Spring special ends 15 September: 30% off qualifying HACCP and FSSC 22000 courses. Code SPRING30 at checkout. See qualifying courses

What a Food Defence Coordinator Actually Does, and How to Evidence the Competence

Home / Guides / What a food defence coordinator does

Food Defence · TACCP · FSMA

Almost nobody is hired as a food defence coordinator. The role arrives the way most food safety work arrives: somebody in a meeting says the standard wants a food defence plan, and it lands on the person who did not step back fast enough. This guide sets out what the role actually owns, what belongs to other departments, what FSMA adds if you export to the United States, and how to evidence the competence the schemes now ask for.

Key facts

  • Method TACCP, threat assessment critical control point
  • Reference standard PAS 96:2026, fifth edition
  • FSSC 22000 clause 2.5.3, food defence
  • BRCGS Food Issue 9 clause 4.2, food defence
  • SQF Edition 10 element 2.7.1, effective 1 September 2026
  • IFS Food version 8 requirement 4.21, not a knock out
  • United States 21 CFR Part 121, the Intentional Adulteration rule
  • Competence required by the schemes, prescribed by none of them

The role exists because five documents create it, not because anyone advertised for it

Search the job boards for food defence coordinator and you will find very little. You will find food safety coordinators, technical managers and compliance officers, with food defence appearing as one line in a list of fourteen duties. That absence is misleading, because the duties are real and somebody has to hold them.

They come from five places. Four certification schemes each require a documented threat assessment and a food defence plan: FSSC 22000 at clause 2.5.3, BRCGS Global Standard Food Safety Issue 9 at clause 4.2, SQF Edition 10 at element 2.7.1 and IFS Food version 8 at requirement 4.21. PAS 96:2026 supplies the method those clauses assume. And for any site exporting to the United States, the FDA Intentional Adulteration rule at 21 CFR Part 121 adds a set of obligations that none of the schemes impose.

Between them they create a job. Nobody writes the job description.

What the coordinator actually owns

This is the list worth printing and taking into the meeting where the role is handed to you, because the difference between what you own and what you were assumed to own is where the first audit finding usually lands.

You own What that means in practice
The threat assessment Keeping it current, defensible and complete across every threat actor and access point, and re-scoring when the site or the threat environment moves.
The plan A documented plan naming the measures, the verification behind each, the responsibilities and the records, supported by your management system.
The people Training and awareness for everyone whose behaviour the plan depends on, which is far more people than sit on the team.
The evidence Records showing the measures ran, the verification happened and the actions closed. At audit, the plan is only as real as its records.
The response Knowing what happens on the day something is found, and having decided it before that day.
The review A scheduled reanalysis, plus the judgement to call an early one when a trigger fires.

What you do not own is the controls themselves. Engineering owns the locks and the card readers. Human resources owns pre-employment vetting. Information technology owns the accounts and the recipe system. Production owns supervision on the line. Security owns the perimeter.

Here is the distinction that matters at audit. A card reader on the chemical store has been broken for three weeks and the door propped open. Engineering will fix the reader and production will stop propping the door, but the finding lands on the plan: a mitigation measure was not working for three weeks and nothing in the system noticed. The measures belong to their owners. The verification that proves they work belongs to you.

Take the role seriously from week one

The Food Defence Coordinator Course is built for the person who has just been handed this. Thirty lessons across five modules, then a graded practical where you score four threat actor and access point pairings on a real site brief and a person marks your work against a rubric.

Food Defence Coordinator Course, R1750, 10 hours
New to the subject? Start with the overview course, R1450
Self-paced, no VAT charged, so the price shown is the price paid.

The team is not your HACCP team

This is the first practical decision and people get it wrong because it is convenient to get it wrong. A HACCP team is built around process knowledge. A food defence team has to be built around access knowledge, and the people who know who can get where, when, and without being seen are not the people who know the cook step.

A working food defence team usually needs production or operations, engineering or maintenance, human resources, information technology, security or facilities, procurement or logistics, and quality. It is wider than a HACCP team and it meets less often, which means the coordinator carries more of it between meetings.

What TACCP actually asks you to do

TACCP scores a pairing: a threat actor at an access point. Not a general worry, a specific pairing. The insider at the open product line is one assessment. The contractor at the chemical store is another. The outsider at the bulk intake is a third. The cyber actor at the recipe and label system is a fourth, and it is the one most sites still leave out.

Each pairing is scored on three factors, which the RA02 method takes at one to five each.

Factor The question
Attractiveness What would somebody gain by doing this here? Brand profile, product reach, publicity, grievance, money.
Vulnerability of the access point How open is it today? Not how open it will be after the capital project, today, including the door propped open in summer.
Impact If it succeeded, what actually happens? Product already in homes, a recall, a safety consequence, or a nuisance and a cost.

Likelihood is derived from attractiveness and vulnerability, and the rating is that likelihood multiplied by impact. The discipline that makes it defensible is scoring the site as it is this morning rather than as it will be after the improvement plan. Scoring the intended state is the single most common way a threat assessment ends up describing a factory that does not exist.

What FSMA adds, and what it does not

If your site exports to the United States, or supplies a business that does, the Intentional Adulteration rule is part of the brief whether or not your certification scheme mentions it. It is formally titled Mitigation Strategies to Protect Food Against Intentional Adulteration and it sits at 21 CFR Part 121.

Three things to be clear about.

It is narrower than TACCP. The rule targets acts intended to cause wide scale public health harm. It is not concerned with a disgruntled employee doing something small, with theft, or with economically motivated adulteration. Your TACCP assessment covers more ground than the rule requires. What the rule adds is a specific method and a specific set of management obligations on the parts it does cover.

It is not the food fraud rule. This trips up a surprising number of coordinators. Economically motivated adulteration is handled in the Preventive Controls rule instead, at 21 CFR 117.130 (b) (2) (iii), which requires the hazard analysis to consider hazards that may be intentionally introduced for purposes of economic gain. If you export to the United States, that sub paragraph is what puts food fraud into your food safety plan, and Part 121 has nothing to say about it.

It reserves certain work for a qualified individual. The rule limits preparing the food defence plan, conducting the vulnerability assessment, identifying mitigation strategies and reanalysing the plan to a qualified individual who has completed training at least equivalent to what FDA recognises as adequate, or who is qualified by experience. Routine monitoring can be done by trained operators. Designing and reassessing the plan cannot. Note that the regulation itself says qualified individual; the term food defence qualified individual comes from FDA guidance rather than from the rule text.

The competence question, and how to answer it in your training file

Every scheme now says something about the knowledge of the person doing this work, and none of them says how you get it. That is unusual, and it is useful.

GFSI Benchmarking Requirements version 2024 requires that appropriate knowledge and expertise be used. FSSC 22000 Version 7 requires the assessment and the plan to be developed and maintained by personnel having appropriate knowledge and competence. IFS Food version 8 requires responsibilities to be clearly defined and held by people with appropriate specific knowledge. Not one of them names a course, a syllabus, a competency level, a qualification or a minimum number of hours.

The practical consequence is that what goes into your training file has to look like evidence of competence in this specific method, not a general food safety certificate. A HACCP certificate does not evidence a threat assessment competence, and a growing number of auditors will say so out loud.

The coordinator’s year

The coordinators who stay on top of this are the ones who put the cycle on a calendar in January rather than reacting to the audit date in October. A workable shape, with the months moved to suit your own audit window.

When What
Two months after the audit Review the access point list. New doors, new contractors, new systems, new shift patterns.
Quarterly Verification that tests behaviour rather than paperwork. Try a door. Ask a contractor who signed them in.
Mid year Re-score the significant pairings and check each mitigation measure is still in place and still being done by the person named.
Three months before audit Full reanalysis with the team in the room, so actions raised can actually be closed in time.
Two months before audit Refresh awareness for the people the plan depends on, and update the training records. The auditor will ask them, not only read the file.
One month before audit Assemble the evidence pack and read it as though you were the auditor.
Each management review The numbers: pairings assessed, significant ones, verification activities run, actions open and closed.

Outside that calendar, certain events force an early reanalysis: a new process or product, a change to the site layout or access control, a security incident or near miss anywhere in the group, a credible external threat, a change of contractor or cleaning provider, a significant change in staffing or a period of industrial relations tension, and a change to the standard you are certified against.

If you also hold the food fraud brief

On most sites below a certain size, one person ends up holding both. That is workable, provided the two assessments stay genuinely separate, because the logic is different. Food defence asks who would want to harm us and how they would get in. Food fraud asks who would want to make money out of us and how the chain would let them. The scoring factors are different, the teams are different, and an auditor who finds the two assessments merged into one document will treat neither as complete.

If that is your position, the companion piece to this one is how to do a food fraud vulnerability assessment, which works a single material group end to end with the scores shown. And if what you need is the clause map across all the schemes, that is TACCP, VACCP and HACCP: which assessments each scheme actually requires.

Evidence the competence, do not just claim it

The schemes ask for appropriate knowledge and competence and leave you to prove it. A course that ends with a multiple choice exam proves you can answer questions about food defence. A course that ends with a threat assessment you built, marked by a person against a rubric, proves something an auditor can actually read.

Food Defence Coordinator Course, R1750
Compare all three food fraud and food defence courses
Thirty lessons, a graded practical marked by a person, coaching notes and a second attempt.

Frequently asked questions

What does a food defence coordinator do day to day?

Most of the work is verification and records rather than assessment. The assessment is rewritten once or twice a year. In between, the job is checking that the measures named in the plan are actually happening, keeping the action tracker moving, running awareness so the people the plan depends on know their part, watching for the triggers that force an early reanalysis, and keeping the evidence pack in a state where you could hand it over tomorrow.

Is there an official food defence coordinator certification?

No statutory licence exists anywhere. Several training providers sell food defence coordinator courses and some issue their own certification on a separate exam. What the certification schemes require is appropriate knowledge and competence, evidenced in your training records, and how you evidence it is left to you and your certification body.

Do I need to know PAS 96 if my site is certified to FSSC 22000?

You do not have to hold it, but you will struggle without it. FSSC clause 2.5.3 requires a threat assessment and a plan without prescribing a method. PAS 96:2026 is the publicly available specification most auditors expect to see behind that clause, and it supplies the threat actor categories, the access point thinking and the four success factors that make the assessment coherent.

Does the FDA Intentional Adulteration rule apply to a South African site?

It applies to food facilities registered with the FDA, which includes South African sites exporting to the United States. Farms are excluded, as are several activities listed in the rule. Very small businesses are exempt from most of it but still have to provide documentation to the FDA on request and keep it for two years.

How is food defence different from food safety?

Food safety deals with hazards that arrive by accident and are controlled by process. Food defence deals with acts somebody chooses to commit, which means the control is not a cook step but access, supervision, detection and response. A HACCP plan will not find a person who intends to cause harm, because HACCP assumes nobody is trying.

Can I complete food defence coordinator training without a site?

Yes, for ASC’s course. Every activity, including the graded practical, is built on the course case study, so consultants, students and people between roles can complete the whole thing.

About the author. Mthokozisi Nkosi is a food scientist, a registered Lead Auditor with Exemplar Global and IRCA, an HPCSA registered Environmental Health Practitioner, and one of four SAATCA registered R638:2018 Lead Implementers. He holds an MSc in International Public Health, an MSc in Data Science, an MBA and a BSc in Agriculture (Food Science and Technology), and is completing a PhD in Public Health. He founded ASC Food Safety Consultants, a SAATCA registered training centre (TC No. 065) and FoodBev SETA accredited provider, and builds and defends food defence plans on manufacturing sites. Connect on LinkedIn.

ASC Food Safety Training · Leading with Science. Ensuring Food Safety. · Fully online, serving all of South Africa and beyond · info@ascfoodsafety.com · WhatsApp +27 61 483 0381 · SAATCA registered training centre (TC No. 065) · FoodBev SETA accredited provider No. 587/00337/1900 · B-BBEE Level 1 · Registered Lead Auditor (Exemplar Global and IRCA) · Consulting and document toolkits at ascfoodsafety.com