A Swiss trading house ships precision components to a buyer in a third market. The end-use documentation looks clean. Six months later, SECO opens a criminal investigation. The question of criminal exposure in export-control cases under SECO rules arrives faster than most compliance teams expect – and the statutory windows for response are short.
Criminal exposure in export-control cases under SECO arises when a person or company exports, brokers, or transits goods, technology, or software in breach of Switzerland's goods-control ordinances and associated sanctions measures, without the required authorisation. The governing instruments are Switzerland's export-control and embargo legislation, administered by the State Secretariat for Economic Affairs (SECO). Violations can attract criminal prosecution – not merely administrative penalties – and the exposure extends to natural persons as well as corporate entities.
This briefing sets out how SECO administers criminal exposure, the legal basis for prosecution, the key risk indicators practitioners see in cross-border mandates, and how Switzerland's regime compares with neighbouring regimes under OFAC, OFSI, and the EU Council.
Who administers export-control criminal enforcement in Switzerland?
SECO – the State Secretariat for Economic Affairs – is the primary Swiss authority responsible for export controls, economic sanctions, and the criminal enforcement of both. It sits within the Federal Department of Economic Affairs, Education and Research. SECO administers the ordinances that control the export of dual-use goods, military goods, and specific strategic items, as well as giving effect to UN Security Council measures and Switzerland's autonomous embargo measures.
In criminal matters, SECO does not prosecute independently. It refers cases to the Office of the Attorney General of Switzerland, which handles federal criminal proceedings for the most serious violations. For lesser infringements under the embargo and goods-control ordinances, the administrative criminal law track applies, and SECO itself may impose penalties through an administrative procedure. That dual track – administrative criminal law and general criminal law – is a distinctive feature of the Swiss system that practitioners must keep clearly in mind.
In our cross-border practice, we see clients underestimate SECO's investigative reach because Switzerland is not a member of the European Union. This is a costly assumption. Switzerland maintains its own autonomous sanctions and export-control ordinances, and SECO enforces them with a rigour comparable to – and in some procedural respects more expeditious than – the EU's member-state authorities. The cross-border implications are real: a Swiss-domiciled entity may face simultaneous scrutiny from SECO and from EU, UK, or US authorities if the same shipment or transaction touches multiple jurisdictions.
What is the legal basis for criminal liability?
Swiss export-control criminal liability rests on a cluster of ordinances and federal statutes, not a single consolidated instrument. The primary pillars are the goods-control ordinances (covering dual-use and military items), the embargo ordinances (implementing UN Chapter VII measures and Switzerland's autonomous regime), and the administrative criminal law act, which creates the procedural mechanism for penalties. Natural persons found to have wilfully or negligently violated these rules face criminal prosecution; legal entities face separate liability in defined circumstances.
A critical point: Swiss law does not confine criminal exposure to the exporter alone. The prohibition extends to brokering – arranging deals between two non-Swiss parties that involve controlled goods – and to transit of controlled items through Swiss territory. For a multinational with a Swiss holding company, a Swiss trading arm, or even a Swiss-registered intermediary in the deal structure, these provisions matter immediately.
Wilful violations attract the most serious criminal consequences. Negligent violations are also caught, though typically at a lower severity. The distinction between wilful and negligent conduct therefore shapes the likely outcome significantly. In our experience, demonstrating that a compliance programme was genuinely operational at the time of the alleged violation – and that any gap arose from inadvertence rather than deliberate choice – is a central element of any enforcement defence before SECO or the Attorney General.
Which goods and transactions carry the highest criminal risk?
Not every export from Switzerland requires authorisation, but the categories that do are precisely those most likely to generate criminal exposure when the authorisation is absent. The following categories carry the highest risk profile in SECO enforcement matters.
- Dual-use goods and technology: items with both civilian and potential military application that appear on the Swiss control lists. Exporters must assess classification before shipment, not after.
- Military goods: items designed or adapted for military use. The threshold for what constitutes a "military good" under Swiss law can reach items that would be classified differently in other regimes.
- Items subject to embargo ordinances: goods, funds, or services prohibited by Swiss embargo measures implementing UN Security Council resolutions or Switzerland's autonomous measures. The autonomous measures in some respects mirror EU Council regulations; in others they diverge.
- Brokering and transit: arranging deals or permitting transit through Swiss territory without the required authorisation, even where Switzerland is not the country of export origin.
- Technology transfers: intangible transfers of controlled technology – including by electronic means – are within scope. Email attachments, cloud-storage access, and remote technical support can each constitute a controlled transfer.
The question to ask at the outset of any Swiss-connected transaction: has the item been classified against the Swiss control lists, and has the end-use been independently verified? A screening step that relies solely on the buyer's representations, without independent verification of the end-use chain, is the most common gap we identify when reviewing cross-border compliance programmes.
How does SECO's criminal enforcement compare with OFAC, OFSI, and the EU?
Cross-border businesses operating across multiple regimes face a patchwork of enforcement approaches. Understanding where the regimes align – and where they diverge – is a precondition for building an effective multi-regime compliance programme.
Under OFAC, the primary civil enforcement track operates on a strict-liability basis for most violations: a person need not have known that their conduct was prohibited for civil liability to attach. Criminal prosecution requires wilful conduct and is managed by the US Department of Justice. The penalty bases for civil violations can reach very significant sums, and OFAC publishes enforcement actions and settlement amounts on its website, providing a degree of transparency about enforcement trends. The voluntary self-disclosure (VSD) mechanism – which entitles a disclosing party to a reduction in the base penalty – is a structured feature of the OFAC system and one that practitioners regularly use.
OFSI in the United Kingdom similarly operates a civil enforcement track for financial-sanctions breaches. OFSI can impose monetary penalties on a strict-liability basis for knowing or having reasonable cause to suspect a breach. Criminal prosecution under UK law requires a higher intent threshold. The UK Government has taken steps to increase the visibility of OFSI enforcement, and OFSI publishes details of certain enforcement actions. OFSI's approach to voluntary disclosure broadly parallels OFAC's in its penalty-mitigation logic, though the procedural details differ.
The EU's approach is fragmented across member states: the Council Regulation creates the primary obligation, but criminal enforcement is a matter of national law in each member state. This means that the criminal consequences of an EU sanctions or export-control breach depend on the national jurisdiction where the breach is prosecuted. Our EU sanctions practice regularly handles matters where a single transaction triggers investigation in more than one member state simultaneously.
Where does Switzerland sit in this comparison? SECO's enforcement is more centralised than the EU's member-state patchwork, but it operates within a system where the administrative criminal law track and the general criminal law track run in parallel. The VSD culture in Switzerland is less institutionally developed than in the OFAC system, though Swiss law does recognise mitigation for cooperation and early disclosure. Crucially, Switzerland is not bound by EU sanctions regulations: its autonomous measures and the UN-implementing ordinances are the governing instruments, not the Council Regulations. A transaction that is permissible under an EU general authorisation may still require a separate Swiss authorisation – and vice versa.
For a business operating between Switzerland and a jurisdiction where OFAC secondary-sanctions risk arises, the exposure is potentially layered. The same shipment may attract OFAC scrutiny for its connection to a blocked person or designated entity, SECO scrutiny for the absence of Swiss export authorisation, and EU scrutiny if EU-origin goods or technology are involved. In our cross-border practice, we advise clients to map each layer of exposure before a transaction closes, not after a query arrives from a regulator.
What are the key risk indicators and common compliance failures?
Criminal exposure in export-control cases under SECO rules rarely arises from a single catastrophic failure. In the great majority of enforcement cases we have reviewed, the pattern is a sequence of smaller compliance gaps that, taken together, constitute a systemic failure. Identifying those patterns early is where enforcement defence begins.
The following risk indicators appear repeatedly in SECO-connected matters.
- Incomplete item classification: relying on a supplier's description or a customs tariff code without cross-referencing the Swiss dual-use and military goods control lists. The Swiss lists are not identical to the EU's combined military list or the US Commerce Control List, and assumptions based on one regime can be wrong for another.
- End-use documentation gaps: accepting an end-user certificate at face value without assessing the plausibility of the stated end-use against the buyer's profile, location, and the nature of the goods. Red flags – an unusual buyer profile, a destination with elevated diversion risk, pricing inconsistencies – that were present in the file but not acted upon are difficult to explain in a criminal proceeding.
- Brokering without authorisation: a Swiss-based trading entity that arranges deals between parties in third countries without considering whether the goods involved are controlled under Swiss brokering rules. This is a structurally underweighted risk in many compliance programmes.
- Inadequate screening against embargo lists: SECO publishes the Swiss embargo list, which implements UN Security Council measures and Switzerland's autonomous measures. Screening only against OFAC's SDN List and the EU Consolidated List, without checking the Swiss list, creates a gap that SECO enforcement can exploit.
- Technology-transfer blindspots: failing to treat intangible transfers of controlled technology as export events. A Swiss engineer providing remote technical assistance to a buyer in a sensitive jurisdiction may be conducting a controlled technology export without the company ever filing for authorisation.
- Inadequate record-keeping: Swiss law imposes record-keeping obligations on licensed exporters. A business that cannot demonstrate what its compliance process looked like at the time of the alleged violation is in a materially weaker position in an enforcement proceeding.
One myth we encounter regularly is that criminal prosecution is reserved for the very largest or most egregious cases – that a "technical" breach will attract at most a modest administrative fine. This is a misreading of how SECO enforcement works. The administrative criminal law track can produce outcomes that affect individuals, not just companies. Directors and senior officers can face personal liability where they authorised or failed to prevent a violation within the company's operations. The personal dimension of Swiss export-control criminal liability deserves far more attention in corporate compliance programmes than it typically receives.
When should a business involve counsel – and what does that engagement look like?
The decision to involve external sanctions and export-control counsel should not wait for a formal notice from SECO or a referral to the Attorney General. By the time a formal investigation is open, options that were available at an earlier stage have often narrowed. There are three windows in which early engagement makes a material difference.
The first is the pre-transaction window. Before a Swiss-connected export, brokering arrangement, or technology transfer completes, a classification and authorisation review can identify whether an authorisation is required, what conditions attach to it, and whether the end-use documentation is sufficient. This is the least costly form of export-control counsel and the one most directly linked to avoiding criminal exposure.
The second is the internal discovery window. A business that identifies a potential violation during an internal audit or a transaction review has a choice: disclose voluntarily to SECO or manage the matter without disclosure. That choice has consequences for the likely enforcement outcome and for any parallel exposure under other regimes. Assessing the full landscape of potential disclosure – to SECO, to OFAC, to OFSI, to EU-member-state authorities – requires coordinated advice across the relevant regimes. We regularly advise on exactly this coordination question.
The third window is the formal investigation window. Once SECO has commenced an administrative criminal proceeding, or the Attorney General has opened a criminal inquiry, the engagement must address the procedural rights of the investigated party, the evidence already gathered, the cooperation strategy, and the available mitigation arguments. In our experience, the quality of the compliance evidence available at this stage – documented policies, training records, internal screening logs – determines in large part the range of outcomes that remain achievable.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss a potential SECO matter in confidence, contact Calder & Vance at info@caldervance.com.
How does criminal exposure differ across the major regimes? A practitioner's comparison
For a compliance officer managing exposure across Switzerland, the EU, the UK, and the United States simultaneously, the divergences between regimes are the principal source of operational risk. The following outline identifies the key structural differences.
Intent threshold. OFAC civil enforcement is strict-liability; SECO's administrative criminal law track similarly captures negligent violations; the EU varies by member state but many national laws require some degree of knowledge. For criminal prosecution in all regimes, wilful conduct is the core element – but the definition of wilfulness diverges. In the US, "wilful blindness" – deliberate ignorance of a known risk – is treated as equivalent to knowledge. Swiss criminal doctrine handles wilful blindness somewhat differently, and practitioners must not assume that the US analysis maps cleanly onto Swiss proceedings.
Disclosure incentive. OFAC operates an explicit VSD programme with a defined penalty-reduction structure. OFSI has introduced disclosure as a mitigating factor in its enforcement guidance. SECO's framework provides for mitigation on cooperation grounds, but without the same formalised structure. Understanding what a Swiss disclosure achieves – and what it does not – before making any disclosure decision is essential.
Corporate versus individual liability. In all three regimes, natural persons can face criminal prosecution for export-control violations. The Swiss track is notable for the directness with which it can reach directors and senior managers where a corporate violation is traceable to their decisions or omissions. The EU regime's criminal reach is mediated through national law and varies considerably. OFAC can pursue individuals through civil enforcement actions and, jointly with DOJ, through criminal prosecution.
Extraterritorial reach. OFAC's secondary-sanctions programmes extend to non-US persons in defined circumstances. SECO's regime is territorially anchored: it applies to Swiss-domiciled persons, Swiss-registered entities, and transactions touching Swiss territory. However, SECO's reach can still affect foreign-owned Swiss subsidiaries and Swiss-domiciled intermediaries in a multinational group. The principle that the stricter prohibition governs applies when multiple regimes are in play: a transaction authorised by one regime cannot proceed if it is prohibited by another.
Transparency and published enforcement. OFAC publishes enforcement actions and settlement details with considerable regularity. OFSI has moved toward greater transparency in its enforcement publications. SECO publishes information about significant enforcement outcomes, but its enforcement record is less publicly detailed than OFAC's. That lower public visibility should not be mistaken for lower enforcement activity.
Related practices that address adjacent aspects of this exposure:
Related practices
- Apparent violation assessment – EU – structured review of potential EU sanctions breaches and disclosure options
- Criminal export exposure under Singapore's regime – comparative briefing on criminal enforcement in Singapore
- Mitigation factors in BIS/EAR enforcement – how BIS assesses violations and applies mitigation under the EAR