Steps 1 to 5 — Prepare the assessment
12 min read
The implementation of this methodology is carried out in 12 sequential steps. Each step is described with its objective, the required activities, the expected outputs and practical recommendations.
8. The 12 steps of the VACCP methodology
Step 1 — Form the VACCP team
Objective: Appoint a multidisciplinary team with the competences needed to carry out the vulnerability assessment and manage the mitigation plan.
Activities:
- Top management formally appoints the VACCP team and its leader.
- The team includes, as a minimum, representatives of the following functions:
- Food safety / Quality — Knowledge of hazards, controls and management systems.
- Purchasing / Supply chain — Knowledge of suppliers, markets and logistics.
- Production / Operations — Knowledge of processes, products and materials.
- Laboratory / Analytical (where applicable) — Detection capability and testing methods.
- Regulatory / Legal (where applicable) — Legal requirements and consequences.
- The team may include external experts where specialised competence is required (e.g. food criminology, intelligence analysis, advanced analytical methods).
- The roles, responsibilities and competences of each member are documented.
- All members receive training on food fraud, on this methodology and on the intelligence sources available.
Outputs:
- Document appointing the VACCP team.
- Record of the members' competences and training.
Recommendations:
- The team should meet at least quarterly and whenever a reassessment trigger occurs.
- The VACCP team leader is recommended to be a different person from the HACCP team leader, although they may share members.
- In small organisations, one person may cover several functions provided they have the necessary competences.
Step 2 — Define the scope of the assessment
Objective: Clearly delimit which products, ingredients, materials, processes and supply chain elements will be assessed.
Activities:
- Define the product categories and production lines included in the assessment.
- Identify all ingredients, raw materials, packaging materials, processing aids and outsourced services within the scope.
- Define the boundaries of the supply chain to be assessed (from which point to which point).
- Document the exclusions and their justification.
- Where the number of products, ingredients or materials within the scope is high (as a guide, > 50 items), apply the grouping criteria by vulnerability category described below.
Outputs:
- Scope statement for the vulnerability assessment.
- Master list of materials, ingredients and services within the scope.
- Where applicable: table of vulnerability categories with grouping criteria and justification.
Recommendations:
- The scope must be consistent with the scope of the organisation's FSMS (ISO 22000 / FSSC 22000).
- Do not exclude materials or ingredients "on grounds of low volume" without a documented justification based on risk analysis.
- Also consider primary packaging materials that could be the object of fraud (e.g. labels, authenticity seals).
- For organisations in retail, warehousing and logistics, distribution, food service and similar sectors that handle an extensive portfolio, assessment by vulnerability category is not a shortcut: it is the only practical and scientifically valid way to keep a VACCP system working.
Assessment by vulnerability category — Criteria for operations with an extensive portfolio
Context and rationale:
Product-by-product assessment is feasible when the organisation handles a limited portfolio of ingredients/materials (typically < 50 items). Many links in the food chain, however, operate with portfolios that make this approach unworkable:
| Type of operation | Typical volume | Example |
|---|---|---|
| Retail / Supermarkets | 5,000 – 40,000 SKUs | Supermarket chain with own-label and multi-brand products |
| Warehousing and distribution (3PL) | 500 – 10,000 SKUs | Logistics operator for dry and chilled goods |
| Food service / HORECA | 200 – 2,000 items | Industrial catering company or restaurant chain |
| Trading / Importers | 100 – 5,000 items | Specialist ingredient distributor |
| Multi-site / multi-line manufacturer | 50 – 500 ingredients | Diversified processed food company |
For these cases, this guide establishes an approach of assessment by vulnerability category, grounded in the principle that products or ingredients with a similar vulnerability profile (same likely type of fraud, same supply chain complexity, same range of economic value and same applicable countermeasures) may be grouped and assessed as a single unit, assigning all members of the group the same score.
This approach is consistent with:
- The principle of risk equivalence of ISO 31000: elements with comparable risk profiles may be managed as a group.
- The SSAFE tool, which allows assessment by product family.
- Accepted practice in FSSC 22000, where the guidance document states that the assessment may be carried out "by ingredient category" where justified.
Grouping criteria: Grouping is valid when the items share all of the following criteria within the same category:
| # | Grouping criterion | Description | Example |
|---|---|---|---|
| 1 | Nature / product family | Same taxonomic or technological family | Vegetable oils, UHT dairy, ground spices |
| 2 | Applicable type(s) of fraud | The same types of fraud are plausible | All susceptible to substitution and dilution |
| 3 | Supply chain profile | Similar complexity, geography and number of intermediaries | All imported from the same region, same number of links |
| 4 | Range of economic value | Unit value within the same order of magnitude | All between $5-$20 USD/kg |
| 5 | Common countermeasures | The same receiving and verification controls apply | Same testing protocols, same type of supplier certification |
Grouping procedure:
a) From the master scope list (Step 2), group the items that meet all the above criteria into vulnerability categories.
b) Assign a descriptive name and a code to each category (e.g. CVA-01 "Imported vegetable oils", CVA-02 "Ground spices and seasonings").
c) For each category, designate a representative item (the one with the highest risk profile within the group), which will be assessed in detail in Steps 6-9. The resulting score applies to the whole category.
d) Document the following in the grouping table:
| Category code | Name | Representative item | # items grouped | Criteria met (1-5) | Justification |
|---|---|---|---|---|---|
| CVA-01 | Imported vegetable oils | Extra virgin olive oil | 12 | 1,2,3,4,5 | All vegetable oils imported from the Mediterranean basin, value $8-$18/kg, susceptible to substitution, same receiving controls |
| CVA-02 | Ground spices | Turmeric powder | 24 | 1,2,3,4,5 | All ground spices imported from Asia, susceptible to addition and substitution, same testing protocols |
| individual | Honey | Honey | 1 | N/A | Individual assessment: unique vulnerability profile, cannot be grouped |
-
Items that do not meet all the grouping criteria for any category must be assessed individually.
-
Items of exceptionally high value, with a documented history of fraud or subject to active alerts must always be assessed individually, regardless of whether they meet the grouping criteria.
Individual escalation rule:
If, during the assessment of the category (Steps 6-9), the vulnerability score V of the representative item comes out at ≥ 5.0 (significant vulnerability), all items in that category must be reassessed to confirm that the grouping remains valid. In case of doubt, the highest-risk items within the group must be escalated to individual assessment.
Benefits of the approach:
- Reduces the number of detailed assessments from hundreds/thousands to typically 15-40 categories.
- Maintains scientific rigour by assessing the highest-risk item in each group.
- Makes the VACCP system easier to maintain and update.
- Is auditable: the justification for the grouping is documented.
Limitations and safeguards:
- Grouping is not a reduction of the scope: all items remain within the scope; only the unit of assessment changes.
- The individual escalation rule ensures that significant vulnerabilities are not diluted within a category.
- The VACCP team must review the validity of the groupings at least annually or whenever the portfolio changes.
Step 3 — Describe products and map the supply chain
Objective: Gather the detailed information needed about each product, ingredient and the supply chain in order to carry out an informed assessment.
Activities:
a) For each product/ingredient/material (or vulnerability category) within the scope, document:
- Description and specifications
- Country/region of origin
- Current and alternative supplier(s)
- Number of known intermediaries
- Mode of transport and storage
- Annual purchase volume and economic value
- Current receiving control method
- Supplier certifications (GFSI, organic, etc.)
b) Produce a visual map of the supply chain for the ingredients and materials of highest value or complexity, identifying:
- All known links from origin to receipt
- Transfer points where custody of the product changes
- Mixing or co-processing points
Outputs:
- Product/ingredient/material sheets (or a sheet per vulnerability category).
- Supply chain map(s).
Recommendations:
- Actively involve the purchasing department in this step.
- For high-value ingredients, ask the supplier for information about their own supply chain (upstream traceability).
- Update the maps whenever suppliers or supply routes change.
- When using the category-based approach, produce the sheet for the representative item and verify that it is reasonably representative of the group.
Step 4 — Gather food fraud intelligence
Objective: Collect up-to-date information on incidents, trends and emerging threats of food fraud relevant to the products and ingredients within the scope.
Activities:
a) Consult the following intelligence sources for each product/ingredient (or vulnerability category):
| Source | Type | Access |
|---|---|---|
| HorizonScan (Fera Science) | Global food fraud incident database | Subscription |
| RASFF (European Commission) | Rapid Alert System for Food and Feed | Public |
| USP Food Fraud Database | Ingredient adulteration database (U.S. Pharmacopeia) | Public (partial) |
| FDA Economically Motivated Adulteration | Reports and guidance on EMA | Public |
| Food Fraud Prevention Think Tank (MSU) | Research and primers on food fraud | Public (partial) |
b) Document the relevant findings for each product/ingredient:
- Historical fraud incidents (type, date, region, substance)
- Price and availability trends
- Active alerts
- Relevant regulatory changes
c) Assess the credibility and relevance of each information source.
Outputs:
- Food fraud intelligence report (kept up to date).
- Record of the sources consulted and the date of consultation.
Recommendations:
- Establish a process of continuous intelligence monitoring (not only at the time of the assessment).
- Designate a team member as responsible for intelligence monitoring.
- Subscribe to automatic alerts from the main sources (RASFF, HorizonScan).
- The minimum updating frequency for the intelligence report should be six-monthly.
Step 5 — Identify vulnerabilities
Objective: Systematically identify all potential food fraud vulnerabilities for each product, ingredient, material, vulnerability category or process within the scope.
Activities:
a) For each item within the scope, the VACCP team identifies:
- The applicable types of fraud (see section 6), considering the nature of the product/ingredient.
- The points in the supply chain where each type of fraud could occur.
- The potential actors who could commit the fraud.
b) Use the following identification matrix:
| # | 1 | 2 |
|---|---|---|
| Product / Ingredient | Example: Honey | Example: Extra virgin olive oil |
| Applicable type of fraud | Addition (dilution) | Substitution |
| Vulnerable point in the chain | Supplier / intermediary | Supplier |
| Potential adulterant / method | High-fructose corn syrup | Sunflower / soybean oil |
| Source of evidence | HorizonScan, history | RASFF, USP FFD |
c) Do not rule out vulnerabilities at this stage. Prioritisation is carried out in steps 6-9.
Outputs:
- Complete vulnerability identification matrix.
- List of all potential vulnerabilities identified.
Recommendations:
- Hold structured brainstorming sessions with the full VACCP team.
- Consider the principle of "thinking like a fraudster": if I wanted to commit fraud with this product, how would I do it?
- Include both internal vulnerabilities (own staff, processes) and external ones (suppliers, logistics).
- When using the vulnerability category approach, identification is carried out on the representative item of each category. Verify that the types of fraud identified are reasonably applicable to all items in the group.
The book in other formats
Reading online is complete and free, and so is the PDF. If you would like to support the work, the book is on Amazon.