Steps 6 to 9 — Assess and score
8 min read
Step 6 — Assess Opportunity
Objective: Assign a quantitative score to the opportunity for fraud for each identified vulnerability, using the sub-factors defined in section 5.1.
Activities:
- For each vulnerability identified in Step 5, assess the four opportunity
sub-factors using the tables in section 5.1:
- O1: Availability of and access to substitutes or adulterants
- O2: Supply chain complexity
- O3: Ease of adulteration without detection
- O4: Transaction volume and mode
- Assign a score from 1 to 5 for each sub-factor based on the descriptors in section 5.1.
- Calculate the Opportunity score: O = (O1 + O2 + O3 + O4) / 4
- Document the justification for each score assigned, including the evidence considered.
Outputs: An O score for each vulnerability, with documented justification.
Recommendations:
- Assess each sub-factor independently before calculating the average.
- Where there is uncertainty between two levels, apply the precautionary principle and assign the higher level.
- Assessments must be based on evidence (intelligence data, specifications, audits) and not on opinion alone.
Step 7 — Assess Motivation
Objective: Assign a quantitative score to the motivation for fraud for each vulnerability, using the sub-factors defined in section 5.2.
Activities:
- For each vulnerability, assess the four motivation sub-factors using the
tables in section 5.2:
- M1: Economic value and profit margin of the fraud
- M2: Documented history of fraud
- M3: Economic pressures in the sector or region of origin
- M4: Regulatory and compliance environment
- Assign a score from 1 to 5 for each sub-factor.
- Calculate the Motivation score: M = (M1 + M2 + M3 + M4) / 4
- Document the justification with reference to the intelligence sources consulted in Step 4.
Outputs: An M score for each vulnerability, with documented justification.
Recommendations:
- The assessment of M3 and M4 may be carried out at country/region of origin level and reused for all ingredients coming from the same region.
- Update the motivation scores when significant changes in prices, availability or geopolitical conditions are detected.
Step 8 — Assess Countermeasures
Objective: Assign a quantitative score to the existing countermeasures for each vulnerability, using the sub-factors defined in section 5.3.
Activities:
- For each vulnerability, assess the four countermeasure sub-factors using the
tables in section 5.3:
- C1: Supplier verification and audit programme
- C2: Analytical and testing capability
- C3: Traceability system
- C4: Organisational culture and governance
- Assign a score from 1 to 5 for each sub-factor.
- Calculate the Countermeasures score: C = (C1 + C2 + C3 + C4) / 4
- Document the evidence for each countermeasure assessed (procedures, records, audit results).
Outputs: A C score for each vulnerability, with documented evidence.
Recommendations:
- Be rigorous and honest in the assessment: score the countermeasures as they are actually implemented, not as they ought to be.
- Verify that the countermeasures assessed are genuinely active and working, not merely documented.
- Countermeasures that are not specific to food fraud (e.g. routine quality tests) may contribute, but will generally receive a lower score than countermeasures designed specifically to detect fraud.
Step 9 — Calculate the overall vulnerability and classify
Objective: Calculate the overall vulnerability score for each identified vulnerability and classify it according to its level of significance.
Activities:
a) For each vulnerability, calculate the overall vulnerability score:
V = (O × M) / C
The theoretical range of V is 0.20 (minimum: O=1, M=1, C=5) to 25.00 (maximum: O=5, M=5, C=1).
b) Classify each vulnerability according to the following table of levels:
| V level | V range | Colour | Required action |
|---|---|---|---|
| Low | V < 2.0 | 🟢 Green | Routine monitoring. Document and review at the next periodic assessment. No additional specific mitigation measures are required. |
| Medium | 2.0 ≤ V < 5.0 | 🟡 Yellow | Increased attention. Assess whether the current countermeasures are sufficient. Consider additional mitigation measures. Review within no more than 6 months. |
| High | 5.0 ≤ V < 10.0 | 🟠 Orange | Significant vulnerability. Specific mitigation measures and a VCCP must be established. Implement within no more than 3 months. |
| Critical | V ≥ 10.0 | 🔴 Red | Critical vulnerability. Immediate action required. Implement emergency mitigation measures and establish a VCCP. Consider temporarily suspending supply until adequate controls are in place. |
c) Record all scores in the vulnerability assessment matrix (see Appendix D).
Outputs:
- Complete vulnerability assessment matrix with O, M, C and V scores.
- Vulnerability level classification for each item assessed.
- List of significant (V ≥ 5.0) and critical (V ≥ 10.0) vulnerabilities.
Calculation example:
| Ingredient | O1 | O2 | O3 | O4 | O | M1 | M2 | M3 | M4 | M | C1 | C2 | C3 | C4 | C | V | Level |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Honey | 5 | 4 | 4 | 3 | 4.0 | 4 | 5 | 3 | 3 | 3.8 | 3 | 2 | 3 | 3 | 2.8 | 5.4 | 🟠 High |
| Extra virgin olive oil | 4 | 3 | 3 | 4 | 3.5 | 5 | 5 | 3 | 2 | 3.8 | 4 | 4 | 4 | 3 | 3.8 | 3.5 | 🟡 Medium |
| Refined salt | 1 | 1 | 1 | 2 | 1.3 | 1 | 1 | 1 | 1 | 1.0 | 3 | 3 | 3 | 3 | 3.0 | 0.4 | 🟢 Low |
Recommendations:
- The significance threshold (V ≥ 5.0) is the recommended default value. The organisation may adjust this threshold downwards (more conservative), but adjusting it upwards is not recommended.
- For vulnerabilities falling close to the threshold (e.g. V = 4.5 – 5.5), apply the decision tree in Appendix C as a supplementary criterion.
- Always document the justification whenever the default threshold is modified.
Calculating on a case of your own
The three presets are the ingredients from the example above, with their twelve scores. Change them and watch how V moves.
Honey: sugar syrup adulteration is widely documented and hive-level traceability is limited.
Honey and extra virgin olive oil start from an identical motivation (3.8 for both): the economic incentive to adulterate them is equivalent. What separates one from the other is the countermeasures, 2.8 against 3.8, and that difference of a single point is what pushes honey above the significance threshold. It is the practical consequence of C being a divisor: you cannot act on a fraudster's motivation, but you can act on your own countermeasures.
The book in other formats
Reading online is complete and free, and so is the PDF. If you would like to support the work, the book is on Amazon.