The factual investigation should produce a transaction timeline: every step from order to delivery, every party that touched the goods or the funds, and every document that existed at each stage. This timeline serves two functions. It identifies what actually occurred. It also reveals what the business knew, or could reasonably have known, at each decision point – which is directly relevant to the question of intent under Swiss law.

Intent is a live question in Swiss enforcement. The severity of the sanction differs between a wilful breach and a negligent one. A business with a documented compliance programme, regular screening, and a clear process failure – rather than a deliberate decision to transact despite a known prohibition – is in a materially different position from one that took a commercial decision to proceed with an unchecked counterparty.

The legal analysis should address: whether the goods, technology, or services were in fact controlled; whether any exemption or authorisation applied at the time of the transaction; whether the correct ordinance version was in force on the relevant date; and whether the business had a good-faith basis for its position. Counsel with dual-use export-control experience alongside sanctions knowledge is important here, because the analysis often spans both.

Documentary hygiene matters considerably. Where a business can produce contemporaneous compliance records – screening logs, counterparty due-diligence files, legal opinions obtained before the transaction – these carry more weight than post-hoc reconstructions. If a transaction was screened and the result was documented, that is an important fact. If it was screened but the log no longer exists, that is a risk.

Step 4 – Assessing the voluntary disclosure option

The question of whether to make a voluntary self-disclosure – a VSD (a proactive disclosure of an apparent violation to the regulator before formal proceedings are initiated) – is one of the most consequential decisions in an enforcement matter. It is not self-evidently the right route in every case.

In many regimes, a VSD is treated as a significant mitigating factor. OFAC has formalised this in its enforcement guidelines, providing explicit credit for proactive disclosure. OFSI and the EU enforcement models also treat cooperation and self-reporting as relevant to penalty determination. SECO operates within a Swiss administrative law tradition that similarly weights cooperation and voluntary disclosure positively, though the mechanism and the degree of credit are governed by Swiss procedural rules rather than a published OFAC-style enforcement framework.

When is a VSD likely to be beneficial? The analysis turns on three variables. First, how likely is it that SECO will discover the matter independently? A matter already flagged by a bank or a customs authority is probably already in the system. Second, what is the relative severity of the underlying conduct? A minor administrative deficiency in export paperwork is a different VSD calculation from a deliberate transaction with a listed counterparty. Third, does a VSD in Switzerland interact with disclosure obligations or enforcement posture in another jurisdiction – OFAC, OFSI, or an EU competent authority – in a way that changes the overall risk picture?

In our experience, the multi-jurisdictional VSD question is where businesses most frequently need structured counsel. A disclosure in one jurisdiction can, depending on the facts, accelerate inquiry in another. That does not mean disclosure is wrong. It means the sequencing and content require careful management.

Step 5 – The settlement process and penalty mitigation

SECO, like other administrative enforcement authorities, resolves matters through a process that can include formal penalty proceedings, negotiated resolution, or a decision not to pursue further action where the matter does not meet a prosecution threshold. The settlement or resolution track is not identical to the OFAC civil-monetary-penalty settlement process, and it should not be approached as if it were.

Penalty mitigation under Swiss administrative law turns on a set of factors that counsel should address systematically. The nature and severity of the underlying conduct is the starting point: was there a clear prohibition, and was it breached? The degree of cooperation, the quality of remediation, and the robustness of the compliance programme at the time of the breach are all relevant. A business that has already taken documented remedial steps – strengthening its screening, retraining staff, restructuring its counterparty due-diligence process – demonstrates to SECO that the breach was an isolated event rather than a systemic failure.

What does the settlement filing itself contain? In the Swiss model, the response to a formal inquiry or the submission accompanying a VSD should include: a factual account of the transaction; an analysis of the applicable ordinance and the business's position under it; a description of the compliance programme as it existed at the time; documentation of any remedial steps taken; and, where relevant, an explanation of any authorisation, exemption, or good-faith basis the business relied on. The filing is not a confession and it is not merely a procedural response. It is a structured legal submission that directly shapes the outcome.

If a transaction has already been flagged, or a preliminary inquiry has been received, early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the specific matter and timeline.

Step 6 – Cross-border dimensions: how SECO compares to OFAC, OFSI, and the EU

Swiss enforcement rarely sits in isolation. A business with operations or banking relationships in the United States, the United Kingdom, or the EU may face parallel exposure across regimes. The enforcement models differ in ways that directly affect the cross-border strategy.

OFAC publishes a detailed enforcement framework that quantifies how specific mitigating and aggravating factors affect civil-monetary-penalty calculations. The framework references base penalty amounts, egregious-case multipliers, and explicit credit for VSDs. This transparency allows counsel to model the exposure range before a matter is resolved. SECO's enforcement process is governed by Swiss administrative law and does not publish an equivalent numerical matrix. The absence of a published framework does not mean outcomes are arbitrary, but it does mean that a counsel's read on the Swiss enforcement environment – the regulator's recent posture, the weight given to specific mitigating factors, and the practical threshold for prosecution – becomes more important, not less.

OFSI's enforcement model, following amendments to the applicable UK legislation, allows civil monetary penalties on a strict-liability basis for financial sanctions breaches – that is, without requiring proof of knowledge or intent, though these remain relevant to penalty quantum. The EU competent authorities vary by member state, but the trend is toward more active enforcement with increased penalties. Switzerland's approach remains intent-sensitive, which is a meaningful distinction for a business assessing its position across regimes.

Secondary-sanctions risk also enters the picture. Where a Swiss business operates in a sector or geography that also triggers potential OFAC exposure, the US enforcement posture is part of the risk map even if the primary inquiry is with SECO. OFAC has asserted extraterritorial jurisdiction over non-US persons in circumstances involving US-dollar transactions, US-origin goods or technology, and US persons as counterparties or intermediaries. A Swiss matter with any of these connections carries secondary-sanctions risk that must be assessed alongside the domestic Swiss position.

For matters involving Singapore or UAE entities on the same transaction chain, parallel considerations arise under those regimes' own enforcement tracks. Our guide on penalty defence and settlement in Singapore and the corresponding guide for the UAE set out the specific steps for those regimes.

Step 7 – Remediation and the post-resolution compliance posture

Resolution of the enforcement matter is not the end of the compliance work. A business that has been through a SECO inquiry is, for a period, under a higher level of scrutiny – from SECO, from its banking counterparties, and potentially from other regulators who are aware of the matter. The compliance posture after resolution shapes both the regulatory relationship and the risk of recurrence.

Effective remediation has a specific structure. It is not sufficient to declare that controls have been improved. Documented remediation means: a root-cause analysis identifying exactly how the breach occurred; specific control changes addressing each root cause; staff retraining with documented completion records; updated screening procedures covering the gap identified; and, where the breach involved a counterparty that has now been removed from the business's approved list, documented evidence of that removal and the process change that prevents similar counterparties from being onboarded in future.

In our experience, businesses that invest in substantive remediation – not as a performance for the regulator, but as a genuine recalibration of their controls – are in a demonstrably stronger position for both the current matter and any future inquiry. The regulator's assessment of whether a breach was isolated or systemic is informed not just by what happened on the specific transaction, but by the quality of the compliance programme before and after it.

What is the practical standard for a well-functioning sanctions compliance programme? Practitioners working across the major regimes look to a five-element model: management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC's published compliance guidance formalised this structure, and it has become the reference standard across other regimes including OFSI and, in practice, for assessing compliance adequacy under the Swiss framework. Calder & Vance tests and builds programmes to this standard.

Common mistakes and risk flags in SECO penalty defence

The most consistent errors in SECO penalty defence are not technical mistakes about the law. They are process errors made in the first days after an inquiry arrives.

The first is substantive engagement before the scope is clear. A business that sends a detailed response to SECO characterising the transaction as compliant – before its own internal investigation is complete – may find that the characterisation is contradicted by documents that emerge later. Silence is not always the answer either; but a holding response that acknowledges receipt, confirms the business is investigating, and gives a realistic timeline for a substantive reply is almost always preferable to a premature position.

The second is treating the SECO matter as wholly domestic when it is not. Many Swiss businesses operate banking relationships through institutions with US correspondent banks. A transaction that was processed through a US-dollar clearing system by a US correspondent bank can carry OFAC exposure even if the business itself has no US presence. That exposure must be assessed before any response strategy is finalised.

The third is failing to identify all potentially applicable ordinances. Switzerland has a range of autonomous sanctions ordinances in force. A compliance function that focused solely on one regime may have missed obligations under a different ordinance covering the same counterparty or goods category.

The fourth – and perhaps the most persistent myth in this area – is the belief that because Switzerland has historically taken a less aggressive enforcement posture than OFAC or OFSI, a SECO inquiry can be managed informally without dedicated legal preparation. This is incorrect. Switzerland's enforcement posture has evolved. SECO has increased its engagement with export-control and sanctions matters, its coordination with other authorities has deepened, and the penalties available under Swiss law – including criminal penalties for wilful breach – are serious. A business that approaches a SECO inquiry as a paperwork exercise, rather than an enforcement matter, risks a materially worse outcome.

Related practices

Frequently asked questions

What are the steps to defend a penalty case under SECO?
Effective defence begins with immediate evidence preservation and a scope assessment before any substantive response is sent to SECO. The core steps are: preserve documents; instruct counsel; map the relevant ordinance and the facts; assess parallel exposure under OFAC, OFSI, or the EU; decide on the VSD question; prepare a structured legal submission addressing the facts, the applicable law, and any mitigating factors; and implement documented remediation. Each step feeds into the next. Skipping the early assessment to save time typically costs more time – and a worse outcome – later.
What is the most common mistake in penalty defence and settlement?
The most common mistake is sending a substantive characterisation of the transaction to SECO before the internal factual investigation is complete. A premature response that frames the conduct as compliant – and is then contradicted by documents or communications identified later – damages credibility with the regulator and narrows the space for an effective defence. The second most common mistake is treating the matter as purely domestic when the transaction chain has US-dollar, US-person, or US-goods elements that carry potential OFAC exposure in parallel.
How does SECO differ from other regimes here?
Three differences are practically significant. First, SECO operates under Swiss administrative law rather than publishing a numerical enforcement matrix comparable to OFAC's; the absence of a published framework makes practitioner knowledge of the enforcement environment more important. Second, Switzerland's enforcement approach is intent-sensitive – the distinction between wilful and negligent breach affects penalty severity – whereas OFSI can impose civil monetary penalties on a strict-liability basis. Third, Switzerland's autonomous sanctions are legally separate from EU Council regulations, meaning the exemptions, listed persons, and ordinance scope do not automatically mirror the EU position, even where the policy direction is aligned.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.