A mid-sized European bank maintains correspondent-banking relationships across several markets. A routine screening refresh flags that one of its downstream correspondents maintains accounts for entities whose ultimate beneficial owners appear on the Swiss sanctions lists administered by SECO (the State Secretariat for Economic Affairs, Switzerland's authority for implementing UN Security Council and Swiss autonomous sanctions measures). The correspondent's home supervisor is now asking questions. The European bank's compliance committee convenes at short notice. Is the relationship still viable? Can the bank continue to process payments? These are not abstract questions. They carry direct liability consequences under Swiss law and, depending on the payment flows, under the rules of other regimes too.
Correspondent-banking de-risking (the practice of a bank terminating or restricting a relationship to reduce sanctions or financial-crime exposure) is one of the most legally consequential decisions a financial institution takes. Under the Swiss sanctions regime, a bank that continues to process transactions for a blocked entity may face enforcement by SECO; a bank that exits a relationship improperly may face civil exposure to the correspondent. Getting the sequencing and the legal basis right is essential.
This case comment walks through an anonymised matter in which a European financial institution faced exactly this situation. It sets out the legal question, the SECO analysis, the cross-regime considerations that complicated the picture, the options reviewed, and the lesson for banks and compliance officers facing similar facts.
The Situation: A Correspondent Relationship Under Scrutiny
The European bank had maintained a USD correspondent-banking relationship with a regional bank – call it Bank X – for several years. Bank X operated in a jurisdiction whose financial sector had come under increased SECO and UN Security Council scrutiny. A periodic review of Bank X's customer base, obtained through the European bank's enhanced due-diligence process, showed that two corporate clients of Bank X had ultimate beneficial owners whose names closely matched entries on the UN Consolidated List (the master list of persons and entities subject to UN Security Council asset-freeze and travel-ban measures) as implemented by SECO through the relevant Swiss ordinances.
The match was not exact. One name had a slightly different transliteration; the other shared a name with a listed individual but differed on date of birth. Bank X had conducted its own screening and concluded the matches were false positives. The European bank's automated tool had returned an amber alert on both. The compliance officer escalated. The correspondent-banking desk asked: escalate to what standard, and under which regime?
This is the situation in which we regularly advise. The question is not simply whether a name appears on a list. It is whether the bank can satisfy itself, to a standard the applicable regime requires, that the match is genuinely false – and, if it cannot, what its obligations then become.
The Governing Regime: SECO's Authority and the Swiss Legal Basis
SECO administers Swiss sanctions under the Embargo Act (Embargogesetz), the primary Swiss statutory basis that authorises the Federal Council to enact sanctions ordinances implementing UN Security Council resolutions and, where Switzerland acts autonomously, its own restrictive measures. The Federal Council implements specific sanctions programmes through individual ordinances, each containing asset-freeze, payment-prohibition, and import/export-restriction provisions as required.
For financial institutions, the central prohibition is straightforward: assets of designated persons and entities must be frozen, and no funds or economic resources may be made available to them, directly or indirectly. The indirect limb is what matters here. A payment processed by a European bank through a correspondent that then benefits a designated person – even if the European bank never holds the designated person's account – can constitute making funds "available indirectly" under the applicable Swiss ordinance.
SECO does not maintain an open-licensing regime in the way OFAC does in the United States. Relief from specific prohibitions is possible under the ordinances, but the route is narrower and the timelines are not fixed by public guidance in the same way as, for example, OFAC's specific-licence processing. In our cross-border practice, clients who are familiar with OFAC's licensing infrastructure sometimes underestimate how different the Swiss position is – and they are surprised to find that there is no close analogue to an OFAC general licence that might bridge a gap while a question is resolved.
Related practices
- Correspondent-banking de-risking under OFAC – OFAC-specific analysis, licensing routes, and enforcement defence for financial institutions.
- Divesting a sanctioned interest – Australian regime matter – how a divestment under Australia's autonomous sanctions regime was structured and completed.
The position above covers the standard case. Your facts – the counterparty, the payment flows, the beneficial-ownership chain, and the regimes in play – will change the analysis materially. To discuss your correspondent-banking exposure under SECO or another regime, contact Calder & Vance at info@caldervance.com.
The Legal Question: False Positive or Genuine Match?
The core legal question in any correspondent-banking de-risking matter is whether the screening alert represents a genuine designation or a false positive, and whether the bank can demonstrate its conclusion to the standard the relevant regime requires. This is an evidential and procedural question, not merely a compliance-operations one.
Under the Swiss regime, as under the EU and UK regimes, the obligation to freeze assets and prohibit payments is triggered by designation – not by suspicion of a match. A bank that freezes funds on the basis of an unresolved amber alert that turns out to be a false positive may face claims from the account-holder. A bank that processes transactions without resolving the alert, and the match later proves genuine, faces enforcement exposure.
In this matter, the analysis involved three distinct steps. First, the available identifying information was compared against the list entries in detail: full name variants, transliterations, dates of birth, nationalities, known addresses, and business-registration details. SECO's published list entries vary in the quality of identifying information they carry, reflecting the underlying UN Consolidated List data. Second, Bank X was requested to provide its own enhanced due-diligence materials on the two corporates, including corporate registry documents and beneficial-ownership declarations. Third, the question was assessed through a cross-regime lens: did the same names appear on the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or the EU consolidated list, which would independently resolve the question?
The cross-regime check proved determinative. One of the two names did not appear on the SDN List or the EU list. The identifying data provided by Bank X, when set alongside the SECO list entry, showed sufficient divergence in date of birth and nationality to support a documented false-positive conclusion. The second name appeared on the EU consolidated list with consistent identifying information, and the corporate's registry documents showed a shareholding structure that brought the EU ownership and control test (the EU test under which an entity owned or controlled by a listed person is itself treated as subject to the same obligations) into play.
What the OFAC and EU Regimes Added to the Analysis
Correspondent-banking de-risking matters almost never live within a single regime. The USD correspondent-banking relationship meant that transactions processed through Bank X passed through the US financial system. That gave OFAC jurisdiction over the payments, independent of the SECO analysis. A payment that is permissible under SECO's rules is not automatically permissible under OFAC's; the stricter prohibition governs in practice, even if the legal systems are formally independent.
For the second corporate – the one where the EU list entry was consistent – the EU Regulation applicable to the relevant programme applied directly to EU-incorporated entities in the group structure that was being used to process some of the payments. This created a parallel obligation. The bank could not simply resolve the question under Swiss law and move on; it had to assess whether EU entities in the payment chain were independently prohibited from acting.
The interaction between these three regimes – SECO, OFAC, and the EU – is exactly the kind of cross-border analysis that a purely domestic compliance function is not designed to handle. In our experience, compliance teams that are strong on their home regime frequently underestimate the reach of the other regimes operating in parallel. Does your correspondent-banking screening capture the full chain of entities that touch a payment, or only the direct counterparty?
The Options Reviewed and the Route Taken
Once the analysis was complete, the European bank faced a structured choice. For the first corporate, the documented false-positive conclusion allowed the correspondent relationship to continue for transactions involving that client, subject to enhanced monitoring and a documented rationale on file. The bank updated its internal alert-management record, obtained confirmation from Bank X of the beneficial-ownership information, and set a periodic review date.
For the second corporate, the position was different. The EU list entry was consistent, the ownership chain reached the threshold required by the applicable EU regulations, and there was no licensing basis under the EU programme that would permit the payments. The bank's options were:
- Continue the correspondent relationship while blocking transactions that involved the second corporate – in effect, ring-fencing the prohibited exposure within an otherwise viable relationship.
- Exit the correspondent relationship entirely, on the grounds that Bank X's inability to segregate or exclude the second corporate's transactions created an unmanageable risk of inadvertent processing.
- Seek legal advice on whether a general authorisation was available under the applicable EU programme for a specific category of transactions.
The first option was technically available but operationally fragile. It required Bank X to identify and segregate every transaction touching the second corporate in real time – a control that Bank X, as a smaller regional institution, could not reliably implement. The third option was explored but the category of transactions at issue did not fall within any standing authorisation. The bank ultimately chose to exit the correspondent relationship in its entirety, with a documented rationale referencing the EU regime obligation and the impossibility of reliable segregation.
The exit was structured with a defined notice period, a final date for processing transactions, and written communication to Bank X setting out, at a level of generality consistent with the bank's own legal obligations, that the decision was driven by compliance requirements. The communication was careful not to identify the specific listed person or corporate by name in the written record, on the advice of counsel, to manage the risk of pre-notification to the designated person. This is a point that often receives insufficient attention in de-risking decisions: the manner and content of the exit communication itself carries legal risk.
If a correspondent relationship has already been flagged, or a filing has been refused, an early legal review can preserve options that narrow with time. To discuss the specific facts of your situation, contact us at info@caldervance.com.
Risk Flags This Matter Illustrates
Several risk patterns in this matter recur across correspondent-banking de-risking files we handle. They are worth identifying precisely, because each represents a point at which a well-designed compliance process should intervene.
The first is the transliteration problem. SECO's list entries, like UN Consolidated List entries, reflect the transliteration choices made at the time of designation. These may differ from the transliterations that a bank's own customer data, or the corporate registry of the correspondent's jurisdiction, uses. A screening tool calibrated to require close orthographic matching will produce false negatives on genuine matches; one calibrated too broadly will produce operationally unmanageable false-positive volumes. The right calibration is not a technical question alone – it is a legal question about the standard of diligence the applicable regime requires.
The second is the aggregation of ownership. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, in the aggregate across all blocked-person holdings) and its EU and Swiss equivalents mean that a corporate can be caught even where no single listed person holds a majority. Screening for the direct customer is not sufficient; the ownership chain behind the customer must be traced.
The third is the cross-regime gap. A bank that resolves a SECO question without checking the OFAC SDN List and the EU consolidated list is operating with an incomplete picture. Correspondent-banking relationships almost always involve USD payment flows or EU-connected entities, which means at least two regimes are in play simultaneously.
The fourth – and the one that is easiest to overlook under time pressure – is the exit communication itself. De-risking decisions made on the basis of a sanctions match carry specific legal risks in how the exit is communicated, to whom, and in what detail. A communication that amounts to tipping off a designated person or their associates can create separate legal exposure.
The Lesson for Banks and Compliance Officers
The myth that correspondent-banking de-risking is a straightforward compliance decision – check the list, find a match, exit the relationship – understates the legal analysis required at each stage. In this matter, the wrong conclusion at the false-positive assessment stage could have led to either improper continued processing or an unjustified exit. Either outcome creates legal risk.
The lesson is also about sequencing. The false-positive assessment must come before the de-risking decision. The cross-regime check must come before the false-positive conclusion is finalised. The exit communication must be reviewed against the tipping-off risk before it is sent. These are sequential steps, not parallel options. Compressing the sequence to meet a business timeline is one of the most common causes of the compliance failures we see in these matters.
What does a defensible de-risking decision look like? It has a documented screening rationale that addresses each alert, identifies the evidence reviewed, and reaches a reasoned conclusion. It has a cross-regime check against the major lists in play. It has a legal-basis analysis for the exit decision, not merely a risk-appetite statement. And it has an exit communication reviewed against legal-privilege considerations and the tipping-off risk.
We regularly advise financial institutions on each of these steps – screening the counterparty and ownership chain, assessing the cross-regime exposure, and structuring the exit or the continued relationship on a sound legal basis.
For related analysis on how correspondent-banking de-risking operates under the OFAC regime, see our service page on correspondent-banking de-risking under OFAC. For a parallel matter involving the divestment of a sanctioned interest under the OFAC programme, see our case comment on that matter.