Your compliance team has just received a formal communication from the State Secretariat for Economic Affairs (SECO – Switzerland's authority for export controls and economic sanctions) requesting information about a transaction, a counterparty, or an internal process. The clock is running. What you do in the next hours and days will shape the entire trajectory of the matter.
Responding to an information request under SECO is a structured, time-sensitive process governed by Swiss ordinances implementing UN Security Council resolutions and Switzerland's autonomous sanctions measures. There is no universal statutory response window published in SECO's guidance, but the expectation of prompt and complete cooperation is explicit. A poorly framed response – or an incomplete one – can transform a routine enquiry into a formal investigation.
This guide walks through every stage: from the moment you receive the request, through document gathering and legal-privilege analysis, to the submission itself – and it flags where Switzerland's position diverges from OFAC, OFSI, and the EU.
Step 1: Understand what SECO is actually asking
The first task is to read the request carefully and determine its legal character. SECO information requests fall into distinct categories. Some are routine transaction-monitoring queries – SECO asks whether a specific payment or shipment occurred. Others are structured enquiries into a counterparty's ownership or control chain. A third type signals that SECO suspects a possible breach and is gathering evidence under its enforcement authority.
The distinction matters immediately. A routine clarification request does not, on its face, require external counsel. A request that references a specific named party on the UN Consolidated List (SECO administers Switzerland's implementation of UN Security Council measures), or that asks you to produce internal communications, is a different proposition. In our experience, businesses frequently underestimate the second and third categories because the correspondence looks politely administrative. Do not be misled by tone.
Read every word of the request. Note which legal instrument is referenced – whether it is the Swiss embargo ordinances, an autonomous Swiss measure, or a UN measure implemented through Swiss law. Note whether SECO has set a response date. Note whether the request is addressed to the legal entity, to an individual, or both. All of this governs the shape of your response.
Step 2: Assemble your internal response team
Once you understand the request's character, convene an internal team before any document collection begins. The team should include the head of legal or compliance, the business unit responsible for the transaction in question, and – where the request touches financial flows – the finance function. If the matter has any cross-border dimension, that consideration needs to be live from day one.
A cross-border dimension is the norm, not the exception. Switzerland occupies a central position in global trade finance, commodity trading, and re-export flows. A transaction under SECO's scrutiny will often also touch OFAC's jurisdiction (if US persons, US-dollar clearing, or US-origin goods are involved), OFSI's jurisdiction (if UK persons or sterling flows are in play), or an EU Council regulation (if EU-nexus goods or entities are present). Does your internal team have the visibility to identify that overlap?
Assign a single internal coordinator. That person owns the privilege log, the document-collection chronology, and the communications with external counsel. Fragmented coordination is one of the most common causes of incomplete or inconsistent responses. We regularly advise clients to treat this appointment as the first formal act of their response process.
Step 3: Apply legal privilege and confidentiality analysis before any disclosure
Legal professional privilege under Swiss law protects communications between a client and a licensed Swiss lawyer (Rechtsanwalt / avocat) in the context of legal advice or proceedings. The protection is broadly comparable to English common-law privilege, but the Swiss position differs in one important respect: in-house lawyers do not enjoy the same privilege protection as external counsel under Swiss law. That distinction is relevant to every document-collection decision you make.
Before producing any document to SECO, map each document to one of three categories: (a) clearly producible, (b) clearly privileged or protected, and (c) uncertain. The uncertain category requires external counsel review. This is not a slow or bureaucratic step – it is the step that prevents inadvertent waiver of privilege over materials that could later become significant in a formal investigation or in a parallel proceeding in another jurisdiction.
The cross-regime angle here is sharp. If the same transaction is also under review by OFAC or by an EU competent authority, a disclosure made to SECO could, depending on how it is framed, be used in those parallel processes. The US, UK, and EU authorities share information with each other and, in certain circumstances, with Swiss authorities under mutual legal assistance channels. We have acted for businesses where a cooperative disclosure in one jurisdiction created an unexpected evidential record in another. Manage that risk from the outset.
For an assessment of your exposure across regimes, including EU apparent violations, see our EU apparent violation assessment service.
Step 4: Conduct a targeted document-gathering exercise
Answer only what is asked. That principle sounds obvious, but in practice the temptation to be comprehensively cooperative leads businesses to produce more than the request requires. Over-production is a risk, not a virtue. It places materials in front of the regulator that may raise questions beyond the scope of the original enquiry, and it can shift a routine information-gathering process into a broader investigation.
Collect documents systematically. For each item in scope, record: the document identifier, the date, the author, the custodian, whether it is privileged, and whether it has been produced or withheld. This is your privilege log and your production record. Maintain it as a live document throughout the process.
For financial-institution clients in particular, transaction records, correspondent-banking messages, and screening records are typically the first categories SECO will seek. Under Switzerland's anti-money-laundering and sanctions ordinances, financial intermediaries are subject to record-keeping obligations that generally require documentation to be retained for a period that practitioners routinely describe as at least five years – verify the current requirement under the applicable ordinance before relying on that figure. Gaps in records are almost always more damaging to a firm's position than the underlying transaction would have been.
Step 5: Draft the response – structure, content, and tone
A well-structured response to a SECO information request has four elements: an opening statement of the entity's cooperation posture; a factual account that directly answers each question posed; the document production, cross-referenced to the factual account; and a closing reservation of rights if the request raises questions beyond what the entity can confirm at this stage.
Factual accuracy is non-negotiable. Submissions to SECO are made under Swiss law; a knowingly false statement to a regulator carries criminal risk. State what you know, distinguish it clearly from what you have been unable to confirm within the time available, and – where facts are uncertain – say so explicitly rather than papering over the gap.
Tone matters. SECO is a professional government authority. Responses that are defensive, evasive, or that read as if they were drafted by a public-relations team rather than counsel create a poor impression and can prompt follow-up. Plain, factual, structured prose is correct. Avoid characterisations of the regulator's questions as unwarranted; address each question on its merits.
If the transaction also involves parties or goods subject to OFAC, OFSI, or EU controls, consider whether a single coordinated response strategy is appropriate. In our cross-border practice, we frequently manage simultaneous information requests from two or more regulators in connection with a single commercial transaction. The consistency of the account given to each authority is important; inconsistencies, even inadvertent ones, generate credibility questions that are difficult to resolve later.
How does SECO differ from OFAC, OFSI, and the EU in this context?
Switzerland's sanctions administration differs from the US, UK, and EU in several respects that directly affect how a business should approach an information request.
OFAC publishes detailed enforcement guidelines that set out the factors it weighs in determining whether to take action – including the nature of the apparent violation, the existence of a compliance programme, and whether the disclosure was voluntary. SECO's published enforcement posture is less granular in comparable publicly available guidance. That does not mean cooperation is less important; it means the evidentiary record you create through the quality and completeness of your response carries particular weight.
OFSI, under SAMLA and the relevant thematic regulations, has issued guidance on licensing, reporting of suspected breaches, and enforcement. OFSI's approach places significant weight on voluntary self-disclosure (VSD – the proactive reporting of a potential breach before the regulator becomes aware of it). SECO also operates in an environment where proactive engagement is viewed favourably, but the formal mechanism and its consequences differ. Do not assume that the OFSI or OFAC VSD calculus maps directly onto a SECO matter.
The EU presents a further contrast. Under EU Council regulations, the primary enforcement authority is the competent authority of the member state where the relevant entity or transaction is located. There is no single EU-level information-request process equivalent to an OFAC or SECO request. The EU General Court is the venue for designation challenges, not for enforcement matters of this kind. If your entity has EU operations, a SECO request and a parallel EU-competent-authority request may need to be managed separately and consistently.
Singapore and the UAE – for businesses with operations in those markets – operate their own information-gathering regimes. See our companion guides on responding to information requests in Singapore and responding to information requests in the UAE for those jurisdictions.
Risk flags: when does a SECO enquiry become something more serious?
Several indicators signal that an information request is transitioning from a routine clarification into a more serious regulatory process. Recognising them early preserves options.
The first indicator is specificity. A request that names a specific listed person, a specific transaction with a precise value or date, or a specific shipment of dual-use goods is not generic. It reflects that SECO has already formed a hypothesis. Treat it accordingly.
The second indicator is breadth. A request that asks for a wide range of internal communications, for records covering an extended period, or for information about your compliance programme itself is gathering systemic evidence, not transaction-specific clarification.
The third indicator is repetition. If SECO has already received one response and has come back with a follow-up request, it is either unsatisfied with the first response or has received information from another source that it is testing against your account.
A fourth indicator – and one that experienced compliance counsel flags immediately – is the simultaneous appearance of enquiries from multiple authorities in connection with the same transaction. If SECO is asking questions and, around the same time, a correspondent bank has suspended processing or an EU competent authority has made enquiries, those are not coincidences. They reflect coordinated information flows.
One objection we hear regularly is: "We did not intentionally breach any sanctions, so there is no real risk here." Intent is relevant to penalty severity in most regimes, but it does not determine whether a violation occurred. The strict-liability character of sanctions prohibitions means that an inadvertent breach of the Swiss embargo ordinances is still a breach. A well-documented response that demonstrates a functioning compliance programme and a good-faith response to the request materially affects the outcome – but the process still needs to be taken seriously from the outset.
If a transaction has already been flagged or a formal enquiry has escalated, an early legal review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your matter in confidence.
When to involve external counsel – and what to ask for
External counsel should be involved as early as possible. That is not a marketing statement; it is a structural observation. The decisions made in the first 48 hours of a regulatory information request – what to collect, what to produce, what to say, and what to hold back – set the parameters for everything that follows. Reversing a poorly framed early disclosure is considerably harder than getting the first response right.
Specifically, involve external counsel if: (a) the request references a named listed person or a named dual-use item; (b) the request asks for internal communications or compliance-programme records; (c) the matter has a cross-border dimension involving OFAC, OFSI, or EU authority; (d) a voluntary self-disclosure question arises in Switzerland or in a parallel jurisdiction; or (e) any parallel proceeding – however early – is visible in another jurisdiction.
What should you ask external counsel to do? The action library here is specific: scope the apparent issue and identify which instruments and authorities are in play; advise on privilege and confidentiality before collection begins; review and sign off the draft response before submission; advise on whether a proactive disclosure in Switzerland or in another jurisdiction is appropriate and on what timeline; and, if the matter escalates, manage the enforcement-defence process.
We have acted for commodity traders, financial intermediaries, and manufacturers of dual-use goods in connection with SECO information requests and enforcement processes. In each case, the quality of the initial response defined the arc of the matter.
Related practices
- EU Apparent Violation Assessment – structured analysis of EU sanctions exposure and enforcement risk for cross-border transactions
- Responding to Information Requests: Singapore – step-by-step guide to MAS and Singapore sanctions authority information requests