Switzerland's adoption of the EU's 20th Russia sanctions package on 19 August 2026 highlights a persistent challenge for sanctions analysts: managing compliance when your jurisdiction trails the regulatory lead by months. While Switzerland completed implementation of the 20th package, the EU had already moved on to its 21st. By the time you've updated your screening logic, training materials, and control documentation, you're already behind.
This checklist helps you build a compliance framework that accounts for Switzerland's implementation lag and maintains control integrity during periods of regulatory divergence.
What This Checklist Covers
Managing sanctions compliance in a jurisdiction that adopts EU measures with a delay creates three operational risks: missing restricted parties during the gap period, applying controls inconsistently across your customer base, and failing audit scrutiny when examiners compare your timeline to the EU's. This checklist addresses the structural elements of a compliance program designed to function across two regulatory timelines simultaneously.
Prerequisites
Before working through this checklist, confirm:
- You maintain current copies of both the Ukraine Ordinance and Regulations (EU) No 833/2014 and (EU) No 269/2014
- Your screening system can accommodate multiple effective dates for the same control logic
- Your sanctions committee meets at least monthly and can convene on short notice
- You have documented escalation criteria for transactions that fall into regulatory gray zones
Checklist Items
1. Establish a dual-timeline monitoring process
Monitor EU Official Journal publications weekly and SECO press releases daily. When the EU adopts a new sanctions package, immediately flag it for internal review even if Switzerland hasn't announced implementation plans.
Good looks like: A standing calendar entry for EU OJ review, a shared spreadsheet tracking announced-but-not-implemented measures, and a protocol for alerting business lines when new EU restrictions create potential exposure before Swiss adoption.
2. Map your customer and counterparty exposure to anticipated restrictions
Within 48 hours of an EU package announcement, run preliminary queries against your customer base and transaction history using the new criteria (expanded annexes, new prohibited goods codes, additional designated entities). Don't wait for Swiss implementation to understand your exposure.
Good looks like: A documented analysis showing which customers or transaction types would be affected, volume estimates, and a preliminary assessment of whether you'll need to suspend activity before the Swiss measure takes effect.
3. Update screening logic with staggered effective dates
The 20 August 2026 amendments included measures taking effect on 1 September 2026, 21 September 2026, and 1 January 2027. Your screening system must apply the correct restriction set based on transaction date, not just the date you updated your rules.
Good looks like: Screening rules with explicit effective-from and effective-to timestamps, test cases confirming that a transaction dated 31 August 2026 doesn't trigger the 1 September restriction, and documented version control showing which rule set applied on which dates.
4. Document your approach to the implementation gap
Write down your policy for the period between EU adoption and Swiss implementation. Will you apply EU restrictions voluntarily? Will you require enhanced due diligence for transactions that would violate EU rules but remain technically permissible under Swiss law? Will you decline certain business categories as a risk management decision?
Good looks like: A board-approved policy statement, dated and version-controlled, explaining your treatment of gap-period transactions with clear rationale (risk appetite, reputational considerations, correspondent banking relationships).
5. Verify anti-circumvention clause coverage for tanker sales
Article 12c paragraphs 2 and 3 now require contractual "no-Russia" clauses for tanker sales to third countries and mandatory SECO notification. If your institution finances, brokers, or facilitates vessel transactions, confirm your standard documentation includes compliant language.
Good looks like: Updated contract templates with the required clause, a notification workflow that triggers automatically when a covered transaction closes, and training materials for relationship managers explaining the new requirements.
6. Review crypto-asset service policies against expanded restrictions
Article 20a now covers central bank digital currencies including the digital ruble, and Article 20b prohibits use of Russian crypto-asset platforms. If you provide any crypto-related services, update your prohibited-platform list and transaction monitoring rules.
Good looks like: A maintained list of Russian crypto platforms (not just exchanges, but transfer and custody services), screening logic that flags transactions involving these platforms, and documentation of how you identify the platform when you only see blockchain addresses.
7. Assess Kyrgyz Republic exposure under new anti-circumvention rules
Article 14h prohibits export of specific goods to Kyrgyzstan (machining centers, data transmission equipment per Annex 38) to prevent re-export to Russia. If you finance trade or provide letters of credit, screen against both the goods codes and the destination.
Good looks like: Enhanced due diligence procedures for Kyrgyz counterparties, specific questions in your trade finance questionnaire about end-use and end-users, and documented decisions when you approve or decline transactions in this corridor.
8. Update managed security services notifications
If you previously notified SECO under the group exception for software and services (Article 28e paragraph 8 letter a), the 21 September 2026 extension to managed security services may change your reporting obligation. Your next notification is due by 31 January 2027.
Good looks like: A compliance calendar entry for 31 January 2027, an inventory of all services provided to Russian entities under the group exception, and a documented analysis of whether any service now qualifies as "managed security services" requiring separate treatment.
9. Confirm intellectual property and judgment-enforcement controls
Articles 28i, 28j, and 28k restrict transactions related to Russian IP seizures and enforcement of certain Russian court judgments. Review your onboarding questionnaire to identify customers involved in Russia-related litigation or IP disputes.
Good looks like: Specific questions in your CDD refresh asking whether the customer is party to litigation involving Russian state entities or enforcement actions in third countries, screening against Annexes 39, 40, and 41, and a legal review protocol when you identify potential exposure.
10. Test your sanctions framework against the next package
Don't wait for the 21st package to be implemented. When Switzerland announces it, use this checklist again. Track your cycle time from announcement to full implementation in your systems.
Good looks like: A post-implementation review document showing days elapsed from SECO press release to screening update, training completion, and control testing, with identified bottlenecks and process improvements for the next cycle.
Common Mistakes
Treating the implementation date as your action date. If the measure takes effect on 20 August and you update your systems on 20 August, you've already missed transactions from earlier that day.
Applying new restrictions retroactively to pending transactions. A letter of credit issued on 15 August under the old rules doesn't become non-compliant on 20 August. Document your cutoff logic.
Assuming Swiss exceptions mirror EU exceptions. Switzerland maintains "Switzerland-specific exceptions, licensing grounds and implementation timelines." Read the actual Swiss text; don't copy your EU subsidiary's procedures.
Ignoring the measures that haven't taken effect yet. You need to prepare for the 1 January 2027 LNG restrictions now, not in December 2026.
Next Steps
Schedule your next sanctions committee meeting to review this checklist against your current program. Assign ownership for each item. Set a recurring review cycle that aligns with your monitoring frequency for EU and Swiss announcements. When Switzerland announces implementation of the 21st package, you'll already have a tested process for managing the gap.
Your goal isn't perfect synchronization with the EU timeline. That's structurally impossible given Switzerland's legislative process. Your goal is a documented, defensible approach to managing the lag period that protects your institution from sanctions violations and demonstrates to examiners that you understand the risk you're managing.



