A Swiss-based trading intermediary — sourcing goods from Asia and distributing them into markets across Europe and the Middle East — conducts what it considers a thorough compliance review before signing a significant supply agreement. Its in-house team runs the principal counterparty through a major commercial screening database. The result is clean. The deal proceeds. Months later, SECO correspondence arrives. A connected entity within the counterparty's ownership chain is linked to a designation. The transaction is frozen. The intermediary's management team is now asking a question they should have asked earlier: what exactly does counterparty due diligence under SECO require?
This counterparty due diligence SECO case illustrates a failure that recurs across mid-market cross-border businesses: relying on surface-level screening when the applicable Swiss sanctions regime demands a full ownership-and-control analysis. Under SECO's autonomous sanctions ordinances and the incorporated UN Consolidated List obligations, assets connected to listed persons must be frozen regardless of whether the immediate contractual counterparty itself appears on a list. The answer to the question above is not in the database result; it is in the ownership chain behind it.
This case comment traces the situation from first identification of the problem through the legal analysis, the options the business faced, the route taken, and the lessons that apply to any business with Swiss-linked supply chains or counterparties.
The situation: what the business thought it had done
The trading intermediary had a written screening policy. It required a check of the principal counterparty's name against the SECO sanctions list and two major commercial sanctions databases before any contract was signed. In practice, that check was run against the legal name of the contracting entity. The database returned no match. The compliance sign-off was documented.
What the policy did not require — and what no one had thought to build into the process — was any inquiry into the ownership structure of the counterparty. The contracting entity was a clean-name trading company. Its majority shareholder was a holding vehicle incorporated in a third jurisdiction. That holding vehicle was itself partially owned by an entity whose ultimate beneficial owner appeared on the SECO list. The chain was three layers deep. The commercial database the intermediary was using flagged direct name matches and known aliases. It did not map beneficial ownership structures.
The goods supplied were not controlled items. The transaction was otherwise lawful. But the payment obligations under the supply agreement created a financial relationship that, on proper analysis, involved assets benefiting a person connected to a listed individual. SECO's asset-freeze provisions, incorporating both autonomous Swiss measures and the relevant UN Security Council resolutions, operate on a substance-over-form basis. The question is not whether the contract counterparty is listed. The question is whether completing the transaction would make assets available to a listed person, directly or indirectly.
In our experience, this gap between what a business believes its screening covers and what the applicable regime actually requires is one of the most common sources of sanctions exposure in mid-market trade. The policy existed. The database was reputable. The sign-off was genuine. None of that mattered once the analysis turned to ownership.
The legal question: what does SECO require on ownership and control?
SECO administers Switzerland's autonomous sanctions regime, which runs in parallel with the incorporated UN Consolidated List obligations. Switzerland is not a member of the European Union, and its sanctions regime is self-standing. SECO's ordinances prohibit the making available of funds and economic resources to listed persons and to entities owned or controlled by them.
The ownership-and-control analysis under Swiss law follows a logic similar to, but formally distinct from, both OFAC's mechanical test and the EU and UK approaches. Under OFAC, the test for whether a non-listed entity is treated as blocked is the 50 percent rule (the rule that treats entities owned 50 percent or more in aggregate by blocked persons as themselves blocked). The threshold is arithmetic. Under OFSI and EU practice, a control test applies alongside an ownership threshold — so a listed person who holds less than a majority stake may still be treated as controlling an entity through contractual rights, board influence, or operational authority.
SECO's approach under its autonomous ordinances is broadly comparable to the EU position: both ownership and effective control are relevant, and neither concept is satisfied by the surface-level structure of the counterparty alone. In our cross-border practice, we regularly advise clients that the prudent standard — the one that reduces risk across all three major Western regimes simultaneously — is to treat any entity where a listed person owns a significant stake or exercises effective control as presenting a high-risk counterparty profile requiring enhanced review, irrespective of whether the precise arithmetic threshold applies in the specific jurisdiction governing the transaction.
For this intermediary, the ownership chain analysis revealed that a listed person's economic interest, though not a formal majority, flowed through the structure in a way that made the holding vehicle a vehicle through which that person's assets were held. The relevant test under the applicable Swiss ordinances was met. The intermediary had, without knowing it, made assets available through a chain that a competent counterparty due diligence process should have identified.
What had gone wrong, and at which stage?
Three distinct failures combined to produce the exposure. The first was structural: the screening policy was designed around name matching, not ownership mapping. Name-matching is a necessary condition of compliant screening; it is not a sufficient condition. A beneficial ownership review (an inquiry into who ultimately owns and controls the counterparty, beyond the legal entity's own registered name) was absent from the process entirely.
The second failure was a misunderstanding of what commercial screening databases actually do. Major databases are excellent at flagging sanctioned-name matches, known aliases, and adverse-media indicators for the entity queried. They are not structured to traverse multi-layer ownership chains and produce a beneficial-owner sanctions match unless that function is explicitly enabled and the user has provided the structured ownership data needed to run it. The intermediary's compliance team did not know this. They believed — reasonably but incorrectly — that a clean database result meant a clean counterparty.
The third failure was the absence of proportionate escalation. For a supply agreement of the value this represented, the intermediary's own risk framework classified the transaction as medium-high value. That classification should have triggered enhanced due diligence. In practice, the enhanced step was understood to mean a second database check, not a substantive ownership review.
By the time SECO made contact, options had narrowed. The transaction had been partly performed. Goods had moved. Payments had been made. The remediation path was more complicated — and more expensive — than a proper pre-transaction review would have been.
How the matter was worked through
The intermediary engaged Calder & Vance at the point when SECO's initial correspondence arrived. The immediate priority was to scope the exposure accurately. We conducted a structured ownership-chain analysis of the counterparty, tracing the beneficial ownership layers through publicly available corporate registries, filings in the counterparty's jurisdiction, and available commercial data. This exercise confirmed the connection the SECO inquiry had flagged and also identified a second-tier entity in the structure that presented a lower but material degree of risk.
The next step was to assess the specific obligations triggered under the applicable Swiss ordinances. Assets connected to the transaction were identified and their status confirmed. The intermediary needed to understand, as a factual matter, which payments and which goods deliveries were potentially tainted and to what degree. This structured the remediation choices.
We then advised on the reporting obligations that applied. SECO's reporting and co-operation requirements are set out in its ordinances and in guidance material it has published. There is a general obligation to report to SECO where a business identifies that assets connected to a listed person are held or have passed through a transaction. Timing and form matter: a prompt, structured, voluntary report to SECO — setting out what was identified, how it was identified, and what steps the business was taking — is assessed differently from a report that arrives only after the regulator has made its own inquiries. In our experience, voluntary and timely engagement with SECO on a potential exposure produces a materially different response than a reactive one.
We prepared a structured written submission to SECO. It set out the ownership analysis, the chronology of the transaction, the steps the intermediary had taken since identification of the issue, and the remediation measures the business was implementing. The submission was careful, factual, and did not overclaim. It acknowledged where the pre-transaction process had been inadequate and presented the steps the business was taking to address this. The matter was ultimately resolved without formal enforcement proceedings against the intermediary. No guarantee of that outcome existed at the outset, and the course of similar matters may differ depending on the specific facts. What the voluntary engagement did was preserve the intermediary's credibility with SECO as a good-faith actor.
If you are in a similar position — having identified a potential exposure under the Swiss or another regime — early engagement with specialist counsel is the action that keeps the most options open. Write to us at info@caldervance.com for an initial confidential review.
Cross-border dimensions: SECO does not operate in isolation
One aspect of this matter that expanded its complexity was the multi-regime exposure. The transaction was governed by Swiss law and conducted through a Swiss intermediary. But the goods had been procured from an Asian supplier using a payment mechanism routed through a bank with US correspondent relationships. The UN Security Council designation at the end of the ownership chain was one that the United States had also implemented through OFAC.
This meant that the US correspondent bank had independent obligations under OFAC. A transaction that violated OFAC's prohibitions — because it involved property in which a blocked person had an interest, routed through a US correspondent — exposed the bank as well as the Swiss intermediary to a separate enforcement risk. The bank had not caused the problem. But the routing decision, taken without awareness of the ownership issue, created a secondary exposure that had to be managed alongside the SECO matter.
For businesses operating between Switzerland and jurisdictions with active US-dollar payment flows, this extraterritorial dimension is not theoretical. OFAC's jurisdiction over transactions cleared in US dollars through US correspondent banking is well-established. The UN Consolidated List, which SECO incorporates, is the same list that underpins OFAC's designations in many thematic programmes. A problem under one regime is frequently a problem under multiple regimes simultaneously.
The EU dimension added a further layer. The intermediary had EU-based distribution partners. Their purchase obligations under the supply agreement meant that goods passing to them from a tainted supply chain could implicate EU Council regulation prohibitions applicable to EU-established entities. Those partners had to be notified of the issue. Managing that notification — what to say, in what form, and when — required care to avoid creating additional legal exposures while also meeting any applicable reporting duties the EU-based parties had under their own regimes.
In our cross-border practice, we have acted for businesses managing exactly this kind of multi-regime pile-up: a single counterparty problem that generates simultaneous exposure under SECO, OFAC, and EU rules. The regimes are not co-ordinated in their responses. Each authority has its own timeline, its own reporting expectations, and its own enforcement posture. Managing all three coherently — with consistent factual positions and appropriate sequencing of disclosures — is one of the most technically demanding aspects of a matter like this.
Risk flags for businesses with Swiss-linked counterparties
Several risk flags in this matter are generalisable to any business that transacts through Switzerland or with Swiss-linked counterparties.
The first is jurisdictional complexity in the ownership chain. An intermediate holding company incorporated in a low-transparency jurisdiction — where registry data is minimal and beneficial ownership disclosure obligations are weak — is a structural feature that demands heightened scrutiny. It is not itself a reason to decline the transaction. It is a reason to conduct more work before committing to it.
The second is the nature of the goods or services involved in relation to the counterparty's sector. Where the counterparty operates in a sector that has attracted heightened sanctions attention — energy, metals, financial intermediation, certain technology categories — the ownership review should be more thorough, not less, even if the specific goods being supplied are not themselves controlled.
The third is the payment route. Transactions settled in US dollars through US correspondent banking carry OFAC exposure as well as the exposure under the directly applicable domestic regime. Payment route analysis — understanding which currencies, which correspondent banks, and which clearing mechanisms are involved — is a standard element of diligence on higher-value or higher-risk transactions.
The fourth is the prevalence of nominee arrangements. In certain ownership structures, the recorded shareholder is a nominee acting for an undisclosed beneficial owner. Where nominee arrangements are known to be common in the counterparty's incorporation jurisdiction, enhanced beneficial ownership verification — going beyond registry data to seek contractual confirmation and ultimate beneficial owner declarations — is appropriate.
The fifth, and perhaps the most frequently underestimated, is the gap between a written policy and actual practice. This intermediary had a policy. The policy did not reflect the regime's actual requirements. Periodic testing of whether the policy, as actually implemented, delivers the result it is designed to produce is a competency that many mid-market businesses have not built. A compliance audit (a structured review of whether a firm's sanctions controls work as intended, not merely as written) is the mechanism for closing that gap before regulators do it for you.
Is your current due diligence process actually reaching the ownership layer that matters? If you are uncertain, a structured review of your counterparty screening procedures is the place to start.
Related practices
- Compliance audit and testing – structured review of whether sanctions controls work as intended in practice
- Crypto and VASP sanctions compliance – how virtual-asset businesses manage cross-border screening obligations
- VASP compliance: Japan matter – sanctions and AML control design for virtual-asset service providers
The myth that a clean database result means a clean counterparty
The most persistent misconception we encounter in advising compliance teams on counterparty due diligence is this: a clean result from a reputable commercial screening database is equivalent to a clean counterparty. It is not. A database result answers a specific and narrow question — does the queried legal entity's name, or a known alias of it, match a name on the list being screened? That is a valuable input. It is not a compliance conclusion.
The regime's question is different. It asks whether completing the transaction will make assets available to a listed person, directly or indirectly, taking into account the ownership and control relationships that exist behind the contractual counterparty. Those two questions have different answers far more often than compliance teams assume.
We regularly advise clients who have operated under the assumption that their database subscription was doing all the work that a proper counterparty due diligence regime requires. In most cases, the database is doing part of the work. The ownership-chain analysis, the beneficial owner verification, the payment-route review, and the proportionate escalation for higher-risk profiles are the parts that a database alone does not and cannot do. The intermediary in this matter had a reputable database and a written policy. Neither substituted for the analysis the regime required.
The correction is not to abandon commercial screening tools — they remain an essential first step. It is to design the counterparty due diligence process so that the database check is the start, not the end, of the analysis.