Steps 1 to 5 — Prepare the assessment

12 min read

The implementation of this methodology is carried out in 12 sequential steps. Each step is described with its objective, the required activities, the expected outputs and practical recommendations.

8. The 12 steps of the VACCP methodology

Step 1 — Form the VACCP team

Objective: Appoint a multidisciplinary team with the competences needed to carry out the vulnerability assessment and manage the mitigation plan.

Activities:

  1. Top management formally appoints the VACCP team and its leader.
  2. The team includes, as a minimum, representatives of the following functions:
    • Food safety / Quality — Knowledge of hazards, controls and management systems.
    • Purchasing / Supply chain — Knowledge of suppliers, markets and logistics.
    • Production / Operations — Knowledge of processes, products and materials.
    • Laboratory / Analytical (where applicable) — Detection capability and testing methods.
    • Regulatory / Legal (where applicable) — Legal requirements and consequences.
  3. The team may include external experts where specialised competence is required (e.g. food criminology, intelligence analysis, advanced analytical methods).
  4. The roles, responsibilities and competences of each member are documented.
  5. All members receive training on food fraud, on this methodology and on the intelligence sources available.

Outputs:

  • Document appointing the VACCP team.
  • Record of the members' competences and training.

Recommendations:

  • The team should meet at least quarterly and whenever a reassessment trigger occurs.
  • The VACCP team leader is recommended to be a different person from the HACCP team leader, although they may share members.
  • In small organisations, one person may cover several functions provided they have the necessary competences.

Step 2 — Define the scope of the assessment

Objective: Clearly delimit which products, ingredients, materials, processes and supply chain elements will be assessed.

Activities:

  1. Define the product categories and production lines included in the assessment.
  2. Identify all ingredients, raw materials, packaging materials, processing aids and outsourced services within the scope.
  3. Define the boundaries of the supply chain to be assessed (from which point to which point).
  4. Document the exclusions and their justification.
  5. Where the number of products, ingredients or materials within the scope is high (as a guide, > 50 items), apply the grouping criteria by vulnerability category described below.

Outputs:

  • Scope statement for the vulnerability assessment.
  • Master list of materials, ingredients and services within the scope.
  • Where applicable: table of vulnerability categories with grouping criteria and justification.

Recommendations:

  • The scope must be consistent with the scope of the organisation's FSMS (ISO 22000 / FSSC 22000).
  • Do not exclude materials or ingredients "on grounds of low volume" without a documented justification based on risk analysis.
  • Also consider primary packaging materials that could be the object of fraud (e.g. labels, authenticity seals).
  • For organisations in retail, warehousing and logistics, distribution, food service and similar sectors that handle an extensive portfolio, assessment by vulnerability category is not a shortcut: it is the only practical and scientifically valid way to keep a VACCP system working.

Assessment by vulnerability category — Criteria for operations with an extensive portfolio

Context and rationale:

Product-by-product assessment is feasible when the organisation handles a limited portfolio of ingredients/materials (typically < 50 items). Many links in the food chain, however, operate with portfolios that make this approach unworkable:

Type of operationTypical volumeExample
Retail / Supermarkets5,000 – 40,000 SKUsSupermarket chain with own-label and multi-brand products
Warehousing and distribution (3PL)500 – 10,000 SKUsLogistics operator for dry and chilled goods
Food service / HORECA200 – 2,000 itemsIndustrial catering company or restaurant chain
Trading / Importers100 – 5,000 itemsSpecialist ingredient distributor
Multi-site / multi-line manufacturer50 – 500 ingredientsDiversified processed food company

For these cases, this guide establishes an approach of assessment by vulnerability category, grounded in the principle that products or ingredients with a similar vulnerability profile (same likely type of fraud, same supply chain complexity, same range of economic value and same applicable countermeasures) may be grouped and assessed as a single unit, assigning all members of the group the same score.

This approach is consistent with:

  • The principle of risk equivalence of ISO 31000: elements with comparable risk profiles may be managed as a group.
  • The SSAFE tool, which allows assessment by product family.
  • Accepted practice in FSSC 22000, where the guidance document states that the assessment may be carried out "by ingredient category" where justified.

Grouping criteria: Grouping is valid when the items share all of the following criteria within the same category:

#Grouping criterionDescriptionExample
1Nature / product familySame taxonomic or technological familyVegetable oils, UHT dairy, ground spices
2Applicable type(s) of fraudThe same types of fraud are plausibleAll susceptible to substitution and dilution
3Supply chain profileSimilar complexity, geography and number of intermediariesAll imported from the same region, same number of links
4Range of economic valueUnit value within the same order of magnitudeAll between $5-$20 USD/kg
5Common countermeasuresThe same receiving and verification controls applySame testing protocols, same type of supplier certification

Grouping procedure:

a) From the master scope list (Step 2), group the items that meet all the above criteria into vulnerability categories.

b) Assign a descriptive name and a code to each category (e.g. CVA-01 "Imported vegetable oils", CVA-02 "Ground spices and seasonings").

c) For each category, designate a representative item (the one with the highest risk profile within the group), which will be assessed in detail in Steps 6-9. The resulting score applies to the whole category.

d) Document the following in the grouping table:

Category codeNameRepresentative item# items groupedCriteria met (1-5)Justification
CVA-01Imported vegetable oilsExtra virgin olive oil121,2,3,4,5All vegetable oils imported from the Mediterranean basin, value $8-$18/kg, susceptible to substitution, same receiving controls
CVA-02Ground spicesTurmeric powder241,2,3,4,5All ground spices imported from Asia, susceptible to addition and substitution, same testing protocols
individualHoneyHoney1N/AIndividual assessment: unique vulnerability profile, cannot be grouped
  1. Items that do not meet all the grouping criteria for any category must be assessed individually.

  2. Items of exceptionally high value, with a documented history of fraud or subject to active alerts must always be assessed individually, regardless of whether they meet the grouping criteria.

Individual escalation rule:

If, during the assessment of the category (Steps 6-9), the vulnerability score V of the representative item comes out at ≥ 5.0 (significant vulnerability), all items in that category must be reassessed to confirm that the grouping remains valid. In case of doubt, the highest-risk items within the group must be escalated to individual assessment.

Benefits of the approach:

  • Reduces the number of detailed assessments from hundreds/thousands to typically 15-40 categories.
  • Maintains scientific rigour by assessing the highest-risk item in each group.
  • Makes the VACCP system easier to maintain and update.
  • Is auditable: the justification for the grouping is documented.

Limitations and safeguards:

  • Grouping is not a reduction of the scope: all items remain within the scope; only the unit of assessment changes.
  • The individual escalation rule ensures that significant vulnerabilities are not diluted within a category.
  • The VACCP team must review the validity of the groupings at least annually or whenever the portfolio changes.

Step 3 — Describe products and map the supply chain

Objective: Gather the detailed information needed about each product, ingredient and the supply chain in order to carry out an informed assessment.

Activities:

a) For each product/ingredient/material (or vulnerability category) within the scope, document:

  • Description and specifications
  • Country/region of origin
  • Current and alternative supplier(s)
  • Number of known intermediaries
  • Mode of transport and storage
  • Annual purchase volume and economic value
  • Current receiving control method
  • Supplier certifications (GFSI, organic, etc.)

b) Produce a visual map of the supply chain for the ingredients and materials of highest value or complexity, identifying:

  • All known links from origin to receipt
  • Transfer points where custody of the product changes
  • Mixing or co-processing points

Outputs:

  • Product/ingredient/material sheets (or a sheet per vulnerability category).
  • Supply chain map(s).

Recommendations:

  • Actively involve the purchasing department in this step.
  • For high-value ingredients, ask the supplier for information about their own supply chain (upstream traceability).
  • Update the maps whenever suppliers or supply routes change.
  • When using the category-based approach, produce the sheet for the representative item and verify that it is reasonably representative of the group.

Step 4 — Gather food fraud intelligence

Objective: Collect up-to-date information on incidents, trends and emerging threats of food fraud relevant to the products and ingredients within the scope.

Activities:

a) Consult the following intelligence sources for each product/ingredient (or vulnerability category):

SourceTypeAccess
HorizonScan (Fera Science)Global food fraud incident databaseSubscription
RASFF (European Commission)Rapid Alert System for Food and FeedPublic
USP Food Fraud DatabaseIngredient adulteration database (U.S. Pharmacopeia)Public (partial)
FDA Economically Motivated AdulterationReports and guidance on EMAPublic
Food Fraud Prevention Think Tank (MSU)Research and primers on food fraudPublic (partial)

b) Document the relevant findings for each product/ingredient:

  • Historical fraud incidents (type, date, region, substance)
  • Price and availability trends
  • Active alerts
  • Relevant regulatory changes

c) Assess the credibility and relevance of each information source.

Outputs:

  • Food fraud intelligence report (kept up to date).
  • Record of the sources consulted and the date of consultation.

Recommendations:

  • Establish a process of continuous intelligence monitoring (not only at the time of the assessment).
  • Designate a team member as responsible for intelligence monitoring.
  • Subscribe to automatic alerts from the main sources (RASFF, HorizonScan).
  • The minimum updating frequency for the intelligence report should be six-monthly.

Step 5 — Identify vulnerabilities

Objective: Systematically identify all potential food fraud vulnerabilities for each product, ingredient, material, vulnerability category or process within the scope.

Activities:

a) For each item within the scope, the VACCP team identifies:

  • The applicable types of fraud (see section 6), considering the nature of the product/ingredient.
  • The points in the supply chain where each type of fraud could occur.
  • The potential actors who could commit the fraud.

b) Use the following identification matrix:

#12
Product / IngredientExample: HoneyExample: Extra virgin olive oil
Applicable type of fraudAddition (dilution)Substitution
Vulnerable point in the chainSupplier / intermediarySupplier
Potential adulterant / methodHigh-fructose corn syrupSunflower / soybean oil
Source of evidenceHorizonScan, historyRASFF, USP FFD

c) Do not rule out vulnerabilities at this stage. Prioritisation is carried out in steps 6-9.

Outputs:

  • Complete vulnerability identification matrix.
  • List of all potential vulnerabilities identified.

Recommendations:

  • Hold structured brainstorming sessions with the full VACCP team.
  • Consider the principle of "thinking like a fraudster": if I wanted to commit fraud with this product, how would I do it?
  • Include both internal vulnerabilities (own staff, processes) and external ones (suppliers, logistics).
  • When using the vulnerability category approach, identification is carried out on the representative item of each category. Verify that the types of fraud identified are reasonably applicable to all items in the group.
How to cite this chapterMunguia, I. (2026). Steps 1 to 5 — Prepare the assessment. En Beira VACCP Framework (v1.0). Beira Consultores. https://beiratraining.com/en/bvf/pasos-1-5-preparar-la-evaluacionComments and suggestions: bvf@beira.com.mx