Steps 6 to 9 — Assess and score

8 min read

Step 6 — Assess Opportunity

Objective: Assign a quantitative score to the opportunity for fraud for each identified vulnerability, using the sub-factors defined in section 5.1.

Activities:

  1. For each vulnerability identified in Step 5, assess the four opportunity sub-factors using the tables in section 5.1:
    • O1: Availability of and access to substitutes or adulterants
    • O2: Supply chain complexity
    • O3: Ease of adulteration without detection
    • O4: Transaction volume and mode
  2. Assign a score from 1 to 5 for each sub-factor based on the descriptors in section 5.1.
  3. Calculate the Opportunity score: O = (O1 + O2 + O3 + O4) / 4
  4. Document the justification for each score assigned, including the evidence considered.

Outputs: An O score for each vulnerability, with documented justification.

Recommendations:

  • Assess each sub-factor independently before calculating the average.
  • Where there is uncertainty between two levels, apply the precautionary principle and assign the higher level.
  • Assessments must be based on evidence (intelligence data, specifications, audits) and not on opinion alone.

Step 7 — Assess Motivation

Objective: Assign a quantitative score to the motivation for fraud for each vulnerability, using the sub-factors defined in section 5.2.

Activities:

  1. For each vulnerability, assess the four motivation sub-factors using the tables in section 5.2:
    • M1: Economic value and profit margin of the fraud
    • M2: Documented history of fraud
    • M3: Economic pressures in the sector or region of origin
    • M4: Regulatory and compliance environment
  2. Assign a score from 1 to 5 for each sub-factor.
  3. Calculate the Motivation score: M = (M1 + M2 + M3 + M4) / 4
  4. Document the justification with reference to the intelligence sources consulted in Step 4.

Outputs: An M score for each vulnerability, with documented justification.

Recommendations:

  • The assessment of M3 and M4 may be carried out at country/region of origin level and reused for all ingredients coming from the same region.
  • Update the motivation scores when significant changes in prices, availability or geopolitical conditions are detected.

Step 8 — Assess Countermeasures

Objective: Assign a quantitative score to the existing countermeasures for each vulnerability, using the sub-factors defined in section 5.3.

Activities:

  1. For each vulnerability, assess the four countermeasure sub-factors using the tables in section 5.3:
    • C1: Supplier verification and audit programme
    • C2: Analytical and testing capability
    • C3: Traceability system
    • C4: Organisational culture and governance
  2. Assign a score from 1 to 5 for each sub-factor.
  3. Calculate the Countermeasures score: C = (C1 + C2 + C3 + C4) / 4
  4. Document the evidence for each countermeasure assessed (procedures, records, audit results).

Outputs: A C score for each vulnerability, with documented evidence.

Recommendations:

  • Be rigorous and honest in the assessment: score the countermeasures as they are actually implemented, not as they ought to be.
  • Verify that the countermeasures assessed are genuinely active and working, not merely documented.
  • Countermeasures that are not specific to food fraud (e.g. routine quality tests) may contribute, but will generally receive a lower score than countermeasures designed specifically to detect fraud.

Step 9 — Calculate the overall vulnerability and classify

Objective: Calculate the overall vulnerability score for each identified vulnerability and classify it according to its level of significance.

Activities:

a) For each vulnerability, calculate the overall vulnerability score:

V = (O × M) / C

O Opportunity, 1.0 to 5.0M Motivation, 1.0 to 5.0C Countermeasures, 1.0 to 5.0

The theoretical range of V is 0.20 (minimum: O=1, M=1, C=5) to 25.00 (maximum: O=5, M=5, C=1).

b) Classify each vulnerability according to the following table of levels:

V levelV rangeColourRequired action
LowV < 2.0🟢 GreenRoutine monitoring. Document and review at the next periodic assessment. No additional specific mitigation measures are required.
Medium2.0 ≤ V < 5.0🟡 YellowIncreased attention. Assess whether the current countermeasures are sufficient. Consider additional mitigation measures. Review within no more than 6 months.
High5.0 ≤ V < 10.0🟠 OrangeSignificant vulnerability. Specific mitigation measures and a VCCP must be established. Implement within no more than 3 months.
CriticalV ≥ 10.0🔴 RedCritical vulnerability. Immediate action required. Implement emergency mitigation measures and establish a VCCP. Consider temporarily suspending supply until adequate controls are in place.

c) Record all scores in the vulnerability assessment matrix (see Appendix D).

Outputs:

  • Complete vulnerability assessment matrix with O, M, C and V scores.
  • Vulnerability level classification for each item assessed.
  • List of significant (V ≥ 5.0) and critical (V ≥ 10.0) vulnerabilities.

Calculation example:

IngredientO1O2O3O4OM1M2M3M4MC1C2C3C4CVLevel
Honey54434.045333.832332.85.4🟠 High
Extra virgin olive oil43343.555323.844433.83.5🟡 Medium
Refined salt11121.311111.033333.00.4🟢 Low

Recommendations:

  • The significance threshold (V ≥ 5.0) is the recommended default value. The organisation may adjust this threshold downwards (more conservative), but adjusting it upwards is not recommended.
  • For vulnerabilities falling close to the threshold (e.g. V = 4.5 – 5.5), apply the decision tree in Appendix C as a supplementary criterion.
  • Always document the justification whenever the default threshold is modified.

Calculating on a case of your own

The three presets are the ingredients from the example above, with their twelve scores. Change them and watch how V moves.

ToolVulnerability calculator
Opportunity4.0
Motivation3.8
Countermeasures2.8
V5.5
High
0.22.05.010.025.0

Honey: sugar syrup adulteration is widely documented and hive-level traceability is limited.

Honey and extra virgin olive oil start from an identical motivation (3.8 for both): the economic incentive to adulterate them is equivalent. What separates one from the other is the countermeasures, 2.8 against 3.8, and that difference of a single point is what pushes honey above the significance threshold. It is the practical consequence of C being a divisor: you cannot act on a fraudster's motivation, but you can act on your own countermeasures.

How to cite this chapterMunguia, I. (2026). Steps 6 to 9 — Assess and score. En Beira VACCP Framework (v1.0). Beira Consultores. https://beiratraining.com/en/bvf/pasos-6-9-evaluar-y-puntuarComments and suggestions: bvf@beira.com.mx