Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · SECO

Supply-chain sanctions mapping under SECO: a practical guide

A Swiss-based trading house routes a shipment through three intermediaries before goods reach their destination. Screening the direct counterparty returns no alerts. Weeks later, a compliance review surfaces a second-tier supplier whose ultimate beneficial owner appears on a SECO sanctions list. The deal is already closed. Supply-chain sanctions mapping under SECO – tracing the ownership and control chain across every tier of a transaction – is the discipline that catches this risk before it crystallises.

As of January 2026, Switzerland's sanctions regime is administered by the State Secretariat for Economic Affairs (SECO), operating under federal ordinances that implement UN Security Council measures and autonomous Swiss measures. Any person or entity subject to Swiss law – or transacting in Switzerland – must ensure that goods, funds, and services do not flow to listed counterparties, directly or through intermediaries. Supply-chain mapping is the structured process that operationalises that obligation across multiple tiers of suppliers, customers, and financiers.

This guide walks through the mapping process in five practical stages, identifies where Swiss obligations diverge from those under OFAC, OFSI, and the EU, and flags the patterns that most frequently generate enforcement exposure under the applicable Swiss regime.

Step 1: Establish the legal perimeter – what does SECO regulate and who does it catch?

SECO administers Swiss economic sanctions through ordinances enacted under the federal Embargo Act. The ordinances implement both mandatory UN Security Council measures and autonomous Swiss measures that may mirror, diverge from, or exceed EU positions.

Scope is defined by connection to Switzerland – not by the nationality of the parties. A foreign company transacting through a Swiss bank, using Swiss export infrastructure, or contracting with a Swiss counterparty is within the perimeter. The question is not "are we a Swiss company?" but "does this transaction touch Switzerland in a material way?"

In our cross-border practice, clients regularly underestimate the connectivity point. A Swiss franc payment cleared through a Swiss correspondent is sufficient to engage Swiss obligations – even if both buyer and seller are incorporated elsewhere. A prudent first step in any supply-chain mapping exercise is therefore to identify every Swiss touchpoint: payment currency and clearing bank, transit jurisdiction, the seat of any group entity, and the governing law of the contract.

The SECO consolidated list is the primary screening reference. It incorporates UN Security Council designations, and in many thematic programmes it also reflects autonomous Swiss additions. The list is publicly available and updated without notice. Static, point-in-time screening is therefore structurally inadequate for sustained trading relationships – a point we address at Step 4.

Step 2: Map the counterparty ownership and control chain across every tier

Once the legal perimeter is established, the mapping exercise turns to the counterparty chain itself. Under Swiss ordinances – as under OFSI and EU Council regulations – a prohibited interest attaches not only to listed persons but also to entities owned or controlled by them.

How deep does the mapping need to go? The answer is risk-calibrated, not mechanical. A direct supplier with publicly available, clean ownership records in a low-risk jurisdiction requires less depth than an intermediary in a jurisdiction with limited corporate-transparency rules. The following factors govern depth of review:

  • The nature of the goods or services – dual-use or controlled items demand greater depth.
  • The jurisdiction of incorporation and the quality of its beneficial-ownership registry.
  • The transaction value and the counterparty's role (direct supplier, sub-supplier, financier, agent).
  • Prior screening alerts, refusals, or customer-due-diligence concerns.
  • Whether the counterparty operates in or through a jurisdiction subject to thematic Swiss measures.

On ownership thresholds: OFAC's 50 percent rule (treating any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked) is mechanical and bright-line. SECO's ordinances and EU Council practice adopt a broader ownership and control test: ownership at or above a material threshold raises a presumption, but de facto control through directors, contractual rights, or economic dependency can catch entities owned well below that line. This difference matters when a listed person holds, say, forty-two percent of a supply-chain company: OFAC's rule does not automatically block the entity; Swiss and EU analysis requires the control question to be answered on the facts. The stricter prohibition governs when obligations overlap – meaning an entity that passes the OFAC threshold test may still be caught under Swiss analysis.

Document the ownership and control chain clearly. A mapping diagram that shows each tier, the percentage holdings, and the source of the beneficial-ownership information will be the primary evidence if a transaction is ever queried by SECO.

How does SECO differ from OFAC, OFSI, and EU sanctions in a supply-chain mapping context?

The four major regimes share a common objective but diverge in ways that directly affect mapping methodology. Understanding those divergences avoids both under-compliance (applying only one regime's standard) and redundant over-process.

The ownership and control test is the most operationally significant difference, as noted above. OFAC is threshold-mechanical; SECO, OFSI, and the EU all apply a broader control analysis. In our experience, clients who run their mapping to the OFAC standard and assume they have satisfied Swiss and EU obligations regularly miss control arrangements that do not reach the fifty-percent floor.

OFAC also has explicit extraterritorial reach through secondary sanctions (measures that can expose non-US persons for dealings with certain designated counterparties, even absent a US nexus). SECO does not operate a secondary-sanctions regime in the same sense. Switzerland's autonomous ordinances can, however, designate persons not designated under UN measures, and may be updated independently of EU Council decisions. A counterparty that passes EU screening may still appear on the autonomous Swiss list – another reason to run both checks.

On the question of licensing, SECO administers an authorisation process for transactions that would otherwise be prohibited. The EU licensing regime operates through national competent authorities in each member state; OFSI administers the UK specific-licence process. Timelines, evidentiary requirements, and the grounds for authorisation differ across regimes. Where a supply-chain mapping exercise surfaces a potential issue, the question of which regime's authorisation route is relevant – and whether multiple licences are needed – should be answered early.

Canada's SEMA regime, Australia's autonomous sanctions, and the Singapore and UAE frameworks each apply their own nationality and nexus tests. For a cross-border supply chain that touches any of these jurisdictions, mapping against a single regime is insufficient. We regularly advise clients to build a multi-regime mapping matrix – one column per relevant jurisdiction, one row per supply-chain tier – so that gaps are visible before the transaction completes.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regimes in play – change the analysis. For a confidential review of a supply-chain mapping challenge, contact Calder & Vance at info@caldervance.com.

Step 3: Screen each tier against the SECO list and cross-reference other consolidated lists

Screening is not a single event. It is a structured, repeatable process with defined triggers for re-screening. A supply-chain mapping exercise should establish five elements for each tier of the chain:

  1. Initial screening against the SECO consolidated list, the UN Security Council Consolidated List, and any other regime's list that is triggered by the transaction's nexus.
  2. Name variant and transliteration controls – listed persons are often added under multiple name forms. Screening tools that match exact strings will miss phonetic and transliteration variants.
  3. Indirect-ownership screening – ownership chains, not just the immediate counterparty entity. A clean entity owned by a listed person is not clean.
  4. Trigger-based re-screening at defined events: contract renewal, change of control in the counterparty, payment instruction change, or a new designation affecting the relevant sector or jurisdiction.
  5. Record of the screening output, including the date, the lists consulted, the tool version, and the disposition of any alert.

Screening tools vary widely in quality. We have observed that commercially available platforms frequently carry outdated list data, apply insufficiently broad fuzzy-matching logic, or fail to surface ownership structures beyond the direct counterparty. For supply chains with material Swiss nexus, a manual or analyst-assisted check of the SECO list – in addition to any automated tool – is prudent where alert volumes are low enough to permit it.

One practical shortcut that creates risk: relying on a counterparty's self-certification ("we are not on any sanctions list") as the only screening measure. Self-certification is a useful input but not a substitute for independent screening.

Step 4: Build a continuing-monitoring process for sustained relationships

A sanctions mapping exercise conducted at on-boarding provides a snapshot. For any ongoing commercial relationship, the snapshot becomes unreliable over time – and the obligation to screen is continuous, not one-off. SECO's consolidated list, like the EU list and the UN list, is updated without advance notice. A supplier that was clean in March may be designated in July. A beneficial owner who held shares indirectly may acquire a controlling stake after the initial review.

A continuing-monitoring process for supply-chain relationships should specify:

  • The frequency of routine re-screening (typically at least quarterly for medium-risk relationships, monthly or continuous for high-risk).
  • The alert-management workflow: who receives alerts, who makes the disposition decision, and what escalation path applies when an alert cannot be cleared.
  • The review triggers beyond periodic re-screening: a payment instruction change, a new beneficial-ownership disclosure, a news-source flag, or a regulatory notification.
  • Record-keeping: all screening outputs and dispositions retained for a defined period. Swiss practice aligns with broader financial-sector record-keeping standards; verify the current requirement before relying on any specific number of years.

Continuing monitoring also means watching for indicators of transshipment or diversion risk. Goods that change transit points without a credible commercial reason, invoices that are inconsistent with the declared goods, and payment routes that pass through jurisdictions unconnected to the commercial relationship are all patterns that a monitoring process should flag for investigation.

If a transaction has already been flagged, or a supply-chain alert has been escalated without resolution, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for an assessment.

Step 5: Record-keeping, escalation, and when to involve counsel

The mapping process is only as useful as the records it generates. Regulators examining a potential breach will ask to see evidence that mapping was conducted, not merely asserted. A well-documented supply-chain sanctions programme should maintain the following materials:

  • A written mapping methodology, describing the tiers covered, the depth of ownership review, and the lists consulted.
  • Entity-level screening records, including the date, the lists checked, the tool or analyst who ran the check, and any alert disposition.
  • Ownership and control diagrams for non-public or complex counterparties.
  • Evidence of re-screening at defined intervals and at trigger events.
  • An escalation log recording any alert that was escalated, the analysis applied, and the outcome.

When should counsel be involved? The honest answer is: earlier than most compliance teams instinctively choose. The following situations call for specialist advice rather than in-house resolution:

  • An ownership or control analysis that does not clearly resolve below or above the relevant threshold.
  • A screening alert that cannot be cleared with reasonable confidence after good-faith investigation.
  • A transaction that appears to require an authorisation under any of the applicable regimes.
  • A discovered breach or near-miss, where voluntary self-disclosure may be relevant.
  • A supply-chain structure that involves multiple regimes with potentially divergent results.

In a recent matter, a manufacturing business identified, through its supply-chain mapping process, that a second-tier component supplier had been designated under the applicable Swiss regime after a payment had already been made. We scoped the apparent violation, advised on the disclosure question under the applicable regime, and prepared the written record of the compliance response. The matter was resolved without penalty proceedings, though no outcome can be guaranteed in any case.

Common risk flags and patterns that generate enforcement exposure

Supply-chain mapping failures tend to cluster around a small number of recurring patterns. Identifying them in advance is the most efficient way to concentrate a mapping programme's attention.

First-tier-only screening. Mapping that stops at the direct counterparty misses the category of risk that generates the greatest enforcement exposure: indirect dealings with listed persons through clean intermediaries. The presence of a professionally managed, unlisted Swiss trading company in the chain does not eliminate risk if that company is owned or controlled by a listed person. The control test under SECO and EU analysis expressly catches this structure.

Beneficial-ownership opacity in certain jurisdictions makes the mapping exercise structurally harder. Where a counterparty is incorporated in a jurisdiction without a public beneficial-ownership register, the mapping effort must rely on contractual disclosure, corporate documents, and, where appropriate, specialist verification services. A counterparty that refuses to provide beneficial-ownership information is itself a risk flag.

Payment-instruction changes are a particularly high-risk trigger. When a counterparty directs payment to a new account, in a different jurisdiction, without a clear commercial explanation, the change may indicate that the original counterparty has become subject to measures and is attempting to route funds through an unaffected third party. This is a pattern that a monitoring process should catch, and it requires immediate escalation.

Goods with dual-use potential – items that have both civil and military applications – attract additional attention under Swiss export-control rules administered alongside the SECO sanctions regime. A supply-chain mapping exercise for a technology or components business should integrate export-control classification review with the sanctions screen, not treat them as separate processes. We have acted for exporters whose supply-chain sanctions mapping was thorough but whose export-classification process operated in a separate silo – creating gaps that only became apparent in an enforcement enquiry.

Do you have visibility into the third tier of your supply chain, or only the first? That question is worth asking before the next transaction closes.

Related practices

Frequently asked questions

What are the steps to map sanctions risk in the supply chain under SECO?
Supply-chain sanctions mapping under SECO follows five main stages: establish whether Swiss nexus exists; trace the ownership and control chain for each counterparty tier; screen each entity against the SECO consolidated list and other applicable lists; build continuing-monitoring with defined re-screening triggers; and maintain full documentary records of the process and its outputs. Each stage involves a judgment about depth of review calibrated to the risk profile of the relationship. Counsel should be involved wherever an alert cannot be clearly resolved or where ownership is opaque.
What is the most common mistake in supply-chain sanctions mapping?
The most common error is screening only the direct counterparty, without tracing the underlying ownership and control chain. A clean entity whose ultimate beneficial owner is a listed person is not a clean counterparty under Swiss, EU, or UK analysis. A related error is treating the initial on-boarding screen as sufficient: listed persons can be added at any time, so ongoing monitoring is structurally required for any sustained commercial relationship.
How does SECO differ from other regimes here?
SECO administers both UN-derived measures and autonomous Swiss measures that can diverge from EU positions. Unlike OFAC, SECO does not operate a secondary-sanctions regime, but its autonomous list may include persons not on EU or OFAC lists, making cross-reference essential. The ownership and control test under Swiss practice is broader than OFAC's mechanical fifty-percent rule, and aligns more closely with the EU and OFSI approaches. For multi-jurisdictional supply chains, the stricter prohibition across applicable regimes governs.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.