Mittelstandspresse
22.07.2026
Compliance Trap 2026
Why the new transparency register for Swiss CEOs is just the tip of the iceberg
Unterföhring bei München, 22.07.2026 (PresseBox) - I. Why you should read the text
Why should CEOs read this article? Because by 2026, compliance will no longer be a back-office issue, but a personal liability risk. Transparency registers, supply chain obligations, chemicals legislation, cyber reporting requirements, and sanctions directly impact strategy, governance, and reputation. Those who fail to properly document responsibilities, evidence, and controls risk fines, directors' and officers' liability, and a loss of trust.
II. Time constraints, expired and upcoming deadlines
In 2026, Swiss CEOs must keep several deadlines in mind: ensuring ongoing sanctions screenings and cyber reporting processes, in particular the 24-hour reporting to the BACS for critical infrastructure. The consultation period for the NUFG (New Financial Markets Act) ends on July 9. Transparency registers and the revised AML Act (Anti-Money Laundering Act) come into effect on October 1. EUDR readiness for EU business transactions must be achieved by December 30. Chemicals Risk Reduction Ordinance (ChemRRV) obligations must also be reviewed on a product- and substance-specific basis.
III. Duties for C-level executives and compliance, including normative aspects
For Swiss CEOs, several specific compliance obligations with direct liability implications will arise in 2026. The focus is on the new transparency register under the Transparency and Justice Act (TJPG) and the revised Money Laundering Act, both of which will come into force on October 1, 2026. Companies must identify, verify, document, and keep up-to-date their beneficial owners. At the same time, KYC, risk, and control processes must be adapted.
In addition, there are obligations arising from existing and new sustainability, product, and cyber regimes. The draft Federal Act on Sustainable Corporate Governance increases the pressure to systematically record human rights and environmental risks along the value chain. The Chemicals Risk Reduction Ordinance requires testing for PFAS, microplastics, and other restricted substances. Operators of critical infrastructure must report notifiable cyberattacks to the BACS within 24 hours.
For internationally active companies, EU regulations also apply, in particular the EU Deforestation Regulation, which comes into effect on December 30, 2026, for affected EU business activities. CEOs should not treat these obligations as a departmental issue, but rather as a governance task: defining responsibilities, documenting controls, establishing escalation procedures, and ensuring auditable documentation.
The most important regulatory references are: the TJPG and the revised GwG from 1 October 2026 for transparency registers, beneficial owners and money laundering prevention; the Information Security Act / BACS reporting obligation for cyberattacks on critical infrastructures; the ChemRRV for PFAS, microplastics and substance restrictions; the NUFG draft on sustainable corporate management; and the EU Deforestation Regulation , insofar as Swiss companies place, trade or export products in the EU.
Identifying beneficial owners: Identification, verification, documentation and updating of beneficial owners according to TJPG .
Use of the transparency register: Reporting and updating obligations for affected legal entities from 1 October 2026 .
Adapting AML processes: KYC, risk analysis, internal controls, documentation and, where applicable, reporting processes according to the revised Money Laundering Act .
Preparing ESG due diligence: identifying human rights and environmental risks along the value chain, defining responsibilities and establishing reporting structures; relevant in the context of the NUFG draft .
Check product compliance: Check materials, products and supply chains for restricted substances such as PFAS and microplastics according to ChemRRV .
Establish cyber reporting processes: For critical infrastructures, reportable cyberattacks must be reported to the BACS within 24 hours .
Ensure sanctions compliance: Continuously check business partners, ownership structures, payments and goods flows against applicable Swiss sanctions regulations.
Establish EUDR readiness: Prepare deforestation-free, traceable and due diligence documentation for EU transactions involving timber, coffee, cocoa, soy, palm oil, beef, rubber and derivative products.
Demonstrate governance: For CEOs, what is crucial is not only the implementation, but also the reliable documentation: Who checks what, when, with what result and what escalation occurs.
IV. Problem areas within the scope of the obligations to be implemented
1.) Organizational and supervisory liability:
Art. 716a OR: non-transferable duties of the board of directors, in particular overall management, organization, financial control and overall supervision.
Art. 717 OR: Duty of care and loyalty.
Article 754 of the Swiss Code of Obligations (OR): Liability for intentional or negligent breach of duty. These provisions form the core of personal liability for corporate officers in Switzerland.
2.) Transparency Register / Beneficial Owners:
TJPG, in particular obligations to identify, verify and report beneficial owners. The law enters into force on October 1, 2026 and applies to legal entities under Swiss private law as well as certain foreign legal entities and trusts.
3.) Money laundering / KYC:
The German Money Laundering Act (GwG) and revised anti-money laundering regulations: The scope of application is being extended to certain advisory services, such as those related to real estate transactions and the formation or structuring of legal entities. This increases liability risks in cases of incomplete identification, risk analysis, or documentation.
4.) Cyber reporting obligation:
Information Security Act (ISG) and Cybersecurity Ordinance (CSV): Operators of critical infrastructure must report cyberattacks to the BACS within 24 hours of discovery. For CEOs, the risk here lies in the lack of an incident response and escalation process.
5.) Product and fabric compliance:
ChemRRV, SR 814.81: The revision concerns, among other things, PFAS and microplastics. Liability risks arise in the case of untested materials, incorrect supplier declarations, sales stoppages, recalls, or regulatory proceedings.
6.) Sanctions compliance:
Embargo Act (EmbG) and the sanctions ordinances based on it: Switzerland implements international sanctions; companies must check business partners, ownership structures, payments, and flows of goods. Violations can have serious criminal and reputational consequences.
7.) ESG / Greenwashing / Sustainability:
Article 3, paragraph 1, letter x of the Unfair Competition Act (UWG) is relevant for climate-related statements: Climate impact claims must be objectively and verifiably substantiated. Additionally, the draft Environmental Impact Assessment Act (NUFG) is politically relevant, but not yet legally binding; therefore, it is better formulated as a "preparatory obligation from a governance perspective," not as an already existing legal obligation.
8.) EU business / Deforestation:
EUDR, Regulation (EU) 2023/1115, in particular Articles 3, 4 and 8: Affected products may only be made available on the EU market or exported if they are deforestation-free, legally produced and covered by a due diligence declaration. Applies from 30 December 2026 to many companies with EU ties.
V. Implementation roadmap and solution recommendations
The most important solution for CEOs in 2026 is: Compliance must be demonstrably managed. This means prioritizing risks, assigning responsibilities in writing, documenting controls, and testing escalation procedures. With regard to Articles 716a, 717, and 754 of the Swiss Code of Obligations (OR), the board of directors and management should be able to demonstrate that transparency registers, anti-money laundering/Know Your Customer (KYC) regulations, cyber reporting obligations, the Chemical Risk Reduction Ordinance (ChemRRV), sanctions, and ESG risks are actively monitored. A robust compliance dashboard with deadlines, owners, audit status, and measures taken is crucial.
1. Implement a CEO compliance dashboard. Create a monthly dashboard for management and the board of directors outlining top risks, deadlines, responsible owners, status, open measures, and escalations. This helps to demonstrably fulfill the supervisory and monitoring obligations under Art. 716a of the Swiss Code of Obligations (OR) and the duty of care under Art. 717 OR .
2. Launch Transparency Register Readiness: By the time the Transparency and Profit Sharing Act (TJPG) and the revised Money Laundering Act (GwG) come into force on October 1, 2026, beneficial owners should be identified, shareholding structures clarified, evidence collected, and reporting processes tested. The new transparency register is intended to create transparency regarding beneficial owners.
3. Recalibrate KYC and AML processes. Review whether new or expanded obligations are relevant for financial intermediaries, trustees, legal, tax, or business advisors. Clear risk categories, documented client files, update cycles, and escalation procedures for ambiguities are essential.
4. Test the Cyber Incident Playbook. Operators of critical infrastructure must report cyberattacks to the BACS within 24 hours of discovery ; this is regulated in the ISG and the Cyber Security Ordinance . CEOs should therefore have a tested reporting process: Who detects, who decides, who reports, and who informs the board, legal, IT, communications, and insurance departments?
5. Conduct product and supply chain screening. Companies involved in production, import, trade, or brand responsibility should conduct material testing for PFAS, microplastics, and other substances relevant to the German Chemicals Risk Reduction Ordinance (ChemRRV ) by 2026. The ChemRRV amendments address, among other things, PFAS and microplastics. In practical terms, this means updating supplier declarations, reviewing product data sheets, defining alternatives, and preparing recall/supply stoppage scenarios.
6. Automate sanctions screening: Business partners, beneficial owners, payments, goods flows, and country connections should be continuously checked against applicable Swiss sanctions regulations. It is particularly important to check not only direct contractual partners but also ownership and control structures.
7. Prepare ESG due diligence, but classify it correctly. The NUFG ( New Public Management Act) is still a legislative project in 2026; the Federal Council opened the consultation process on April 1, 2026. Nevertheless, large and internationally active companies should already be mapping human rights and environmental risks along their value chain, defining responsibilities, and preparing complaint and redress processes.
8. Check EUDR readiness for EU business. Anyone placing affected products such as wood, coffee, cocoa, soy, palm oil, beef, rubber or derivative products in the EU or exporting them should set up traceability, supplier data and due diligence documentation early on.
9. Review D&O insurance and liability gaps. CEOs and board members should clarify whether new risks arising from transparency registers, anti-money laundering regulations, cyber risks, sanctions, ESG, and product compliance are covered. It is also important to understand which exclusions apply in cases of intentional breaches of duty, sanctions, or cyber incidents.
10. Create evidence files for each risk area. For each top risk, there should be a digital "evidence file": policy, risk analysis, responsible parties, controls, training records, audit reports, escalations, and board meeting minutes. This is because, in liability cases under Art. 754 of the Swiss Code of Obligations , it is not only what was done that counts, but also whether it can be proven later.
In short: CEOs in 2026 should not accumulate even more individual measures, but rather create a system that demonstrates: risks have been identified, responsibilities clarified, controls implemented, and the board of directors informed. This is the most effective defense against personal liability.
VI. Conclusion
For Swiss CEOs, compliance will become a personal leadership responsibility by 2026. Transparency registers, the Anti-Money Laundering Act (AML), cyber reporting obligations, the Chemicals Risk Reduction Ordinance (ChemRRV), sanctions, and ESG risks demand clear responsibilities, robust controls, and auditable documentation. The crucial factor is not whether compliance has been delegated, but whether the board of directors and management have effectively monitored compliance in accordance with Articles 716a, 717, and 754 of the Swiss Code of Obligations (OR).
Ansprechpartner
Cassedy Brose
Anna Tatar
+49 89 452 429 70 113
Zuständigkeitsbereich: Online Marketing Managerin
Über S&P Unternehmerforum GmbH:
S+P Unternehmerforum GmbH mit Sitz in München ist ein führender Anbieter für praxisnahe, rollenbasierte Weiterbildung im deutschsprachigen Raum. Seit der Gründung im Jahr 2004 unterstützt S+P Fach- und Führungskräfte sowie C-Level-Manager:innen aus der Finanzwirtschaft und Industrie dabei, sich gezielt weiterzuentwickeln und regulatorisch sowie strategisch sicher zu handeln.
S+P bietet ein breites Portfolio an Online-Seminaren, E-Learnings, Zertifikatslehrgängen und Executive Education Programmen. Themenschwerpunkte sind unter anderem Compliance, Geldwäscheprävention, Risikomanagement, Projektmanagement, Finance, Leadership und digitale Transformation.
Ein Alleinstellungsmerkmal ist die S+P Tool Box – mit sofort einsetzbaren Arbeitshilfen wie Leitfäden, Checklisten, Gantt-Plänen und Risikochecks. Zusätzlich steht allen Teilnehmer:innen die digitale Lernplattform S+P Lounge zur Verfügung.
Mit dem Zertifikat S+P Certified und dem digitalen Karriere-Badge dokumentieren Absolvent:innen ihre Kompetenz sichtbar – für Arbeitgeber, Kunden und Netzwerke.
Teilnehmer bewerten S+P Seminare auf ProvenExpert mit 4,65 von 5 Sternen. Für jedes gebuchte Seminar pflanzt S+P im Rahmen des ESG-Projekts „Dein Seminar, dein Baum, deine Zukunft“ einen Baum in Deutschland.
Mehr Informationen unter: www.sp-unternehmerforum.de
Datei-Anlagen:
(47 kB)
1616929.attachment
Compliance Trap 2026: why the new transparency register is only the tip of the iceberg for Swiss CEOs — D&O liability, AMLA duties and 24-hour cyber reporting explained.
- Mehr Infos zu dieser Meldung unter www.pressebox.de
- zurück zur Übersicht















