Food fraud — vulnerability assessment (VACCP) and mitigation plan

Food Fraud: what it is, what it requires and how to train

The only food safety hazard whose cause is someone's economic decision rather than a process failure. That is why it is not controlled with a CCP: it is controlled by knowing which raw material is worth adulterating, and closing that door first.

Food fraud is the deliberate substitution, addition, tampering or misrepresentation of a food, an ingredient, its packaging or its labelling, committed for economic gain. It is assessed through a vulnerability methodology known as VACCP (Vulnerability Assessment and Critical Control Points), which identifies where adulteration is profitable and determines the controls that make it hard or detectable. Since 2018 every certification scheme recognised by the Global Food Safety Initiative (GFSI) has required a documented food fraud vulnerability assessment and a mitigation plan derived from it.

In short

Motivation
Economic (unlike food defense)
Methodology
VACCP — vulnerability assessment
Required by
All GFSI-recognised schemes
Mandatory since
1 January 2018
FSSC 22000 V7
Additional requirement 2.5.4, food fraud mitigation
BRCGS Food v9
Clause 5.4, product authenticity
IFS Food v8
Clause 5.6, food fraud
SQF Ed. 9
Clause 2.7, food defense and food fraud
Guide

This guide is written for whoever has to learn or teach Food Fraud. If what you need is for us to implement the system at your company, that work is done by Beira Consultores.

See consulting at beira.com.mx

Food fraud and food defense are not the same thing

Both methodologies protect against a deliberate act, and that is where the resemblance ends. In food fraud (VACCP) the motivation is economic: someone makes money if the product passes for what it is not, and they do not want anyone to fall ill, because an outbreak draws exactly the attention that ruins the business. In food defense (TACCP) the motivation is to cause harm, and the attacker wants the opposite.

The consequence is operational, not terminological: the economic attacker is careful and their adulteration is designed not to be detected, so what stops them is not a camera or an access control but an analysis that looks for what should not be there. This is why a plant can have an impeccable defense plan and still buy adulterated oil every week.

Health risk is the other uncomfortable difference. Fraud is usually harmless (a cheaper oil sold as extra virgin), until it is not: the melamine added to milk in 2008 to fake protein content killed six infants and sickened three hundred thousand. A fraud scheme that starts as a purely commercial deception escalates without warning.

What your scheme requires, exactly

Since version 7 of the GFSI benchmarking requirements, published in February 2017 and enforceable from 1 January 2018, every recognised scheme has carried two deliverables. Not one: two, and the second is the one most often forgotten.

  • A documented food fraud vulnerability assessment covering the certification scope.
  • A mitigation plan derived from that assessment, with assigned and verifiable controls.
  • FSSC 22000 requires it in additional requirement 2.5.4, separate from 2.5.3 on food defense.
  • BRCGS Food Safety Issue 9 covers it in clause 5.4, under product authenticity and claims.
  • IFS Food version 8 develops it in clause 5.6, with a documented team, scope and review.
  • SQF edition 9 covers it in clause 2.7, alongside food defense.
  • ISO 22000:2018 does not require it explicitly: it appears when certifying under a GFSI scheme built on it.

Why a CCP does not work here

Classic HACCP is built for hazards that happen, not for hazards someone causes. A critical limit controls a process variable that behaves according to physics and biology: pasteurisation temperature does not change strategy when it realises it is being measured. An adulterator does.

So a fraud assessment does not ask what can fail, but who benefits and at what cost. The useful questions are different: how easily can that raw material be reached unnoticed, how much is gained by adulterating it, and would your current controls detect it. What is assessed is not your own process: it is the whole supply chain, backwards, and the incentive at each link.

How a vulnerability assessment is done

The work follows much the same sequence in nearly every methodology, and what separates them is whether they score or merely describe. An assessment that only describes produces a long document from which no decision follows, and it is the most frequent audit finding: complete matrix, empty mitigation plan.

  • Form a team with procurement, quality and whoever knows the market for that input.
  • Define the scope: raw materials, packaging, outsourced services and finished product.
  • Gather intelligence: incident history, public alerts, prices and how they behave.
  • Identify the vulnerability of each input, not of the process as a whole.
  • Score it against explicit, repeatable criteria, so results can be compared and ranked.
  • Determine where the score demands control and set the mitigation measure.
  • Verify the control works and reassess when the market or the supplier changes.

How to train in food fraud

Training in this field has a problem of its own: most of what is taught stops at definitions and fraud types, and students leave knowing what substitution is but unable to fill in the matrix the auditor asks for. What is needed is the opposite: a method with numbers, scoring criteria two people would apply the same way, and a mitigation plan they can write by the end.

The audience is not only food safety, either. Procurement decides which supplier is used and against which specification, and that decision moves vulnerability more than any plant control. Training that leaves procurement out leaves out half the problem.

Free book

The Beira VACCP Framework, in full and without signing up

The methodology this page describes is developed in full in a book you can read for free, with no account and without leaving your email: the three pillars of vulnerability with a descriptor for every level, the scoring formula, the decision tree that confirms a VCCP, the twelve implementation steps and the templates for the matrix and the mitigation plan. It is published under a CC BY-SA 4.0 licence, so you may cite and adapt it with attribution.

Read the book
Who it applies to

Who needs training in Food Fraud

Food safety or systems manager

Build the full vulnerability assessment and defend every score to the auditor, not just hand over a completed matrix.

Buyer or supplier manager

Know what to ask a new supplier and what document to request, because vulnerability almost always enters through the supply chain.

Food fraud (VACCP) team

Gather intelligence, score against a shared standard and revisit the assessment when the market moves, not only once a year.

Supplier quality manager

Answer the assessment a customer sends with real authenticity evidence rather than a signed declaration.

Training

Online Food Fraud courses

See all
CUR-203
Coming soonVACCPIntermediate
32

Prevención del Fraude Alimentario con VACCP

Sales con tu evaluación de vulnerabilidad puntuada y tu plan de mitigación escrito

Coming soon
Questions

Frequently asked questions about Food Fraud

What is food fraud?

Food fraud is the deliberate substitution, addition, tampering or misrepresentation of a food, an ingredient, its packaging or its labelling, committed for economic gain. It covers seven recognised types: substitution, addition, tampering, misrepresentation, unapproved enhancements, counterfeiting and stolen goods. It differs from food defense in intent: here the aim is to make money, not to cause harm.

What is the difference between VACCP and TACCP?

VACCP assesses vulnerability to food fraud, whose motivation is economic, and its central question is who benefits from adulteration and by how much. TACCP assesses food defense threats, whose motivation is to cause harm, and covers sabotage, intentional contamination and extortion. Both analyse deliberate acts, but the actor's profile is the opposite and so are the controls that work.

Does my certification require a food fraud vulnerability assessment?

Yes, if your scheme is recognised by GFSI. Since 1 January 2018 every recognised scheme requires a documented food fraud vulnerability assessment and a mitigation plan derived from it. It appears as additional requirement 2.5.4 of FSSC 22000, clause 5.4 of BRCGS Food Safety Issue 9, 5.6 of IFS Food version 8 and 2.7 of SQF edition 9. ISO 22000:2018 on its own does not require it explicitly.

How often should the vulnerability assessment be reviewed?

At least once a year, and additionally whenever something changes the incentive to adulterate: a new supplier, a new input, a sharp price movement in a raw material market, a public alert about that ingredient or an incident of your own. Waiting for the annual review after an input's price has spiked is reacting late, because that is precisely when vulnerability rises.

Does a food fraud plan cover food defense?

No, and presenting them as one is a common finding. They share the team and part of the starting information, but the assessment differs: the fraud one scores economic incentive and the defense one scores access and intent to harm. Schemes ask for two assessments with two plans, although a single document may hold both as long as each is distinguishable.

Is there a specific food fraud standard?

There is no certifiable international standard dedicated solely to food fraud, as there is for quality or for food safety. The requirement lives inside GFSI-recognised schemes and in each country's regulation on authenticity and labelling. That is why the methodology used to meet it is not prescribed: each organisation picks one and has to justify to the auditor that it is systematic and repeatable.