Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · SECO

Internal sanctions investigations under SECO: the essentials

A Swiss-based trading company discovers, mid-quarter, that a payment has passed through a bank account linked to a counterparty whose ultimate beneficial owner appears on a SECO list. The transaction was booked. The funds moved. What does the business do next – and who in Switzerland is watching?

Internal sanctions investigations under SECO rules are triggered when a business identifies a potential breach of Switzerland's autonomous sanctions ordinances or the UN-derived measures that SECO administers. The State Secretariat for Economic Affairs (SECO) – Switzerland's sanctions authority – holds both administrative and criminal-referral powers. A well-structured internal investigation is the first and most consequential step a business can take to protect its position.

This briefing sets out the governing regime, the authority's enforcement posture, how an internal investigation should be structured, where Switzerland's approach diverges from the EU, UK, and US positions, and when external counsel must be involved.

Who administers SECO sanctions and what is the legal basis?

SECO administers Switzerland's sanctions regime under the federal Embargo Act (the governing statute for both UN-derived and autonomous Swiss measures), acting as the competent authority for implementing measures against designated persons, entities, and goods. The Act empowers the Swiss Federal Council to issue ordinances giving effect to UN Security Council resolutions and to autonomous Swiss measures aligned with those of the EU and other partners. SECO sits within the Federal Department of Economic Affairs, Education and Research and operates the relevant sanctions lists, licensing mechanisms, and enforcement functions.

The criminal dimension is significant. Where SECO identifies evidence of intentional breach, the matter may be referred to the Federal Department of Economic Affairs or, in serious cases, to the Office of the Attorney General of Switzerland. A business conducting an internal investigation in Switzerland is therefore managing a risk that sits simultaneously in administrative, civil, and criminal law. That layering is not always appreciated by compliance teams used to purely administrative-penalty regimes elsewhere.

As of April 2026, Switzerland maintains autonomous ordinances covering a range of designated jurisdictions and individuals, as well as measures that mirror Security Council Consolidated List entries. The scope of those ordinances has expanded materially in recent years, and businesses that last reviewed their Swiss exposure more than twelve months ago should treat that review as overdue.

What triggers the obligation to investigate internally?

A potential SECO breach becomes an internal-investigation trigger when a business has a credible basis to believe that a transaction, relationship, or asset may involve a SECO-listed person or a prohibited good, service, or fund movement. That credible basis can arise from a screening hit, a transaction-monitoring alert, a whistleblower report, or a query from a Swiss financial intermediary.

Swiss financial intermediaries operate under separate anti-money-laundering obligations enforced by FINMA, but those obligations intersect with SECO's sanctions rules at exactly the point where an unusual payment or counterparty is flagged. A FINMA-driven query to a bank can, in practice, surface a sanctions question that the corporate customer has not yet identified. In our experience, businesses first learn of a potential SECO issue through their banking relationship rather than through their own screening. That is a process gap, not a regulatory defence.

The internal-investigation obligation is not codified as a formal statutory duty in the same way that, for example, the UK's OFSI reporting obligation is. However, the practical imperative is equally strong: a business that receives a SECO enquiry without having conducted a prior internal review is in a materially weaker position than one that can present a documented, chronological account of its own fact-finding.

What types of transaction patterns should raise an investigation flag? The most common in our cross-border practice are: payments transiting Swiss correspondent accounts where an intermediate institution appears on a list; re-export of goods through Switzerland to a prohibited destination; and services provided by a Swiss entity to a non-Swiss affiliate operating in a restricted market. Each of these has a distinct factual and legal profile that shapes the scope of the internal investigation.

How should a SECO-facing internal investigation be structured?

A well-run internal investigation under SECO rules follows a defined sequence: scope definition, document preservation, fact reconstruction, ownership and control mapping, and a written findings memorandum. Each stage has practical consequences for how SECO – or a criminal referral body – will evaluate the business's cooperation and good faith.

Scope definition is the first decision. An investigation that is scoped too narrowly – examining only the transaction that triggered the alert – risks missing the wider pattern that SECO will eventually see. An investigation scoped too broadly creates disclosure and privilege risks, particularly where documents are shared across jurisdictions. In our experience, the right scope covers: the specific transaction or relationship; all transactions with the same counterparty in the relevant period; and any related counterparties disclosed by the ownership-and-control analysis.

Document preservation must be immediate. Swiss law does not codify a litigation-hold doctrine in the same terms as US practice, but evidence destruction or alteration carries serious criminal risk. Communications with the flagged counterparty, payment instructions, compliance sign-off records, and screening-tool outputs should all be preserved at the moment the investigation is opened.

Fact reconstruction involves building a chronological account of the transaction lifecycle – from origination and onboarding through approval, execution, and settlement. Gaps in that timeline are material. SECO's enforcement posture treats unexplained gaps in a transaction record as an indicator of deliberate concealment, which is a far more serious finding than an administrative breach.

The ownership and control mapping is often the most demanding element. Switzerland applies an ownership and control test to determine whether a non-listed entity is caught through a listed person's influence. The test looks at direct and indirect shareholding, contractual control, board representation, and economic benefit. Unlike OFAC's 50 percent or more aggregation rule – which is mechanical – the Swiss and EU tests can catch a counterparty where control is exercised through means other than majority ownership. That difference is consequential in complex corporate structures where no single listed person holds a majority but the combined influence is decisive.

The written findings memorandum is the output that matters most. It should set out the facts established, the legal analysis under the relevant ordinance, the conclusion on whether a breach occurred, the remediation steps taken, and any recommended disclosure. A memorandum that is incomplete, internally inconsistent, or silent on obvious questions does more damage than an early, frank disclosure.

The position above covers the standard case. Your facts – the counterparty structure, the goods or services involved, the route of the funds, the precise ordinance in play – change the analysis materially. For an assessment of your exposure under SECO, contact Calder & Vance at info@caldervance.com.

How does SECO's enforcement posture compare with the EU, UK, and US?

SECO's enforcement approach is administratively quieter than OFAC's and more reliant on criminal referral than OFSI's, but it would be an error to treat it as the most lenient of the major regimes. The comparison is instructive precisely because businesses operating across Switzerland, the EU, the UK, and the US face divergent but overlapping obligations when a potential breach arises.

Under OFAC, the voluntary self-disclosure (VSD) mechanism – a formal process of disclosing an apparent violation to OFAC before the agency identifies it independently – can reduce a civil monetary penalty by a significant factor. OFAC publishes detailed guidance on the factors it weighs in penalty computation, and the framework is relatively transparent. The penalty bases are public record, and the enforcement file follows a documented process.

OFSI in the UK operates a monetary-penalty regime under the Sanctions and Anti-Money Laundering Act. OFSI's enforcement guidance addresses the weight given to self-disclosure, cooperation, and the quality of a business's compliance programme at the time of the breach. Critically, OFSI can impose a civil penalty without a criminal conviction, and the monetary-penalty power is exercisable in a shorter timeframe than criminal prosecution. For businesses with UK nexus, the OFSI position therefore creates a parallel track to any SECO process.

The EU regime – enforced by national competent authorities under the relevant Council Regulations – adds a third layer for businesses with EU operations or EU-incorporated affiliates. The EU General Court provides an annulment route for designation challenges, but enforcement of transaction-level breaches is handled at member-state level with significant variation in penalty severity and procedural approach between, for example, a German, French, or Dutch authority.

SECO's distinctiveness is the criminal dimension. Where OFSI and most EU member-state authorities proceed on an administrative-penalty basis for transaction-level breaches, SECO has a lower threshold for criminal referral, and the federal criminal procedure can move with considerable speed once a referral is made. A business that self-discloses promptly and cooperates fully with SECO's fact-finding is in a structurally different position from one that discloses only after receiving an enquiry letter. That asymmetry mirrors the OFAC VSD principle but is not formalised in the same way: SECO's published guidance on voluntary disclosure is less granular than OFAC's, which means the evidential quality of the internal investigation itself becomes the primary signal of good faith.

For businesses whose operations touch Switzerland, the EU, and the UK simultaneously – a common profile for commodity traders, financial intermediaries, and precision manufacturers – a breach that triggers SECO may also trigger OFSI reporting obligations and EU member-state notification requirements. Coordinating the sequencing of those disclosures is one of the most tactically significant decisions in a multi-regime investigation. If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.

What are the principal risk flags in a SECO internal investigation?

The risk flags that most frequently complicate a SECO internal investigation fall into three categories: ownership-chain opacity, transaction-record gaps, and multi-jurisdiction disclosure conflicts. Each requires a different response.

Ownership-chain opacity arises when the counterparty's beneficial ownership cannot be verified through publicly available records. Swiss company law requires disclosure of beneficial owners to a small degree, but that disclosure is not always current or complete. Where the counterparty is incorporated in a jurisdiction with limited public-registry requirements, the business's screening tool may have returned a clean result on the legal entity while missing the sanctioned individual who holds economic benefit through a trust or nominee structure. In our cross-border practice, this is the most common reason an initial "clean" screen is later found to be incomplete.

Transaction-record gaps are both a factual risk and a credibility risk. SECO – like OFAC and OFSI – weighs the quality of a firm's record-keeping when assessing the seriousness of a breach. A firm that cannot produce a complete payment trail, a signed counterparty-verification record, or the compliance sign-off that preceded the transaction faces a harder conversation with the regulator than one that can demonstrate a documented process that failed despite reasonable controls. Record-keeping obligations under the applicable Swiss financial-services and corporate rules require retention over a significant period; a business should ensure its investigation team retrieves records from all relevant systems, not just the primary accounting ledger.

Multi-jurisdiction disclosure conflicts arise when the facts that must be disclosed to SECO would, if disclosed simultaneously to another regulator, create a risk of inconsistency, waiver of legal professional privilege, or prejudice to a parallel proceeding. The sequencing of disclosures across SECO, OFSI, and an EU national competent authority is a legal question, not a process question. Getting the sequence wrong can convert a manageable administrative matter into a criminal-referral risk in one of the regimes.

A further risk flag – one that is sometimes underestimated – is the conduct of the investigation team itself. Interviews of employees that are poorly structured or inadequately warned can produce statements that later create problems in criminal proceedings. Preservation of legal professional privilege over the investigation memorandum requires careful structuring of the mandate and the document-flow from the outset. These are areas where experienced external counsel add material value early, before the investigation has generated a paper trail that cannot be undone.

What is the common misconception about SECO's reach?

A persistent misconception among businesses without prior Swiss-sanctions exposure is that Switzerland's neutral political tradition translates into a light sanctions touch. It does not. Switzerland has implemented the full range of UN Security Council mandatory measures and, since 2022, has adopted autonomous measures covering the same scope as the EU's principal country ordinances. SECO is an active regulator with investigative powers, the ability to freeze assets, and a referral relationship with the federal criminal prosecution authorities.

A second, related misconception is that a Swiss-incorporated entity is insulated from EU, UK, or US consequences if the breach occurs entirely within Switzerland. That is rarely true. Where funds transit a correspondent bank with a US nexus, OFAC's long-arm jurisdiction may apply. Where an EU-incorporated affiliate was involved in the transaction chain, the relevant EU member state's competent authority has jurisdiction over that affiliate's conduct. The extraterritorial reach of US secondary sanctions adds a further dimension: a Swiss business that facilitates a transaction involving a person subject to secondary-sanctions designations may face US consequences independently of any SECO proceeding.

In our practice, the businesses most at risk are those that have compartmentalised their Swiss compliance function from their global programme. SECO exposure does not sit in a silo. It intersects with OFAC, OFSI, and the EU regime at every point where a cross-border payment, a re-export, or a service contract touches more than one jurisdiction.

Related practices

When does a SECO investigation require external counsel?

External counsel should be instructed at the earliest possible stage – ideally before the investigation team has conducted any employee interviews or made any internal findings. There are four situations that make early instruction not merely advisable but operationally necessary.

First, where the facts suggest an intentional breach rather than a process failure. SECO's criminal-referral threshold is lower than many businesses expect. If the initial fact pattern suggests that a business-unit employee or a manager had actual knowledge of the designated status of the counterparty, the risk profile shifts from administrative to criminal immediately. At that point the investigation must be structured with criminal-defence considerations in mind, not merely compliance-remediation ones.

Second, where the potential breach touches more than one jurisdiction. The sequencing and content of disclosures to SECO, OFSI, and an EU national competent authority cannot be managed as three parallel but independent processes. A statement made in one disclosure can undermine privilege or create inconsistency in another. Counsel with cross-regime experience can design a disclosure strategy that protects the business's position across all three.

Third, where SECO has already made direct contact – whether by way of an enquiry letter, a freeze order, or an oral enquiry to a financial intermediary. At that stage the regulatory clock is running. Response timelines, even where not formally prescribed, are tracked by the authority, and a delay in substantive engagement is itself a negative signal.

Fourth, where the business is in a sector with heightened SECO scrutiny: financial intermediation, commodity trading, precision engineering, pharmaceuticals, and logistics. SECO's enforcement resources are not unlimited, and the authority focuses those resources on sectors and transaction types that present the greatest systemic risk. A business in one of those sectors should assume a higher probability of proactive engagement from SECO if a disclosure is made or an investigation is visible.

In a recent matter, a European commodity-trading firm identified, through its annual sanctions audit, a series of payments that had passed through a chain including an entity linked to a SECO-listed person. The firm had no prior SECO engagement and had not self-disclosed. We were instructed to scope the investigation, prepare a findings memorandum, and advise on the disclosure sequence across SECO and the relevant EU authority. The matter was resolved through structured voluntary disclosure with full cooperation, and the firm implemented a revised counterparty-verification protocol covering the Swiss ordinances specifically.


Frequently asked questions

Who administers internal sanctions investigations under SECO?
SECO – the State Secretariat for Economic Affairs – is Switzerland's competent authority for administering and enforcing the federal sanctions regime, including the oversight of potential breaches by businesses. SECO holds investigative and asset-freezing powers and may refer evidence of intentional breach to the federal criminal prosecution authorities. Swiss financial intermediaries subject to FINMA oversight operate parallel compliance obligations that intersect with SECO's sanctions rules and may independently surface matters requiring an internal investigation.
What does SECO prohibit in relation to internal sanctions investigations?
Switzerland's sanctions ordinances prohibit making funds, assets, or economic resources available to designated persons and entities, as well as providing prohibited services or facilitating transactions involving restricted goods. There is no statutory prohibition on internal investigations themselves; rather, the obligations SECO enforces concern the underlying conduct that an investigation is designed to identify and remediate. A business that discovers a potential breach and fails to investigate it – or that structures its investigation to obscure findings – faces materially greater regulatory and criminal risk than one that investigates promptly and transparently.
How is internal sanctions investigations enforced under SECO?
SECO enforces Swiss sanctions through administrative powers – including asset-freezing orders and investigative enquiries – and through referral to criminal-prosecution authorities where intentional breach is evident. Unlike OFAC, SECO does not publish a standardised voluntary-self-disclosure formula, but the quality of a business's internal investigation and the promptness of its cooperation are central to how any enforcement proceeding develops. Businesses that self-disclose with a complete, well-documented internal investigation record are in a structurally stronger position than those that engage only after a regulatory enquiry has been opened.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.