Scope and normative references

4 min read

1.1 Applicability

This guide applies to all organisations in the food chain, regardless of their size, geographical location or category, including but not limited to:

  • Food manufacturing and processing (FSSC 22000 categories CI, CII, CIII, CIV)
  • Manufacture of food packaging materials (category I)
  • Primary production (category B)
  • Transport and storage (category G)
  • Food service and catering (category E)
  • Animal feed (category D)
  • Distribution and retail (categories FI, FII)
  • Provision of services (category K)

1.2 Purpose

The purpose of this guide is to provide a methodology to:

  1. Identify vulnerabilities to food fraud in the products, ingredients, materials and processes within the organisation's scope;
  2. Quantitatively assess those vulnerabilities using a three-dimensional model (Opportunity, Motivation, Countermeasures);
  3. Determine significant vulnerabilities and Vulnerability Critical Control Points (VCCPs);
  4. Develop, implement and maintain a food fraud mitigation plan; and
  5. Establish mechanisms for verification, periodic review and continual improvement.

1.3 Exclusions

This guide does not address:

  • Unintentional food safety hazards → covered by HACCP (Codex Alimentarius).
  • Intentional threats motivated by ideology or the intent to cause harm → covered by TACCP/Food Defense (PAS 96, FSSC 22000).
  • Country-specific regulatory aspects → the organisation must supplement this guide with the legislation applicable in its jurisdiction.

1.4 Relationship with other systems

SystemFocusMotivationMain reference
HACCPFood safetyUnintentional (hazards)Codex Alimentarius
TACCPFood defenceIntentional — to cause harmPAS 96
VACCPFood fraudIntentional — economic gainBVF (this guide)

The three systems are complementary and must coexist within the organisation's Food Safety Management System (FSMS). Separate assessments for each system are recommended, as they address fundamentally different motivations.

2. Normative references

The following documents are referenced in this guide. For dated references, only the cited edition applies. For undated references, the latest edition of the referenced document applies.

  • ISO 22000:2018 — Food safety management systems — Requirements for any organization in the food chain.
  • ISO 31000:2018 — Risk management — Guidelines.
  • FSSC 22000 — Certification Scheme for Food Safety Management Systems, Part 2, Requirement 2.5.4 (Food Fraud Mitigation).
  • GFSI Benchmarking Requirements Version 2024 — Requirements for food safety management systems, Food Fraud.
  • GFSI Food Fraud Technical Document — Technical document on food fraud prevention through food safety management systems.
  • SSAFE Food Fraud Vulnerability Assessment Tool — Food fraud vulnerability assessment tool developed by SSAFE in collaboration with VU Amsterdam, PwC and GFSI.
  • Codex Alimentarius — General Principles of Food Hygiene (CXC 1-1969, Rev. 2020).
  • PAS 96:2017 — Guide to protecting and defending food and drink from deliberate attack (comparative reference for TACCP).
How to cite this chapterMunguia, I. (2026). Scope and normative references. En Beira VACCP Framework (v1.0). Beira Consultores. https://beiratraining.com/en/bvf/alcance-y-referencias-normativasComments and suggestions: bvf@beira.com.mx