Food Fraud Coordinator Course: VACCP, the Schemes and the Prevention Plan
About Course
A food fraud coordinator course that takes you from a blank page to a finished, audit ready food fraud vulnerability assessment and mitigation plan. It is built on the seven vulnerability factors in ISO 22002-100:2025 clause 16.3, and mapped to FSSC 22000 clause 2.5.4 in both Version 6 and Version 7, BRCGS Food Safety Issue 9 section 5.4, SQF Edition 10 clause 2.7.2, IFS Food version 8 section 4.20 and the GFSI Benchmarking Requirements version 2024.
Almost nobody sells this as a role. The market sells food fraud as a topic, or as a clause to close out before an audit, and then lists nine job functions who might attend. Meanwhile four certification schemes and one benchmarking body between them hand a specific set of duties to one person on your site, and that person is usually you, given it on top of the day job. This course is written for that person.
You do not sit an exam. You build a vulnerability assessment and a person marks it
Module 4 gives you a full sourcing brief for a chilled ready meals manufacturer and asks you to score three material groups end to end: the scenario in the fraudster’s voice, all seven factors, the opportunity score, the probability, the severity, the mitigation and the residual position. You do it online, in the browser. Nothing about the case can be downloaded or copied, so the work is yours.
Your submission is marked against a rubric built from the faults auditors actually raise, and you get coaching notes rather than a memorandum: notes telling you what to look at again, attached to the specific material group they belong to, so the correction comes from your own thinking. Then you get a second attempt. A facilitator can see your full submission and the reasoning behind every mark, so if you disagree with something there is a person to ask. When your second attempt is marked, your own completed vulnerability assessment is yours to download. It is the only downloadable thing in the course.
That matters because the question practitioners ask most often, on every food safety forum, is some version of this: where can I see a worked food fraud vulnerability assessment with the ratings filled in? By the end of this course you will not be looking for one. You will have written one, had it marked, and corrected it.
What the five modules cover
- Getting ready. Why food fraud is scored on opportunity rather than on how often it has happened, the seven factors the standard expects you to evaluate, building a food fraud mitigation team with procurement in the room, the sourcing information every score has to be defensible from including price history, and the cycle that keeps the assessment current.
- Scoring vulnerability. The recognised fraud types tested against a material group, grouping materials sensibly, mapping a supply chain well enough to score access and complexity, scoring all seven factors against the workbook definitions, converting an opportunity score to a probability, choosing a severity across the three kinds of fraud risk, a full worked example from scenario to residual rating, and how to write a fraud scenario that can actually be scored.
- From score to plan. Mitigation carrying both preventive and detection measures, the criteria that separate a real control from a line on a spreadsheet, the residual scoring discipline and how to recognise one that has been faked, horizon scanning that survives an audit, verifying a certificate the way it has to be verified, handling a suspected fraud, and the eleven questions auditors are told to ask.
- The graded practical. Three material groups scored on a real sourcing brief, marked by a person, with coaching notes and a second attempt.
- The coordinator’s wider brief. What the role actually owns, one assessment mapped onto FSSC, BRCGS, SQF, IFS and GFSI, detectability and what your testing can genuinely find, how far back up the chain you have to score when you buy through a distributor, horizon scanning sources that are free and current, the law that bites when fraud reaches your label in South Africa, the European Union, the United Kingdom and the United States, and a working calendar for the year.
Who it is for
Food fraud coordinators and food fraud mitigation team leaders, technical and quality managers who have picked up the food fraud brief, procurement and supply chain managers who are being asked questions they have no method for answering, HACCP and food safety team members, internal auditors, and consultants who have to produce or defend a vulnerability assessment for a client.
You do not need to be employed on a site to complete it. Every activity works against the course case study as well as against your own supply chain, so a consultant or someone between roles can finish the whole course including the graded practical.
Why this one rather than another
- It is assessed on work you produce. Most food fraud training, including the good training, finishes with a multiple choice exam or a certificate of attendance. Anyone can pass a quiz on food fraud. Far fewer people can build a vulnerability assessment that survives an audit, and this course proves you can.
- It is current, and it says which version. FSSC 22000 Version 7 was published in May 2026 and moved the method out to ISO 22002-100:2025 clause 16.3, while Version 6 remains auditable until 30 April 2027. SQF Edition 10 took effect on 1 September 2026. This course teaches both sides of both transitions, which most material on the market has not caught up with.
- Every clause is cited by number: FSSC 22000 2.5.4, BRCGS Issue 9 section 5.4, SQF Edition 10 2.7.2, IFS Food 8 section 4.20, GFSI 2024 FSM 8.2, 8.3 and 8.5, and ISO 22002-100:2025 clause 16.3.
- It teaches the two questions nobody else answers. How far back up the chain do you score when you buy through a distributor, and what would your testing actually find. Those are the two places where real vulnerability assessments fall over, and they get a lesson each.
- It covers the law, not just the standard. No jurisdiction requires a VACCP study. Every jurisdiction punishes the outcome. The course names the provisions in South Africa, the EU, the UK and the US, which is the argument that gets the programme funded.
- It costs R1750. Comparable coordinator level programmes run from several hundred to well over a thousand US dollars, and many providers do not publish a price at all.
- It is written by a practising food safety consultancy that implements these plans on real sites, in plain language, by people who have sat on both sides of the audit.
How long it takes, and where the eight hours actually go
About seven hours are the taught modules, delivered as twenty nine lessons, most of them ten to seventeen minutes, so you can take one in a tea break and still finish the thought. The rest is you working: scoring the three material groups, reading your coaching notes, and correcting your own scores on a second attempt. That is time spent producing something, not time spent watching a slide advance.
- Twenty nine lessons across five modules, most of them ten to seventeen minutes, self-paced, with the course remembering where you stopped.
- Four knowledge checks and two games built into the modules, drawn at random from banks, so a retake is a fresh set of questions rather than the same ones again.
- The graded practical: three material groups scored on a real sourcing brief and marked by a person against a rubric.
- Coaching notes and a second attempt. This is where the learning actually lands, and it is the part most courses leave out.
- A final assessment drawn from a large bank to close the course out.
None of it is padding. There is no video of somebody reading the standard aloud and no module that exists to make the number look bigger. If you already know a section, its knowledge check will tell you so in ninety seconds and you can move on. Most delegates do it across two or three weeks, a lesson or two at a time, and finish with a vulnerability assessment they can take straight back to their own supply chain.
Questions people ask before they enrol
What qualification does a food fraud coordinator need?
None is prescribed. GFSI Benchmarking Requirements version 2024, FSM 8.5, requires that appropriate knowledge and expertise be used in developing and maintaining the food fraud assessment plan, and FSSC 22000 Version 7 clause 2.5.4 (a) requires the assessment and the plan to be developed and maintained by personnel having the appropriate knowledge and competence. Neither names a course, a syllabus, a competency level or a number of hours. How you evidence that competence is left to you and your certification body, which is why a food fraud specific training record is worth more in that file than a general food safety certificate.
What is the difference between TACCP and VACCP, and do I need both?
VACCP assesses vulnerability to food fraud, which is deception for economic gain. TACCP assesses threats of deliberate contamination intended to cause harm. They use different scoring logic, they usually involve different people, and every GFSI benchmarked scheme requires both as separate assessments. This course covers food fraud. The food defence coordinator course covers the other side.
I buy through a distributor. Do I assess the distributor or the original producer?
Both, for different things. You assess the direct supplier on the relationship, and the chain behind them on opportunity. A distributor does not shorten your supply chain, it lengthens it by one and hides the rest. Lesson 5.4 works through how far back is far enough, and what to record when the chain goes dark. This is the single most asked question in the subject and it has a lesson to itself.
We test every incoming consignment. Does that mean detectability is good?
Not on its own. A test finds what it is looking for, and a fraudster chooses something your specification does not measure. Frequency is not power. Lesson 5.3 covers targeted and non targeted methods, why a certificate of analysis is not authenticity evidence, and why your sampling design often matters more than your method.
How often does a vulnerability assessment have to be reviewed?
IFS Food version 8 names at least once within a twelve month period, or whenever significant changes occur. SQF requires an annual review of the plan documentation. FSSC requires the plan to be kept up to date. In practice the annual review is the floor and the triggers are the mechanism, and an out of cycle re-score with its reason recorded is stronger audit evidence than a perfect annual one. Lesson 5.7 lists the triggers.
Is there an internationally agreed definition of food fraud?
No. Codex draft guidelines on the prevention and control of food fraud sit at Step 5, which is a procedural midpoint and not adoption. The European Commission states that EU legislation provides no formal definition of fraud in the agri-food chain. The definition almost everyone quotes is GFSI’s, which is a private scheme definition rather than law. The course says so plainly, and teaches the provisions that do have legal force.
Do I need my own site to complete the course?
No. Every activity, including the graded practical, is built on the course case study, so consultants, students and people between roles can finish the whole thing.
Five modules, twenty nine lessons, four knowledge checks, two games, a graded practical assessment marked by a person, and a final assessment. Approximately eight hours, self-paced, with a certificate of completion.
Course Content
Module 1: Getting Ready to Build a Vulnerability Assessment
-
1.1 Why a Vulnerability Assessment Is Not a Hazard Analysis
-
1.2 Building the Food Fraud Mitigation Team
-
1.3 Collecting Your Sourcing Information Before You Start
-
1.4 The Rhythm the Plan Runs On
-
Module 1 Knowledge Check