[codicts-css-switcher id=”346″]

Global Law Experts Logo
foundations compliance switzerland

How to Comply with AML and Sanctions Rules for Swiss Foundations in 2026: KYC, Reporting and Risk Controls

By Global Law Experts
– posted 58 minutes ago

Updated September 2026, reflects Switzerland’s beneficial-ownership transparency reform and the current sanctions landscape.

Who this is for: foundation boards, family offices, trustees, general counsel and compliance officers.

What this delivers: actionable procedures, checklists and templates to meet AML, KYC and sanctions rules for Swiss foundations in 2026.

Reading time: approximately 14–18 minutes.

Foundations compliance Switzerland has moved from a background governance concern to a front-line operational obligation, and 2026 is the year boards can no longer defer it. New beneficial-ownership transparency measures, an expanded and more volatile sanctions landscape, and heightened cross-border enforcement mean that a foundation which accepts a donation or makes a grant abroad can be exposed within days. This guide translates the statutory framework into a step-by-step operations playbook, covering donor and beneficiary KYC, sanctions screening, suspicious activity reporting, recordkeeping and board controls, with templates, timelines and worked examples. It is written for the people who actually run the controls, not just those who theorise about them.

Quick checklist: why 2026 matters for foundations compliance Switzerland

Before diving into detail, use this six-item scan to decide where your foundation stands today. If you cannot answer “yes” to each, you have a gap to close.

  • Risk assessment. Have you completed a documented, risk-based assessment of donors, beneficiaries and grant destinations within the last 12 months?
  • KYC files. Do you hold identity, source-of-funds and beneficial-ownership records for every material donor and intermediary?
  • Sanctions screening. Are all counterparties screened against the relevant SECO, UN, EU and other applicable lists before funds move?
  • Reporting route. Does every officer know when and how to file a report to the Money Laundering Reporting Office Switzerland (MROS) and who signs it off?
  • Beneficial ownership. Are you ready to meet the beneficial-ownership obligations introduced under Switzerland’s transparency reform?
  • Board oversight. Has the board adopted written AML and sanctions policies, and does it review high-risk cases?

The remainder of this article works through each of these in operational detail, anchoring every prescriptive step to the primary Swiss statute or regulator guidance.

1. Which AML and sanctions rules apply to Swiss foundations?

The starting point for foundations compliance Switzerland is understanding that several distinct legal regimes overlap. A foundation is not automatically a regulated financial intermediary, but it can fall within AML obligations depending on its activities, and it is always bound by Swiss sanctions measures regardless of its size or purpose.

1.1 Primary statutes and regulators

Several pillars define the landscape:

  • Swiss Civil Code. The foundation’s legal form, its purpose-bound assets and the duties of its board are governed by the foundations provisions of the Civil Code (Articles 80 et seq.). These fiduciary duties underpin every compliance obligation that follows.
  • Anti-Money Laundering Act (AMLA). The AMLA is the primary statute setting out when an entity is a financial intermediary, the due diligence and identification obligations that follow, and the recordkeeping and reporting duties.
  • Embargo Act and related ordinances administered by SECO. The State Secretariat for Economic Affairs (SECO) administers and enforces Swiss sanctions measures adopted under the Embargo Act and can order the blocking of funds. Sanctions apply universally, a foundation does not need to be a financial intermediary to be caught by an asset freeze.

The Swiss Financial Market Supervisory Authority (FINMA) issues guidance on the risk-based approach and supervisory expectations for supervised financial intermediaries, which is a useful reference point for how due diligence should be calibrated in practice.

1.2 Secondary obligations: transparency and data protection

Two secondary regimes materially affect operations. First, Switzerland’s beneficial-ownership transparency reform introduces obligations for legal entities, potentially including foundations within scope, to identify and record beneficial ownership information, with a federal transparency register being established under the reform. Foundations should confirm the scope and commencement of these obligations, as the precise timing and registration requirements are set by the implementing legislation and ordinances. Second, all KYC data processing sits within the Swiss data protection regime supervised by the Federal Data Protection and Information Commissioner (FDPIC). Collecting passports, addresses and source-of-funds evidence is lawful for AML purposes, but it must be proportionate, secured and retained only as long as the law requires.

1.3 How enforcement works

Breaches attract both criminal and administrative consequences. Failure to report suspicious activity, or dealing with a sanctioned party, can expose officers and the foundation to criminal liability. SECO can impose administrative measures and refer breaches to prosecutors. Because donors and grantees are frequently cross-border, Swiss authorities cooperate with foreign counterparts, meaning a single mishandled transfer can trigger enquiries in multiple jurisdictions. The international benchmark for how a foundation should approach this is the Financial Action Task Force (FATF) guidance on the risk-based approach for non-profit organisations, which Swiss practice reflects.

2. Who is covered and when a foundation becomes AML-obliged

Not every foundation is a reporting entity, and a proportionate approach to foundations compliance Switzerland begins with honestly classifying your own activities. Over-engineering controls wastes resources; under-scoping them creates legal exposure.

2.1 When a foundation is a “financial intermediary” under the AMLA

A foundation may be treated as a financial intermediary, and therefore fall squarely within AMLA due diligence and reporting duties, when it performs financial intermediation on behalf of others, such as accepting, holding or transferring third-party assets, or facilitating payments that are not simply its own grant-making. A foundation that receives donations, applies them to its stated charitable purpose and disburses grants from its own assets is engaged in different activity from one that routes third-party funds. The practical test is whether the foundation is handling assets on behalf of others in a way that resembles a payment or asset-management service.

2.2 Risk indicators that trigger higher obligations

Even where formal AMLA status is uncertain, the following features should push a foundation toward the full control set:

  • Payment processing. Acting as a conduit for funds between third parties.
  • Virtual assets. Accepting or holding cryptoassets, which carry elevated tracing and sanctions risk.
  • Use of intermediaries. Relying on agents to introduce donors or distribute grants, where you cannot see the ultimate counterparty.
  • High-risk geographies. Donors or grantees connected to sanctioned or high-risk jurisdictions.

2.3 Cross-border donor and grant triggers

Cross-border activity is the single most common trigger for elevated obligations. A large anonymous international donation, a grant to an organisation operating in a conflict zone, or a payment routed through a jurisdiction on a watchlist each demands enhanced scrutiny before funds move. When any of these is present, treat the transaction as high-risk by default and apply the enhanced due diligence steps set out below.

3. KYC for donors, beneficiaries and intermediaries, step by step

Know-your-customer procedures are the operational core of foundations compliance Switzerland. The objective is not to collect paper for its own sake but to satisfy a materiality and risk test: verify enough to be confident about who you are dealing with and where the money comes from. The following five steps form a repeatable sequence.

3.1 Step 1, Risk classification and KYC scope

Begin by classifying each incoming donor, grant or intermediary as low, medium or high risk. Score against donor type (individual versus entity), amount, geography, source of funds transparency and any political exposure. The classification determines the depth of KYC required. A modest domestic donation from a known supporter sits at the low end; a large donation from an offshore corporate structure sits at the high end and demands enhanced due diligence. Record the classification and the reasoning, an unexplained score is a finding waiting to happen in an audit.

3.2 Step 2, Information to collect

Collect the identity of the counterparty, the purpose of the relationship, the source of funds and the beneficial owner behind any entity. The documents required vary by category. The table below sets out a minimum expected file, aligned to Swiss AML recordkeeping principles. Note that AMLA generally requires records to be kept for at least ten years after the end of the business relationship or the completion of the transaction; confirm the applicable period for your specific obligations.

Category Documents to obtain Indicative retention
Individual donor Passport/ID copy; proof of address (utility bill); donor declaration; source of funds statement At least 10 years
Corporate / legal entity donor Certificate of incorporation; register excerpt; articles; identity documents for directors/authorised signatories; beneficial ownership evidence At least 10 years
Intermediary / agent Engagement letter; AML/compliance policy excerpt; proof of onboarding due diligence performed by agent At least 10 years
Beneficiary (where applicable) ID; relationship evidence; beneficiary declaration; purpose of grant documentation At least 10 years
Payment & transfer records Bank confirmation; SWIFT/transaction trace; contracts At least 10 years
Risk assessment & KYC file Completed risk scoring sheet; approval emails; EDD notes At least 10 years

3.3 Step 3, Verifying identity and beneficial ownership

Verification can be documentary (certified copies of identity documents and register extracts) or electronic (identity-verification services and reliable database checks). For entities, you must trace through to the natural persons who ultimately own or control the structure. Where ownership is layered through holding companies or nominee arrangements, do not stop at the first tier, the beneficial owner is the human being at the end of the chain. Retain evidence of each verification step in the KYC file.

3.4 Step 4, Enhanced due diligence

Escalate to enhanced due diligence (EDD) whenever the risk classification is high, or when a red flag appears mid-relationship. EDD typically involves obtaining additional documentary evidence of source of wealth, corroborating information from independent sources, obtaining senior management or board approval before proceeding, and applying more frequent ongoing monitoring. FATF guidance supports precisely this graduated approach: not every counterparty warrants EDD, but those presenting elevated risk clearly do.

3.5 Step 5, Ongoing monitoring and refresh cycles

KYC is not a one-time gate. Set refresh cycles proportionate to risk, for example, more frequently for high-risk relationships and on a longer cycle for low-risk ones, and monitor for changes in circumstances, adverse media and new sanctions designations. A donor who was clean at onboarding can become sanctioned, which is why ongoing screening (covered below) sits alongside periodic KYC refresh.

KYC red flags

  • Reluctance to disclose beneficial owners or evasive answers about source of funds.
  • Donations disproportionate to the donor’s known profile.
  • Complex offshore structures with no clear commercial or philanthropic rationale.
  • Requests for unusual routing, third-party payments or use of cryptoassets.
  • Connections to high-risk or sanctioned jurisdictions.
  • Pressure to move funds quickly before due diligence is complete.

4. Sanctions screening: steps, tools and escalation

Sanctions screening is among the highest-consequence elements of foundations compliance Switzerland, because dealing with a designated party is a serious exposure, good intentions offer limited protection. The following four-step sequence should be embedded in every grant and donation workflow.

4.1 Step 1, Determine sanctions exposure

Assess exposure across three vectors: the nationality and residence of the donor or beneficiary, the routing of any payment (correspondent banks and intermediary jurisdictions), and the location where grant funds will ultimately be used. A grant to a domestic charity has minimal exposure; a transfer to a project operating near a sanctioned region has significant exposure that must be resolved before funds move.

4.2 Step 2, Screening frequency and watchlists

Screen every counterparty at onboarding, before each material payment, and on an ongoing basis against updated lists. The Swiss measures administered by SECO under the Embargo Act are the primary reference for a Swiss foundation. Because Swiss foundations frequently operate cross-border, it is prudent to also screen against other applicable regimes, for example the United Nations consolidated list, the European Union list, US OFAC designations, and the UK regime where relevant to the transaction. Sanctions lists change frequently, so batch re-screening of the existing donor and grantee population should run on a regular cadence, not only at onboarding.

4.3 Step 3, Handling hits: triage, false positives and escalation

When a screening hit appears, triage it immediately. Many hits are false positives caused by common names; resolve these by comparing date of birth, nationality and other identifiers. Where a hit cannot be cleared, escalate to the compliance officer and legal counsel, and apply a payment hold. Do not release funds on a “probably fine” basis. A sample hold notice might read:

“Pending completion of mandatory compliance checks, this transaction is placed on hold. No funds will be released until the check is cleared and internal approval obtained. We will revert within [X] business days.”

4.4 Step 4, Recordkeeping and reporting

Document every screening result, every false-positive resolution and every escalation. Where a confirmed match arises, SECO can order the blocking of funds, and you may have notification obligations to SECO and to other competent authorities. Retain the full audit trail. The choice of screening tool affects both accuracy and the quality of that audit trail, as the comparison below shows.

Option Coverage Cost Pros Cons
In-house manual screening Basic (national lists) Low Control over process; immediate Time-consuming; prone to misses
Third-party screening vendor Multi-jurisdictional, automated Medium–High High accuracy, SLA, audit logs Ongoing fees; integration needed
Bank / custodian screening Bank’s lists via account relationships Low–Medium (fee via account) Hands off for payment channels May not cover grants paid via non-bank channels

For most foundations making cross-border grants, a third-party vendor combined with bank-level screening offers the best balance of coverage and defensibility. Manual screening alone is rarely sufficient once activity crosses borders.

5. Suspicious activity reporting and recordkeeping

Reporting is the point at which foundations compliance Switzerland intersects most directly with the criminal law. Getting the timing and confidentiality right protects both the foundation and its officers.

5.1 When to file a report to MROS

For AML-obliged entities, the trigger is a well-founded suspicion, an articulable belief that assets are connected to money laundering, a predicate offence, organised crime or terrorist financing. This is not certainty. If, having reviewed the facts, a diligent officer would suspect illicit origin or purpose, the reporting obligation may arise. Reports are filed with the Money Laundering Reporting Office Switzerland (MROS), the Swiss financial intelligence unit. Do not wait for proof, and do not “investigate” your way past the applicable deadline.

5.2 How to prepare and submit a report

Prepare the report using a structured checklist: identify the counterparty, describe the transaction and amounts, set out the specific facts that founded the suspicion, attach supporting KYC and transaction records, and record the internal approval. Submit to MROS through the designated reporting channel within the applicable timeframe. Keep the submission and its acknowledgement in a restricted file.

5.3 Interaction with criminal investigations and confidentiality

Once a report is filed, strict confidentiality applies, tipping off the counterparty is prohibited and can itself be an offence. Cooperate with any subsequent enquiry from authorities through counsel. An obligation to freeze or hold assets pending instructions may run in parallel with the reporting duty, depending on the circumstances.

5.4 Record retention, audit trails and data protection

Retain KYC, screening and reporting records for the statutory period, generally at least ten years under Swiss AML practice. Balance retention against data protection: personal data must be secured, access-restricted and not kept beyond the lawful retention period. The FDPIC’s guidance on proportionate data processing should inform your retention schedule so that AML retention and data protection minimisation are reconciled rather than in conflict.

6. Board and operational controls: policies, roles and training

Controls only work when ownership is clear. The board carries ultimate responsibility for foundations compliance Switzerland, and it discharges that duty through a defined governance framework rather than ad hoc reaction.

6.1 Minimum governance framework

At a minimum, adopt a written AML/CTF policy, a written sanctions policy, and a delegation of roles setting out who does what. These documents should map directly to the procedures in this guide so that staff have a single, coherent operating reference.

6.2 Responsibilities

  • Board / Chair. Approves policies, oversees the risk framework, and decides high-risk and escalated cases.
  • Managing officer. Ensures day-to-day implementation and resourcing of controls.
  • Compliance Officer. Runs KYC, screening, reporting and monitoring, and maintains records.
  • External advisers. Provide legal review on complex EDD cases, sanctions hits and reporting decisions.

6.3 Training cadence and testing

Train all relevant staff and board members regularly, at least annually is good practice, and refresh whenever the regime changes materially. Use scenario exercises: walk the team through a mock high-risk donation and a mock sanctions hit to test whether escalation lines actually function under pressure.

6.4 Insurance, indemnities and legal escalation

Confirm that directors’ and officers’ cover addresses compliance exposures, that indemnity arrangements are documented, and that there is a clear, fast route to external counsel when a payment must be held or a report filed. Escalation that depends on a single unavailable individual is a control failure.

7. Practical workflows, timelines and templates

Translating policy into a repeatable workflow is what makes foundations compliance Switzerland sustainable. The timeline table below sets out a defensible sequence with owners and indicative durations; adjust these to your own risk profile and resources.

Step Who (owner) Indicative duration
Initial risk classification of incoming donor/grant Compliance Officer / Manager 1–3 business days
Basic KYC collection (ID, org docs) Donor / Relationship Manager 2–7 business days
Beneficial ownership verification Compliance Officer / third-party vendor 1–10 business days
Sanctions screening (automated) Compliance Officer / screening vendor Minutes–24 hours
Enhanced due diligence & legal review Compliance Officer + External Counsel 3–14 business days
Board escalation for high-risk cases Board / Chair Next scheduled meeting or extraordinary (1–7 days)
Payment hold and reporting to authorities Finance + Compliance Immediate (hold) + file within applicable timeframe

7.1 Sample grant-making workflow with AML and sanctions gates

A robust workflow builds compliance gates into the payment process so that funds cannot leave without clearance. In practice: (1) a grant request is logged; (2) the beneficiary is risk-classified; (3) KYC is collected and, if required, EDD performed; (4) sanctions screening runs on the beneficiary and payment route; (5) approval is granted at the appropriate level; and only then (6) finance releases the payment. Each gate must be passed and evidenced before the next begins.

7.2 When to pause a payment and sample hold language

Pause immediately on any unresolved sanctions hit, any unexplained KYC gap, or any red flag emerging late in the process. Communicate the hold neutrally, without disclosing a suspicion where confidentiality applies. A short internal note recording the reason for the hold and the approver protects the foundation if the decision is later reviewed.

7.3 Template resources

To operationalise these steps, foundations should maintain a KYC donor questionnaire, a suspicious activity report template, an AML policy checklist and a risk assessment scoring spreadsheet. Standardising these documents ensures consistency across officers and produces the audit trail that regulators expect.

For complex structures or cross-border grant channels, it is prudent to take advice, see When to hire a foundations lawyer in Switzerland (practical counsel), and to understand how the foundation form compares with alternatives in Foundation vs Trust, Swiss foundations overview.

8. What changes in 2026 and what to do now

The 2026 environment raises the baseline for foundations compliance Switzerland in two decisive ways, and both demand attention.

  • Beneficial-ownership transparency. Switzerland’s transparency reform introduces beneficial-ownership identification and recording obligations for legal entities within scope, supported by a federal transparency register. Confirm whether and how your foundation is in scope, gather the underlying data, and prepare to meet the applicable registration and record obligations as they take effect.
  • Sanctions volatility. Lists are expanding and changing frequently, increasing the risk that a previously clean counterparty becomes designated. Re-screening cadence should increase accordingly.

Immediate actions: update your AML and sanctions policies to reflect current requirements; run a gap analysis against the quick checklist at the top of this guide; onboard or upgrade a screening tool with adequate multi-jurisdictional coverage; and refresh board and staff training so that everyone understands the current filing and screening duties.

9. Common pitfalls and remediation

  • Poor recordkeeping. Remediation: adopt standardised KYC files and a fixed retention schedule; audit a sample quarterly.
  • Over-reliance on third parties without oversight. Remediation: retain responsibility for outcomes; review vendor and intermediary performance and evidence their due diligence.
  • Missing beneficial owners. Remediation: trace ownership to natural persons; do not accept a corporate name as the endpoint.
  • Unclear escalation lines. Remediation: document who holds, who approves and who files, with named deputies for absence.
  • Stale screening. Remediation: schedule regular batch re-screening of the existing population, not only onboarding checks.

Conclusion

Foundations compliance Switzerland in 2026 is a matter of disciplined process rather than occasional reaction: classify risk, verify counterparties, screen against sanctions before funds move, report on well-founded suspicion, keep defensible records and give the board genuine oversight. The transparency and sanctions developments in play this year raise the baseline for every foundation that accepts donations or makes cross-border grants, and the practical steps, tables and templates in this guide are designed to be implemented now rather than deferred. Treat compliance as an operational capability the foundation owns end to end, and both the entity and its officers are substantially better protected.

This page provides general compliance guidance and does not constitute legal advice. Foundations should consult counsel for case-specific obligations and confirm current statutory requirements before acting.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Marie Flegbo-Berney at BONNARD LAWSON, a member of the Global Law Experts network.

Sources

  1. Swiss Civil Code (Foundations provisions, Art. 80 et seq.), Fedlex
  2. Swiss Anti-Money Laundering Act (AMLA), Fedlex
  3. FINMA, Anti-money laundering guidance
  4. SECO, Swiss sanctions and export controls
  5. MROS, Money Laundering Reporting Office Switzerland (fedpol)
  6. FATF, Guidance on the Risk-Based Approach for Non-Profit Organisations
  7. Swiss Federal Data Protection and Information Commissioner (FDPIC)

FAQs

What AML and sanctions rules apply to foundations in Switzerland?
Foundations are governed by the Civil Code as to their legal form and board duties, by the Anti-Money Laundering Act where they perform financial intermediation, and by Swiss sanctions measures administered by SECO under the Embargo Act, which apply universally. FINMA guidance shapes the risk-based approach for supervised intermediaries, and FATF guidance for non-profit organisations provides the international benchmark.
Where a foundation is AML-obliged, or where risk indicators are present, yes. KYC should be applied on a risk-based basis to donors, beneficiaries and intermediaries, covering identity, purpose, source of funds and beneficial ownership, with enhanced due diligence for high-risk relationships.
For an AML-obliged entity, the obligation arises on a well-founded suspicion that assets are connected to money laundering, a predicate offence, organised crime or terrorist financing. Reports are filed with the Money Laundering Reporting Office Switzerland (MROS) within the applicable timeframe while maintaining strict confidentiality.
Triage the hit, resolve genuine false positives using identifying data, and where a match cannot be cleared, place a payment hold and escalate to the compliance officer and legal counsel. SECO can order the blocking of funds, so no payment should be released until the hit is cleared and approved.
Under Switzerland’s beneficial-ownership transparency reform, legal entities within scope, potentially including many foundations, must identify and record beneficial ownership information, with a federal transparency register being established. Confirm your specific obligation and its commencement, and prepare accurate underlying records.
The board holds ultimate responsibility: approving AML and sanctions policies, overseeing the risk framework, ensuring resourcing and training, and deciding escalated high-risk cases. These duties flow from the fiduciary obligations imposed on foundation boards under the Civil Code.
By Olufunke Olumide

posted 54 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Comply with AML and Sanctions Rules for Swiss Foundations in 2026: KYC, Reporting and Risk Controls

Send welcome message

Custom Message