Food fraud is the intentional deception of buyers or consumers about food for economic gain — substitution, dilution, mislabeling, counterfeiting, or misrepresenting a product's origin, species, or ingredients. Manufacturers manage this risk through a Vulnerability Assessment Critical Control Point (VACCP) process, while Threat Assessment Critical Control Point (TACCP) covers the separate risk of malicious, intentional contamination. Both are now standalone, actively audited requirements across GFSI-recognized certification schemes, not background paperwork.
VACCP vs. TACCP vs. food defense: three different threats
These three programs are easy to conflate because they all sit outside ordinary hazard analysis, but they answer different questions. Food safety programs like HACCP address accidental, unintentional contamination. Food defense, assessed through TACCP, addresses intentional but malicious harm — sabotage, tampering, or an insider attack meant to hurt people or a brand. Food fraud, assessed through VACCP, addresses intentional deception for financial gain — the adulteration itself isn't necessarily meant to harm anyone, but the economic deception can still create a real safety risk if, for example, a cheaper undeclared substitute triggers an undisclosed allergen.
Why GFSI schemes now require a food fraud vulnerability assessment
Food fraud and food defense have moved from supporting documentation to standalone, actively audited requirements across the major GFSI-recognized schemes. BRCGS Food Safety Issue 9 requires a documented food fraud vulnerability assessment conducted by a team that understands the site's raw materials and the principles of vulnerability assessment, reviewed at least annually or whenever there's a significant change in raw materials, suppliers, or market conditions. FSSC 22000 Version 6 goes a step further and requires a documented procedure for how the assessment is conducted, not just the completed assessment record itself. Auditors under both schemes now expect to see a defined methodology, a cross-functional team, and evidence of periodic review — not a one-time form filled out for the last audit and never revisited.
How to conduct a food fraud vulnerability assessment
- Map raw materials and suppliers. Start with ingredients that have a documented history of adulteration — olive oil, honey, spices, seafood, and dairy are common industry examples — and the suppliers behind them.
- Review fraud history and data. Pull known incident data, industry alerts, and any supplier-specific red flags, including price volatility that can create an incentive to cut corners.
- Score likelihood and impact. Rate each raw material and supplier combination for how likely fraud is and how severe the consequence would be if it happened.
- Assign mitigations. Document the specific control for each significant vulnerability — supplier verification, certificate of analysis review, targeted testing, or sourcing changes.
- Review annually, or sooner if something changes. A new supplier, a new raw material, or a market disruption (like a shortage that spikes prices) should trigger an off-cycle review rather than waiting for the scheduled one.
Where IONI fits
Keeping supplier documentation, certificates of analysis, and vulnerability-assessment evidence connected to the ingredients they actually cover is what makes a food fraud vulnerability assessment defensible at audit — not just a completed template. See how IONI Ingredients Intelligence helps food manufacturers manage supplier and ingredient risk.
Frequently asked questions
What's the difference between food fraud and food defense?
Food fraud (assessed through VACCP) is intentional deception for financial gain, like substituting a cheaper ingredient. Food defense (assessed through TACCP) is intentional, malicious contamination meant to cause harm. The motive, and the controls used to manage each, are different.
Is a food fraud vulnerability assessment mandatory?
It's required by the major GFSI-recognized certification schemes, including BRCGS Food Safety Issue 9 and FSSC 22000 Version 6, as a condition of certification. It generally isn't a standalone US federal regulatory requirement in the way HARPC is, but it's a practical necessity for any manufacturer holding or pursuing GFSI certification.
How often should a food fraud vulnerability assessment be reviewed?
At least annually, and sooner if there's a significant change in raw materials, suppliers, or market conditions that could raise the incentive or opportunity for fraud.
What ingredients are most commonly targeted by food fraud?
Olive oil, honey, spices (like saffron and paprika), seafood, and dairy products have well-documented histories of substitution, dilution, and mislabeling, and are typically prioritized first in a vulnerability assessment.


