Switzerland sits at the intersection of long-established financial regulation and one of the world's most active digital-asset markets. For any virtual asset service provider (VASP – a business offering exchange, custody, transfer or related services in digital assets) operating under the FINMA regime, sanctions screening is not a compliance formality. It is a hard legal obligation enforced through the Anti-Money Laundering Act, the Embargo Act and the rules of whichever self-regulatory organization (SRO) or directly supervised structure the firm sits within. Miss it, and the consequences range from SRO suspension to FINMA enforcement proceedings and frozen banking relationships – the exact outcome that ends a digital-asset business faster than any competitive pressure.
This page explains what Switzerland requires, how the obligation interacts with the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), where the cross-border gaps appear, and what operators need in place before the auditor or the regulator arrives.
Why Switzerland's sanctions regime is different for crypto
Switzerland is not an EU member state. It maintains its own autonomous sanctions regime under the Embargo Act, administered by the State Secretariat for Economic Affairs (SECO). SECO publishes its own sanctions lists – which largely track the UN, EU and US OFAC designations, but not identically and not always simultaneously. A VASP that screens only against OFAC or EU consolidated lists is not compliant under Swiss law. The SECO list is the controlling document.
FINMA has made clear through its supervisory guidance that crypto firms are subject to the same financial-crime obligations as banks in the relevant respects: know your customer, transaction monitoring and, critically, real-time or near-real-time sanctions screening at onboarding, at the point of transaction and on an ongoing basis whenever a list update occurs. Under the FINMA framework, a digital-asset firm that qualifies as a financial intermediary – through an SRO affiliation or through direct FINMA supervision under a fintech licence or banking licence – carries the full scope of these duties. There is no lighter-touch path once you are inside the supervised perimeter.
The cross-border dimension compounds this immediately. A VASP incorporated in Zug but serving users in the EU, the UAE and Singapore simultaneously sits across at least four sanctions regimes. Swiss law governs the entity; EU law may govern the counterparty; OFAC reach applies whenever a US-dollar denominated stablecoin touches the rails. Managing these layers requires a system, not a checklist.
Who is caught by the Swiss AML and sanctions perimeter?
Under the Swiss Anti-Money Laundering Act, a firm is a financial intermediary subject to supervision if it professionally accepts, holds, transfers or exchanges assets on behalf of others – and digital assets fall squarely within that definition following FINMA's published guidance. The practical consequence is that every business that: accepts crypto deposits from clients, executes exchange or swap transactions for clients, provides custody services, or transmits crypto on behalf of clients needs to be affiliated with a FINMA-recognized SRO or hold a direct FINMA licence. Without one of those structures, the firm is operating outside the regulated perimeter and its banking relationships will reflect that.
SRO affiliation is the most common entry point for smaller and mid-sized operators. The SRO conducts periodic audits and requires members to maintain a documented AML program (the full suite of KYC, transaction monitoring, sanctions screening, record-keeping and reporting obligations). FINMA itself supervises the SROs and can step in directly when a member's conduct requires it.
For firms operating at scale – exchange platforms, custodians holding significant client assets, firms seeking to issue tokens – a direct FINMA licence is frequently the right structure. The fintech licence (for firms accepting public deposits up to a defined threshold) and the full banking licence sit at different regulatory intensities, but both carry the complete sanctions-screening obligation.
To discuss how Switzerland's supervised perimeter applies to your specific operating model, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography and the banking relationships – change the analysis materially.
What does sanctions screening actually require in practice?
A compliant Swiss sanctions screening program has four operational components: list coverage, screening frequency, escalation workflow and documentation.
List coverage must include, at minimum, the SECO consolidated list. Operators serving EU counterparties should also screen against the EU consolidated list; those interacting with US persons or US-dollar instruments should screen against OFAC's Specially Designated Nationals list. A fit-for-purpose compliance program maps the counterparty universe and applies the corresponding list set – not just the most visible one.
Screening frequency is where many firms fall short. Static onboarding-only checks are not sufficient. Swiss supervisory expectations require ongoing monitoring: when list updates are published, the entire client base should be rescreened. Given that SECO, the UN Security Council, the EU and OFAC each publish updates on irregular schedules, the practical requirement is an automated system that ingests list updates and flags matches within hours.
The escalation workflow matters as much as the technical system. A match – whether a true positive or a potential false positive – must go to the Money Laundering Reporting Officer (MLRO, the senior compliance function with statutory reporting duties) on the same business day. The MLRO determines whether to freeze the transaction, file a suspicious activity report with the Money Laundering Reporting Office Switzerland (MROS), or document the false-positive reasoning. Each decision is recorded.
Documentation requirements under Swiss law are specific: records of every screening run, every match, every escalation and every MLRO decision must be retained for a defined period and must be producible to the SRO or FINMA on request. Gaps in the audit trail are treated as control failures, not administrative oversights.
How does the Travel Rule interact with sanctions screening?
The Travel Rule – implemented in Switzerland through FINMA guidance aligned with the FATF Recommendation 15 standard – requires a VASP to transmit originator and beneficiary information alongside any virtual asset transfer above the applicable threshold. The interaction with sanctions screening is not additive. It is sequential and mandatory: the counterparty VASP, and the underlying beneficial owner, must be screened before the transfer is sent or confirmed.
FATF Recommendation 15 is the international baseline that Switzerland has adopted. In practice, this means that a Swiss VASP sending USDC to a counterparty on an exchange in a non-FATF-equivalent jurisdiction faces a compounded problem: it must collect the beneficiary data, screen it against applicable lists, and assess the counterparty VASP's own AML posture – all before settlement. Automated Travel Rule solutions help with data collection and transmission, but they do not substitute for the sanctions-screening step.
The cross-border gap is real. A Swiss firm's Travel Rule obligation does not disappear because the receiving VASP sits in a jurisdiction with lighter AML standards. FINMA's approach is risk-based but demanding: if the counterparty cannot provide compliant Travel Rule data, or if the counterparty VASP is unregulated or in a high-risk jurisdiction, the Swiss firm must assess whether to proceed, enhance due diligence or decline the transaction. That assessment must be documented.
In our cross-border practice, we consistently see firms underestimate the counterparty-VASP due diligence burden. It is not enough to confirm that the other firm exists. The screening obligation extends to the legal entity behind the counterparty, its beneficial owners and, in elevated-risk cases, the underlying client whose funds are being transferred.
How do banking access and tax interact with AML obligations?
Banking access for Swiss crypto firms is a live pressure point. Swiss banks are themselves subject to FINMA supervision and carry their own AML obligations. A crypto firm that cannot demonstrate a documented, functioning AML program – including a live sanctions-screening system – will not open or maintain a Swiss banking relationship. This is not a soft preference; it is how Swiss banks manage their own regulatory risk.
The consequence for inbound operators is direct. A business setting up in Switzerland – whether in Zug, Geneva or the FINMA-regulated mainstream – that has not built its AML infrastructure before approaching banks will find the process stalled at the account-opening stage. Banking relationships follow compliance credibility, not corporate registration.
On the tax side, Switzerland applies a structured approach to the taxation of digital assets, but that tax treatment is entirely separate from the AML/sanctions perimeter. What connects them is the KYC framework: the same client identification and verification that the AML regime requires also underpins the tax-residency and beneficial-owner data that the Swiss Federal Tax Administration may request. A firm with a coherent KYC infrastructure satisfies both demands efficiently. A firm that treats them as separate tracks often creates inconsistencies that audit processes expose.
For operators with entities in multiple jurisdictions – a common structure where the operating company is in Switzerland, the holding structure is offshore, and custody is in a third hub – the AML obligation attaches to each regulated entity in each jurisdiction. Swiss law governs the Swiss entity; it does not govern the whole group. But FINMA's group-supervision expectations mean that a parent structure with weak AML standards can affect the Swiss subsidiary's supervised status.
If your structure spans two or more jurisdictions and you need to pressure-test the AML and banking layer before committing, write to us at info@oboluslaw.com. We map the compliance stack across the operating, custody and payment layers together.
A practical illustration: onboarding failure triggering an SRO inquiry
In a recent compliance matter, a digital-asset exchange with Swiss SRO affiliation had built its screening process around a single commercial screening database that did not automatically ingest SECO list updates. During a routine SRO audit, the auditor identified a four-day lag between a SECO designation and the firm's rescan of its client base. One client account had remained active during that window. We were engaged to scope the remediation: a revised vendor integration, an updated MLRO escalation protocol and a retroactive documentation exercise covering the affected period. The SRO accepted the remediation plan. The firm retained its affiliation. The lesson was not that the firm had bad intentions – it had a documentation gap that a systematic program would have prevented.
What are the most common sanctions-compliance failures for Swiss crypto firms?
A common assumption is that a well-drafted AML policy document equals a functioning AML program. The SRO and FINMA audit against implementation, not documentation. The distinction matters.
The most frequent failures we see fall into four categories. First, screening coverage gaps: the SECO list is missed because the compliance team relies on an international database that does not carry it natively. Second, update-lag problems: the system ingests list updates on a weekly batch cycle rather than in near-real-time, leaving a window during which a designated person transacts. Third, escalation process failures: a match is flagged by the automated system but sits in a queue without MLRO review because the escalation path is unclear or understaffed. Fourth, counterparty VASP screening gaps: the Travel Rule data is collected and transmitted, but the receiving firm's entity and beneficial owners are never screened against sanctions lists before the transfer is confirmed.
Each of these failures is detectable in an audit. Each creates potential liability for the firm and for the MLRO personally under Swiss law. Addressing them requires a combination of system design, process documentation and ongoing staff training – not a single remediation exercise.
Self-assessment: is your Swiss AML program fit for regulatory scrutiny?
A firm operating in Switzerland under an SRO affiliation or a direct FINMA licence should be able to answer yes to each of the following questions before the next audit cycle.
Does your screening system ingest SECO list updates automatically and rescan the full client base within hours of publication? Is your MLRO function resourced and empowered to freeze transactions and file MROS reports without board-level approval delays? Do your Travel Rule procedures include counterparty-VASP sanctions screening as a step before transfer confirmation? Are all screening runs, matches, escalations and MLRO decisions logged and retained in a form that can be produced on regulatory request? Does your AML program documentation reflect what the system actually does – not an idealized version written before the system was built?
If any answer is uncertain, the gap is worth identifying now. SRO audit cycles are not long-notice events. FINMA supervisory attention to the digital-asset sector is increasing across all the major hubs, and Switzerland is not an exception.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – end-to-end program design across licensing, KYC and transaction monitoring
- KYC and onboarding framework in the Seychelles – how a Seychelles-incorporated VASP manages client identification obligations
- Crypto fraud and asset recovery in Bermuda – recovery options when misappropriated assets are traced through a Bermuda-connected structure
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, grounded in FATF Recommendation 15 and implemented under FINMA guidance in Switzerland, requires a VASP to collect and transmit the full name, account details and, in many implementations, address information of both the originator and beneficiary alongside any qualifying virtual asset transfer. The obligation applies before the transfer is confirmed. Swiss-supervised firms must also screen that data against applicable sanctions lists as part of the same workflow.
Who must act as MLRO for a crypto firm?
Under the Swiss AML regime, a financial intermediary must designate a qualified Money Laundering Reporting Officer with the authority and independence to freeze transactions, conduct internal investigations and file reports with MROS. The role carries personal legal exposure. For smaller SRO-affiliated firms, the MLRO may also hold other senior functions, but the compliance responsibility is not dilutable. FINMA and SRO auditors will examine whether the MLRO has genuinely exercised the role, not merely held the title.
How do regulators audit crypto AML programs?
SRO auditors and FINMA examiners typically review the completeness of the documented AML program, cross-reference it against actual system logs and transaction records, and test escalation cases to confirm the MLRO process functioned as documented. Sanctions screening is audited by examining list coverage, update frequency records and the trail of any match events. A gap between the written policy and the operational record is the most common finding. Firms that treat compliance documentation as a live operational record – not a filing exercise – consistently perform better in examination.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and sanctions-screening programs that sit around them. Digital assets are the whole of our practice. We map the licence and compliance stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when recovery is needed. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in sanctions and AML program design for FINMA-supervised and SRO-affiliated digital-asset firms operating across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.