Home / Guides / How to do a food fraud vulnerability assessment
Food Fraud Β· VACCP
Key facts
- Method seven vulnerability factors, scored 1 to 3 each
- Opportunity score 7 to 21, converted to a probability of 1 to 5
- Rating probability multiplied by severity
- Significant at a rating of 10 or more
- Source ISO 22002-100:2025 clause 16.3
- FSSC 22000 V7 clause 2.5.4, published May 2026
- FSSC 22000 V6 clause 2.5.4.1 and 2.5.4.2, auditable to 30 April 2027
- Scope every raw material, ingredient, packaging material and outsourced process
Why food fraud is scored on opportunity, not on frequency
A hazard analysis asks how likely something is to happen and how bad it would be. A vulnerability assessment cannot work that way, because food fraud is committed by a person who is deciding whether to do it. People respond to opportunity. If the margin is good, the chain is long, nobody is looking closely and the test you run would not find it, the fraud becomes attractive whether or not it has ever happened to you before.
That is why the seven factors do not ask how often you have been defrauded. They ask how much opportunity your supply chain currently offers. A clean history is weak evidence, because a fraud that worked is a fraud nobody spotted.
The single most common reason an auditor rejects a vulnerability assessment is that it is a severity times likelihood risk register wearing a different title. If your document has two columns and one of them is called likelihood, you have not done a vulnerability assessment.
The seven factors
ISO 22002-100:2025 clause 16.3 names the factors a vulnerability assessment is expected to evaluate. In the RA18 method they are each scored 1 to 3, where 1 is low vulnerability and 3 is high.
| Factor | The question it answers |
|---|---|
| Economic vulnerability | How much money is available to somebody who substitutes, dilutes or misdescribes this material? Price volatility, margin, and the cost gap between the real thing and the cheap alternative. |
| Historical data | Has this material, or this commodity, been adulterated before, anywhere? Notifications, alerts, court cases, trade press and your own complaint history. |
| Detectability | Would you find it? Not whether you test, but whether the tests you actually run would identify the adulterant the scenario names. |
| Access in the supply chain | How easy is it physically to interfere with the material without being seen? Bulk liquids and ground powders sit at one end, sealed retail packs at the other. |
| Relationship with the supplier | How long, how transparent, what contract, what audit history, and will they tell you who actually made the material? |
| Certification and assurance | What third party assurance sits behind the material, and does that assurance actually address authenticity rather than hygiene? |
| Complexity of the supply chain | How many hands, how many countries, how many intermediaries between the producer and your gate? |
Step one: group your materials before you score anything
You do not score every stock code. You score material groups, where a group is a set of materials that share a supply chain and a fraud profile. Two oils from the same refiner belong together. The same spice from two countries does not.
The scope is wider than most people assume. IFS Food version 8 section 4.20 requires the assessment to cover all raw materials, ingredients, packaging materials and outsourced processes. BRCGS Food Safety Issue 9 keeps packaging outside section 5.4, but if you are certified to both, build to the wider scope once rather than keeping two files that disagree. Do not forget labels, rework, returns and traded goods you buy finished and put your own name on.
Learn this method properly, then have your work marked
This article shows you one worked example. The Food Fraud Coordinator Course walks you through the method across twenty nine lessons and then makes you do it: you score three material groups on a real sourcing brief, a person marks your work against a rubric, you get coaching notes rather than a model answer, and then a second attempt.
Food Fraud Coordinator Course, R1750, 8 hours
New to the subject? Start with the overview course, R1450
Self-paced, no VAT charged, so the price shown is the price paid.
Step two: write the scenario in the fraudster’s voice
Most assessments fail here, and they fail quietly. A scenario that reads “risk of adulteration of paprika” cannot be scored, because it names no actor, no method, no point in the chain and no reason it would work. A scenario that can be scored answers four questions: who would do this, with what, at which point in the chain, and what would have to be true for them to get away with it.
Compare these two.
Cannot be scored. There is a risk that our ground paprika is adulterated.
Can be scored. A processor or an intermediary in the origin country extends ground paprika with cheaper plant material and restores the colour, because the price gap makes it worth doing, and it survives to our gate because our incoming specification measures moisture, ash and microbiological counts, none of which would identify it.
The second version tells you what to score, and it tells you what mitigation has to be aimed at. That last clause, the one explaining why it survives, is where the detectability score comes from.
Step three: score the seven factors, with a worked example
Take that ground paprika. Bought through a local distributor, origin stated as Spain, used as a seasoning on a ready to eat product with no kill step after it is added.
| Factor | Score | Why |
|---|---|---|
| Economic vulnerability | 3 | Volatile commodity price, and a wide gap between the price of the real material and the price of what could be used to extend it. |
| Historical data | 3 | Ground spices are among the most persistently adulterated commodities in the trade, and notifications appear regularly. |
| Detectability | 3 | The site tests moisture, ash and microbiology. None of those would identify what the scenario names. |
| Access in the supply chain | 3 | A ground powder, handled in bulk, with several points where it could be blended without anyone noticing. |
| Relationship with the supplier | 2 | Four years with the distributor, a contract in place, but they will not name the processor, citing commercial confidentiality. |
| Certification and assurance | 2 | The distributor is certified to a GFSI benchmarked scheme and sends a certificate of analysis with every delivery. Neither of those addresses authenticity. |
| Complexity of the supply chain | 3 | Grower, processor, exporter, importer, distributor. At least five steps across two countries, and only the last one is visible to us. |
Add them up. 3 + 3 + 3 + 3 + 2 + 2 + 3 = 19. That is the opportunity score, on a scale that runs from 7 to 21.
From opportunity score to probability
| Opportunity score | 7 to 9 | 10 to 12 | 13 to 15 | 16 to 18 | 19 to 21 |
|---|---|---|---|---|---|
| Probability | 1 | 2 | 3 | 4 | 5 |
An opportunity score of 19 gives a probability of 5.
Choosing a severity
Severity is not the same question as probability and it is judged separately, across three kinds of consequence: food safety, legality, and brand or economic damage. You take the worst of the three, not an average of them.
Here, the material is added to a ready to eat product after the last step that would kill or remove anything. An undeclared extender is a labelling and legality failure on its own, and the colourants historically used in this commodity are not permitted in food, which makes it a safety question as well. Severity 4.
The inherent rating
Probability 5 Γ severity 4 = 20. On the RA18 bands that is Critical, and anything at 10 or above is significant, which means this group now has to carry a documented mitigation plan and a material by material justification.
Step four: build mitigation that is aimed at a factor
The test of a mitigation measure is simple: name the factor it moves. A measure that does not move a factor is a line on a spreadsheet. Good mitigation carries both kinds of measure, preventive and detection, because preventing an opportunity and finding a fraud that already happened are different jobs.
| Measure | Kind | Factor it aims at |
|---|---|---|
| Supplier agreement amended to require disclosure of the processor and the country of origin at each delivery | Preventive | Relationship with the supplier |
| Specification tightened to state no added colouring matter and a declared origin | Preventive | Relationship, and evidence for any later claim |
| Price monitoring with a written trigger when the delivered price moves against the market | Detection | Economic vulnerability, as an early warning |
| Targeted authenticity testing on a defined sampling plan, on a sample drawn from the delivered bulk by our own goods receiving team | Detection | Detectability |
| Mass balance against the distributor’s declared volumes | Detection | Detectability, without a laboratory |
| One supply chain audit, one step further back than the distributor | Preventive | Complexity, partially |
Notice the fourth measure. It is not “test the material”. It is testing the right thing, on a sample we choose, drawn where the supplier cannot select it. If the fraud lies in the difference between the approval sample and the shipment, then a more sensitive method applied to the supplier’s own sample buys you nothing at all.
Step five: re-score the residual, honestly
Here is the part that separates a real assessment from a decorative one. You re-score only the factors the mitigation genuinely moved. Most of them do not move.
| Factor | Inherent | Residual | Did it move? |
|---|---|---|---|
| Economic vulnerability | 3 | 3 | No. You cannot change the market. |
| Historical data | 3 | 3 | No. History does not change. |
| Detectability | 3 | 1 | Yes. Targeted testing on your own sample now finds what the scenario names. |
| Access in the supply chain | 3 | 3 | No. It is still a bulk powder. |
| Relationship with the supplier | 2 | 1 | Yes. The contract now compels disclosure and the processor is named. |
| Certification and assurance | 2 | 2 | No. Nothing about the certification changed. |
| Complexity of the supply chain | 3 | 3 | No. One audit does not shorten a five step chain. |
New opportunity score: 3 + 3 + 1 + 3 + 1 + 2 + 3 = 16, which gives a probability of 4. Severity does not change, because mitigation does not make the consequence smaller, only less likely. 4 Γ 4 = 16, which is High, and still significant.
That result is the point of the example. Reasonable, funded, well aimed mitigation moved this group from 20 to 16. It did not move it to 2. An assessment where every residual rating collapses into the green has almost always been written backwards from the answer somebody wanted, and experienced auditors read residual columns first for exactly that reason.
The two places real assessments fall over
Supplier or distributor?
You assess the direct supplier on the relationship and the chain behind them on opportunity. Buying through a distributor does not shorten your chain, it lengthens it by one and hides the rest. If your assessment stops at the distributor, your complexity factor is scoring a chain of one when the real chain is five, and your access factor is scoring a relationship with a warehouse.
How far back is far enough? The practical test is whether you can score the seven factors honestly from what you know. If the answer to “how many hands touch this” is “I do not know”, you have not gone far enough. Where the chain genuinely goes dark, say so in the assessment and score it at the high end. A documented unknown is defensible. A blank is a finding.
Detectability
A test finds what it is looking for. A moisture test finds moisture. A protein test finds nitrogen, which is the whole reason melamine worked. Your microbiological specification finds microorganisms. None of them is looking for what the fraudster added, because the fraudster chose something your specification does not measure.
Targeted methods measure something you have named in advance and are blind to everything else. Non targeted methods compare a whole profile against authentic reference material and can flag something odd without knowing in advance what was added, but they are only as good as the reference database behind them. Most sites have targeted testing only, and that is a perfectly acceptable position. What is not acceptable is scoring detectability as though you had capability you do not have.
Keeping it current is part of the requirement
Every scheme requires the plan to be kept up to date, and horizon scanning is how you do it. The failure mode is not that sites do not read about fraud, it is that the reading leaves no record. Name your sources in the procedure, name who reads each one, set a frequency, and keep a one page log with the entries that found nothing as well as the ones that did. Those empty entries are the evidence that the system ran.
Two corrections worth making to most source lists. The Food Fraud Database that people still call the USP database was acquired from USP in 2018 and is a commercial subscription product, so it does not belong on a list of free resources. And the standalone EU food fraud summary report ended with the 2020 edition; the current outputs are the Alert and Cooperation Network annual report and the monthly reports on agri-food fraud suspicions, alongside the European Commission Joint Research Centre’s monthly food fraud digest, which is free and is probably the best single starting point because the filtering is already done.
What each scheme asks for
One assessment, built to the widest scope, satisfies all of them. What differs is the vocabulary and one or two additions.
| Scheme | Where food fraud sits | Worth knowing |
|---|---|---|
| FSSC 22000 Version 7 | Clause 2.5.4, plus ISO 22002-100:2025 clause 16.3 | Version 7 moved the method out to the ISO clause and left only the additions in 2.5.4, including a competence requirement for the assessor. |
| FSSC 22000 Version 6 | Clauses 2.5.4.1 and 2.5.4.2 | Still auditable until 30 April 2027, so both versions are live during the transition. |
| BRCGS Food Safety Issue 9 | Section 5.4, product authenticity, claims and chain of custody | Packaging sits outside section 5.4. Issue 10 is in development and has no publication date. |
| SQF Edition 10 | Clause 2.7.2, alongside 2.7.1 food defence | Effective 1 September 2026, with fewer sub-clauses than Edition 9. |
| IFS Food version 8 | Section 4.20, alongside 4.21 food defence | Widest scope, names a twelve month review, and is not a knock out requirement. |
| GFSI Benchmarking Requirements v2024 | FSM 8.2, 8.3 and 8.5 | Calls it a food fraud management plan, and requires appropriate knowledge and expertise without prescribing how you get it. |
If you want this mapped clause by clause, with the transitions and what each scheme uniquely adds, that is covered in TACCP, VACCP and HACCP: which assessments each scheme actually requires.
The difference between reading the method and being able to defend it
You can follow this article and produce something. Whether it survives an auditor is a different question, and the only way to find out before the audit is to have somebody mark your work. That is what the coordinator course is built around.
Food Fraud Coordinator Course, R1750
Compare all three food fraud and food defence courses
Three material groups scored online, marked by a person against a rubric, coaching notes and a second attempt.
Frequently asked questions
What is a food fraud vulnerability assessment?
A documented assessment of how much opportunity your supply chain gives somebody to commit food fraud and get away with it, scored on a defined methodology across every raw material, ingredient, packaging material and outsourced process. It is not a hazard analysis, and it is not scored on how often fraud has happened to you.
How often must the assessment be reviewed?
IFS Food version 8 names at least once within a twelve month period or whenever significant changes occur. SQF requires an annual review of the plan documentation. FSSC requires the plan to be kept up to date. Treat the annual review as the floor and named triggers as the mechanism: a new supplier, a new origin, a notification naming a material you buy, a sharp price movement, a new intermediary, a complaint that does not fit the process, or a change to the standard you are certified against.
Do I assess my distributor or the original producer?
Both, for different things. The direct supplier is assessed on the relationship, the chain behind them on opportunity. If a distributor will not name the producer, that refusal is information: record it, score complexity and supplier relationship at the high end, aim mitigation at the gap, and put the disclosure request into the contract at the next renewal.
Is a certificate of analysis proof of authenticity?
No. It tests the parameters in your specification, which are the parameters a fraudster designs around, and it describes a sample the supplier selected. Falsified certificates are themselves a common fraud, because a document is cheaper to fake than a product. Treat a certificate as a control on the supplier relationship, not as authenticity evidence.
Is there an internationally agreed legal definition of food fraud?
No. Codex draft guidelines on the prevention and control of food fraud sit at Step 5, which is a procedural midpoint and not adoption. The European Commission states that EU legislation provides no formal definition of fraud in the agri-food chain. The definition almost everyone quotes comes from GFSI, and it is a private scheme definition rather than law.
Does South African law require a food fraud vulnerability assessment?
No, and no other jurisdiction requires one either. The assessment requirement comes from your certification scheme. The liability does not. The Foodstuffs, Cosmetics and Disinfectants Act 54 of 1972 prohibits adding a substance to increase mass or volume with the object to deceive, and describing a foodstuff in a way that is false or misleading as to its origin, nature, substance, composition or quality. The Agricultural Product Standards Act 119 of 1990 section 6 covers substitution, origin fraud and misdescription in a single provision. The Consumer Protection Act adds trade description and misleading marketing offences. None of that cares whether you are certified.
Can I do this course without a site of my own?
Yes. Every activity in the Food Fraud Coordinator Course, including the graded practical, is built on the course case study, so consultants, students and people between roles can complete the whole course.
ASC Food Safety Training Β· Leading with Science. Ensuring Food Safety. Β· Fully online, serving all of South Africa and beyond Β· info@ascfoodsafety.com Β· WhatsApp +27 61 483 0381 Β· SAATCA registered training centre (TC No. 065) Β· FoodBev SETA accredited provider No. 587/00337/1900 Β· B-BBEE Level 1 Β· Registered Lead Auditor (Exemplar Global and IRCA) Β· Consulting and document toolkits at ascfoodsafety.com