Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · SECO

Enforcement risk after a breach under SECO: scope and obligations

A Swiss-based trading house completes a series of commodity transactions, then discovers that one counterparty may have been subject to a Swiss sanctions ordinance at the time of payment. The goods have moved. The funds have settled. What happens next – and who decides?

Enforcement risk after a breach under SECO rules sits with the State Secretariat for Economic Affairs, which administers Switzerland's sanctions regime under the Embargo Act (the primary federal instrument authorising economic sanctions ordinances). SECO holds investigative and referral powers; criminal prosecution passes to the federal authorities where the threshold is met. As of April 2026, Switzerland's ordinances mirror a significant portion of EU designations, which means that a breach of the Swiss regime will frequently also engage EU, UK, or US obligations for the same business.

This briefing covers who holds authority, what obligations arise after a potential breach is identified, how the enforcement procedure works, how Swiss enforcement compares with OFAC and OFSI, and when to involve specialist counsel.

Who administers Switzerland's sanctions regime and holds enforcement authority?

SECO – the State Secretariat for Economic Affairs, operating within the Federal Department of Economic Affairs, Education and Research – is the competent authority for administering and enforcing Switzerland's embargo and sanctions ordinances. SECO maintains the Swiss Sanctions List, issues licences for exceptional transactions, and acts as the principal regulator for civil and administrative enforcement of the Embargo Act.

SECO's enforcement powers are not unlimited. Where conduct meets the threshold for criminal liability under the Embargo Act, SECO refers the matter to the Federal Department of Justice and Police and, in turn, to the Federal Criminal Court or cantonal prosecutors, depending on jurisdiction. This split between administrative and criminal tracks is a defining feature of the Swiss system and one that frequently surprises businesses accustomed to the US model, where OFAC handles both civil penalties and referral in a single agency.

The Embargo Act provides the legal basis for all sanctions ordinances. Each ordinance – covering a designated country or thematic programme – implements that framework. The Swiss Sanctions List consolidates designations arising from United Nations Security Council resolutions and, separately, autonomous Swiss measures that broadly but not identically follow the EU's Council regulations. Practitioners should note that Swiss autonomous designations do not automatically track EU additions in real time. A counterparty may be listed under the EU regime for a period before the Swiss ordinance is updated – or vice versa. This timing gap creates a specific compliance risk for businesses that run a single EU-based screening process and assume Swiss alignment.

What legal obligations arise when a potential breach is identified?

Swiss law does not impose a generalised affirmative duty to self-report a past violation to SECO in the same explicit terms as OFAC's voluntary self-disclosure programme or OFSI's mandatory reporting obligation for financial institutions. However, several overlapping obligations become relevant the moment a business identifies a potential breach.

First, Swiss financial intermediaries subject to the Anti-Money Laundering Act have reporting obligations to the Money Laundering Reporting Office Switzerland when they identify transactions connected to potential sanctions violations. This is not a SECO obligation in form, but it operates as a parallel disclosure trigger. In our cross-border practice, businesses that treat sanctions compliance as separate from AML compliance often discover they have inadvertently delayed both obligations simultaneously.

Second, where assets are identified as belonging to or controlled by a designated person, those assets must be frozen immediately under the relevant ordinance. There is no grace period for the freeze obligation. The question of whether to disclose the freeze to SECO – and in what timeframe – turns on the specific ordinance and any applicable guidance SECO has issued for that programme. Verify the current position for the operative ordinance before relying on any general statement about timing.

Third, and critically, cooperation with SECO's investigation – if one is opened – is not optional. SECO holds powers to require information and documentation from regulated parties and from businesses that fall within the scope of an ordinance. Refusal or obstruction carries its own liability exposure, distinct from the original breach.

What does this mean in practice? A business that discovers a potential breach should take four immediate steps: preserve all relevant records, freeze any assets that are or may be subject to a prohibition, seek legal advice before making any further payments or deliveries, and assess whether parallel reporting obligations under Swiss AML law have been triggered.

How does the SECO enforcement procedure work in practice?

SECO's enforcement procedure follows a broadly administrative model that shares features with EU Commission and OFSI processes but diverges from OFAC's civil-monetary-penalty structure in important respects.

An investigation may be initiated by SECO on its own motion – for example, following press reporting, a tip-off, a Suspicious Activity Report from a Swiss financial intermediary, or a referral from a foreign regulator. It may also begin following a business's own disclosure. Once initiated, SECO may request documents, conduct interviews, and require the production of ownership and transaction records. The investigation phase has no publicly prescribed maximum duration; complex cross-border matters can run for an extended period.

Where SECO concludes that a civil or administrative sanction is appropriate, it issues an administrative decision. That decision may impose conditions, require disgorgement of proceeds, or result in a penalty. Critically, SECO's administrative decision is subject to appeal through the Swiss administrative courts, providing a formal challenge route that businesses should factor into their response strategy from the outset.

Where SECO concludes that the conduct meets the threshold for criminal liability under the Embargo Act, the matter is referred to the prosecutorial authorities. Criminal proceedings in Switzerland are separate from the administrative track and carry the possibility of custodial sentences as well as fines. The criminal threshold – broadly, intentional violation – is higher than the administrative threshold, which can capture negligent or reckless conduct. This distinction matters enormously for the post-breach response strategy.

In a recent matter, a trading business in the commodities sector identified that a series of payments had been routed through an intermediary with indirect links to a designated entity. We worked with the business to scope the apparent violation, map the ownership and control chain under the relevant Swiss ordinance, and prepare a structured presentation of the facts and the firm's remediation steps for engagement with the relevant authorities. The matter was resolved at the administrative level. No outcome of that kind can be guaranteed, but the manner and timing of engagement with SECO can affect how a matter is assessed.

How does Swiss enforcement compare with OFAC, OFSI, and EU enforcement?

For a business operating across multiple jurisdictions, the critical question is not only "what does SECO require?" but "how does the Swiss position interact with the regimes of the other jurisdictions we are subject to?" Enforcement risk after a breach under SECO rules is rarely a single-regime problem.

Under OFAC, civil enforcement uses a structured penalty framework with base-penalty amounts and aggravating and mitigating factors explicitly set out in OFAC's enforcement guidelines. A voluntary self-disclosure (VSD – a proactive disclosure to OFAC of a potential violation) can substantially reduce the penalty base; OFAC treats a VSD as a significant mitigating factor. The US framework is transactional and relatively predictable in its mechanics, though outcomes vary with the programme and the egregious-case designation.

OFSI in the United Kingdom operates a mandatory reporting obligation: a relevant firm (as defined under the relevant UK sanctions regulations) that knows or suspects that a person is a designated person or has breached a financial-sanctions prohibition must report to OFSI. OFSI has published a monetary-penalties guidance document and applies a "reasonable grounds to suspect" standard for breach. OFSI also has a power to impose civil monetary penalties without requiring proof of criminal intent; the UK thus has a lower threshold for civil penalty than Switzerland's criminal track requires.

The EU enforcement regime is distributed across member-state competent authorities. There is no single EU enforcement body for financial sanctions; each member state applies its own penalty and enforcement procedures within the framework of the relevant Council regulation. This creates asymmetry: a breach that touches a French entity and a German entity may be investigated by two separate national authorities applying different penalty scales. For cross-border groups, coordination of the response across these authorities is an essential element of the post-breach strategy.

Switzerland's position sits in a distinct place. The administrative/criminal split means that the response strategy – particularly the question of whether and how to approach SECO voluntarily – must be calibrated differently from a VSD to OFAC or a report to OFSI. There is no published Swiss equivalent of OFAC's explicit VSD mitigation percentage. However, voluntary cooperation and early disclosure are generally recognised mitigating factors in Swiss administrative and criminal practice. The absence of a formalised VSD framework does not mean that proactive engagement is irrelevant; it means that the form and framing of that engagement require careful handling.

One further divergence deserves attention. OFAC's 50 percent rule (the rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) is mechanically defined in OFAC guidance. The Swiss regime – like the EU and UK regimes – applies an ownership and control test (the test for whether a non-listed entity is caught through a designated person's ownership or control). The Swiss test is not purely mechanical. A non-listed entity may be caught by a Swiss ordinance where a designated person exercises effective control, even without majority ownership. This can produce outcomes that diverge from the OFAC analysis of the same corporate structure – a gap that due-diligence workflows must address explicitly.

For businesses that also export controlled goods, the interaction between Swiss embargo measures and export-licensing requirements under the Swiss export-control regime adds a further dimension. We regularly advise exporters who discover that a transaction that requires SECO scrutiny for sanctions reasons also requires a re-examination of the export-licence status of the goods.

What are the principal risk flags that indicate exposure has increased?

Several conditions materially increase enforcement risk after a potential breach, and businesses should treat each as a trigger for immediate legal review.

A designation that was added to the Swiss Sanctions List after a contract was signed but before the transaction settled places the business in a sharp-edged position. The obligation to freeze runs from the designation date; the business may have continued performance in the intervening period through no deliberate fault. SECO's assessment of such a case will turn heavily on the adequacy of the firm's screening process and the speed of its response once the designation was identified.

Corporate ownership changes that bring a designated person above any relevant ownership or control threshold mid-transaction are a documented source of post-breach exposure. The ordinance catches the entity from the point at which the designated person's ownership or control meets the threshold, not from the point at which the business learns of it. Screening at the point of onboarding is insufficient if no periodic review process exists.

Parallel foreign-regulator interest is a significant escalator. Where OFAC or OFSI or an EU national authority opens an inquiry into the same underlying conduct, SECO may become aware of it through inter-agency channels. A business that manages its US and UK disclosures without considering the Swiss position may find that SECO's awareness of the matter precedes any voluntary engagement it had planned.

Record-keeping gaps are consistently a factor in unfavourable enforcement outcomes. SECO – like all major sanctions authorities – will examine the quality and completeness of a business's records when assessing both the breach and the adequacy of the compliance programme. A business that cannot produce contemporaneous documentation of its screening steps, its ownership-chain analysis, and its decision-making process will face a harder case regardless of the substantive merits.

Have you reviewed your screening process for the timing gap between EU and Swiss Sanctions List updates? That gap is a structural source of exposure that a well-calibrated programme should explicitly address.

Common misconceptions and objections

There is a widespread belief in the market that Switzerland's neutrality tradition translates into a light enforcement posture under the Embargo Act. That belief is incorrect. SECO has demonstrated a consistent willingness to investigate apparent violations and to refer conduct that meets the criminal threshold to prosecutorial authorities. The administrative/criminal split does not soften the regime; it creates two potential tracks of exposure rather than one.

A related misconception is that Swiss sanctions rules apply only to Swiss-domiciled businesses. The Embargo Act and its ordinances apply to activities carried out in Switzerland, to persons in Switzerland, and, in relevant respects, to Swiss nationals and Swiss-incorporated entities regardless of where the transaction is executed. A multinational with a Swiss subsidiary cannot treat Swiss obligations as a local compliance matter managed in isolation from its global programme. We regularly advise international groups that have discovered – often during an M&A due-diligence exercise – that a Swiss entity's transaction records disclose exposure that the group's central compliance function was not aware of.

A third misconception is that alignment with EU sanctions is sufficient for Swiss compliance. As noted above, Swiss autonomous designations do not update automatically with EU Council decisions. A programme that runs EU-list screening and treats Swiss coverage as derivative will carry a timing-gap risk that SECO's enforcement posture does not excuse.

When should a business involve specialist counsel?

The answer is: earlier than feels necessary. The post-breach period is where the decisions that shape enforcement outcomes are made, and those decisions compress quickly.

Specialist counsel should be involved as soon as a potential breach is identified – before any disclosure is made, before any further transaction steps are taken, and before any internal communications about the breach are created without legal-privilege cover. The privilege position for internal investigations in Switzerland has its own specific rules; early structuring of the investigation under proper legal oversight protects the business's ability to manage disclosure strategy.

If a transaction has already been flagged by a Swiss financial intermediary, or a SECO enquiry has already been received, an early review preserves options that narrow with time. The position above covers the standard case. Your specific facts – the counterparty, the goods or services, the transaction route, the ordinance in play, and the conduct of other group entities in other jurisdictions – all change the analysis.

For an assessment of your exposure under the Swiss SECO regime, or to discuss the interaction of a Swiss matter with parallel OFAC, OFSI, or EU obligations, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

Who administers enforcement risk after a breach under SECO?
SECO – the State Secretariat for Economic Affairs – administers and enforces Switzerland's sanctions ordinances under the Embargo Act. For conduct that meets the criminal threshold, SECO refers matters to federal prosecutorial authorities. Financial intermediaries also face parallel reporting obligations to the Money Laundering Reporting Office Switzerland under Swiss AML law, which operates alongside the SECO enforcement track rather than as part of it.
What does SECO prohibit in relation to enforcement risk after a breach?
Switzerland's Embargo Act and the ordinances made under it prohibit dealings with designated persons and entities, the making available of funds or economic resources to such persons, and the provision of services where the relevant ordinance so provides. Where assets are subject to a prohibition, they must be frozen immediately. Failure to freeze, continued performance of a prohibited transaction, or obstruction of a SECO investigation each carry liability exposure under the administrative and, where intent is present, criminal tracks.
How is enforcement risk after a breach enforced under SECO?
SECO may open an investigation on its own motion or following a disclosure. The investigation may result in an administrative decision imposing conditions or penalties, which is appealable through the Swiss administrative courts. Where conduct meets the threshold for criminal liability, SECO refers the matter to prosecutorial authorities, and custodial sentences are possible for intentional violations. Early and well-structured engagement with SECO – advised by specialist counsel – is a recognised mitigating factor, though no specific outcome can be guaranteed.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.