Steps 10 to 12 — Mitigate and verify

9 min read

Step 10 — Determine significant vulnerabilities and VCCPs

Objective: Confirm the significant vulnerabilities using the decision tree and determine the Vulnerability Critical Control Points (VCCPs).

Activities:

a) For each vulnerability with V ≥ 5.0, apply the decision tree in Appendix C to confirm whether a VCCP is required:

Decision tree for determining a VCCP
Q1: Is the overall vulnerability score V ≥ 5.0?
  │
  ├── NO → Not a significant vulnerability.
  │         Document and monitor at the periodic review.
  │         END.
  │
  └── YES → Continue to Q2.

Q2: Is there at least one mitigation measure already implemented
  that is specific to this vulnerability?
  │
  ├── NO → A VCCP is required.
  │         Go to Step 11 to design mitigation measures.
  │
  └── YES → Continue to Q3.

Q3: Is the existing mitigation measure verifiable
  (does it have measurable performance criteria and is it monitored)?
  │
  ├── NO → A VCCP is required.
  │         Formalise the existing measure as a VCCP with
  │         performance criteria and monitoring.
  │
  └── YES → Continue to Q4.

Q4: Has the existing mitigation measure been shown to be
  effective (evidence of operation over the last 12 months)?
  │
  ├── NO → A VCCP is required.
  │         Review and strengthen the existing measure.
  │         Establish it as a VCCP with reinforced monitoring.
  │
  └── YES → It is a VCCP that is already managed.
            Formally document it as a VCCP in the mitigation
            plan. Maintain monitoring and verification.
            END.

Answer the four questions for your own vulnerability:

ToolVCCP decision tree
p1

Is the overall vulnerability score V ≥ 5.0?

b) Document the result of the decision tree for each significant vulnerability.

c) Assign a unique code to each VCCP (e.g. VCCP-001, VCCP-002, …).

Outputs:

  • List of VCCPs determined, with their codes.
  • Record of the decision tree applied to each significant vulnerability.

Recommendations:

  • Not all VCCPs require the same measures. A VCCP at "ingredient receipt" may require analytical testing, while a VCCP at "supplier selection" may require audits.
  • When a vulnerability has V ≥ 10.0 (critical), the VCCP is established automatically, without the need to apply the full decision tree.
  • Limiting the number of VCCPs to those that are genuinely critical is recommended in order to keep the system manageable. If there are too many VCCPs, assess whether the general countermeasures can be strengthened so as to reduce the vulnerability of several items at once.

Step 11 — Develop the mitigation plan

Objective: Design and implement specific mitigation measures for each VCCP and significant vulnerability, documented in a formal plan.

Activities:

a) For each VCCP, define:

Plan elementDescription
VCCP codeUnique identifier (e.g. VCCP-001)
Associated vulnerabilityReference to the vulnerability in the assessment matrix
Product / ingredientItem affected
Type of fraudType(s) of fraud being mitigated
Preventive mitigation measuresActions to prevent the fraud from occurring
Detective mitigation measuresActions to identify the fraud if it occurs
Corrective mitigation measuresActions to be taken if the fraud is confirmed
Performance criteriaMeasurable parameters indicating that the measure works
Monitoring methodHow compliance with the criteria is verified
Monitoring frequencyHow often monitoring is carried out
Person responsiblePerson or function responsible for implementation and monitoring
RecordsDocuments and records generated
Implementation dateDeadline for implementation

b) Classify the mitigation measures by type:

Preventive measures (before the fraud):

  • Supplier approval and audit programmes.
  • Contractual agreements with anti-fraud clauses.
  • Diversification of suppliers for critical ingredients.
  • Verification of certifications and authenticity of documents.
  • Staff training and awareness.

Detective measures (during or after the fraud):

  • Analytical authenticity testing on receipt.
  • Mass balance and inventory reconciliation.
  • Monitoring of prices and market anomalies.
  • Random and unannounced sampling.
  • Review of documentation and consistency of certificates.

Corrective measures (response to the fraud):

  • Procedure for holding and quarantining suspect product.
  • Internal investigation protocol.
  • Procedure for notifying authorities and customers.
  • Change or suspension of supplier.
  • Review and strengthening of countermeasures.

c) Assign implementation priority based on the level of vulnerability:

  • Critical (V ≥ 10.0): Immediate implementation (30 days maximum).
  • High (5.0 ≤ V < 10.0): Implementation within 90 days maximum.

d) Obtain formal approval of the plan from top management.

Outputs:

  • Documented and approved food fraud mitigation plan (see Appendix E for the template).
  • Implementation schedule.
  • Allocation of resources.

Recommendations:

  • Mitigation measures must be proportionate to the level of vulnerability identified.
  • Always combine preventive measures with detective measures (defence in depth).
  • Consider the cost-benefit of the measures, but do not use cost as an excuse for failing to implement necessary measures on critical vulnerabilities.
  • Review the consistency of the mitigation plan with the HACCP plan and the Food Defense plan, to avoid duplication and take advantage of synergies.

Step 12 — Verification, review and continual improvement

Objective: Ensure that the VACCP system remains effective, up to date and aligned with changes in the organisation and its environment.

Verification activities (ongoing):

a) Periodically verify that the mitigation measures are implemented as planned:

  • Review of monitoring records
  • Internal audits of the VACCP system (at least annually)
  • Analytical verification testing
  • Evaluation of the effectiveness of training

b) Include the VACCP system in the FSMS internal audit programme.

Scheduled periodic review:

c) Carry out a full review of the vulnerability assessment at the following minimum frequency:

ElementMinimum frequency
Intelligence reportSix-monthly
Vulnerability scoresAnnual
Complete mitigation planAnnual
Effectiveness of the mitigation measuresAnnual
Scope of the assessmentAnnual, or whenever the scope of the FSMS changes

Reassessment triggers (unscheduled):

d) Initiate a partial or full reassessment whenever any of the following events occurs:

  • Introduction of new ingredients, raw materials or suppliers.
  • Change of supplier for an existing ingredient.
  • A relevant food fraud alert in databases or the media.
  • A food fraud incident detected (internally or in the sector).
  • Significant changes in the prices or availability of key ingredients.
  • Relevant regulatory changes.
  • Audit results identifying weaknesses.
  • Changes in the structure of the supply chain.
  • Geopolitical events affecting regions of origin.
  • Significant organisational changes (mergers, acquisitions, restructuring).
  • Anomalous results in analytical testing.

Continual improvement:

e) Incorporate the results of the verifications and reviews into the improvement of the system:

  • Update vulnerability scores in the light of new evidence.
  • Strengthen mitigation measures wherever weaknesses are detected.
  • Incorporate new technologies and detection methods as they become available.
  • Share lessons learned with the team and the organisation.

f) Include the key indicators of the VACCP system in the management review:

  • Number of significant vulnerabilities and how they are evolving.
  • Status of implementation of the mitigation plan.
  • Verification and audit results.
  • Fraud incidents detected or suspected.
  • Changes in the risk profile of the supply chain.

Outputs:

  • Verification reports.
  • Minutes of the periodic review with decisions and actions.
  • Updated vulnerability assessments.
  • Updated mitigation plan.
  • Input data for the management review.
How to cite this chapterMunguia, I. (2026). Steps 10 to 12 — Mitigate and verify. En Beira VACCP Framework (v1.0). Beira Consultores. https://beiratraining.com/en/bvf/pasos-10-12-mitigar-y-verificarComments and suggestions: bvf@beira.com.mx