Food Fraud Vulnerability Assessment: Step-by-Step Guide [2026]

iComplai
Guide · Food fraud

Build your food fraud vulnerability assessment with this 7-step guide. Templates, high-risk ingredients, and AI-powered tools to strengthen your FFVA.

Linocut-style illustration of workers passing a crate hand to hand along a loading dock. Between two of them the crate hangs in mid-air, momentarily held by nobody: the worker who let go has already turned away and the next has not yet turned round.
Fraud does not need a broken chain — one unheld moment in a well-run handover is enough. The assessment’s job is to find that moment before someone else does.

A food fraud vulnerability assessment (FFVA) is no longer a nice-to-have document sitting in a binder. Estimates of what food fraud costs vary widely with method — the FDA reports outside expert estimates that food fraud affects about 1% of the global food industry at a cost of $10–15 billion a year, with more recent estimates as high as $40 billion — and the figures circulating in trade coverage are often relayed from private datasets rather than published research. What is not in doubt is the compliance position: a documented vulnerability assessment is a certification requirement, and BRCGS Issue 9 examines it clause by clause — the assessment itself under 5.4.3, the assurance and testing that follow it under 5.4.4. This guide walks you through exactly how to build, document and operationalise yours.

Key facts

What does a food fraud vulnerability assessment have to cover?

A food fraud vulnerability assessment is a documented judgement about where in your supply chain someone has both a motive and an opportunity to adulterate, substitute, dilute or mislabel a raw material, and what you do about it. It is not optional for certified sites: GFSI made it mandatory across every benchmarked scheme, and BRCGS carries the requirement in clause 5.4.3, with the mitigation plan and its assurance or testing processes in clause 5.4.4. The distinction that trips teams up is that a vulnerability assessment is not a hazard analysis. HACCP asks what can go wrong unintentionally; a fraud assessment assumes an actor who is trying not to be caught, so it weighs economic incentive, supply-chain opacity and how easily a substitution would pass the tests you actually run.

Definitions

What is a food fraud vulnerability assessment?

A food fraud vulnerability assessment is a structured, documented process that identifies which raw materials, ingredients, and supply chain touchpoints in your operation are susceptible to economically motivated adulteration (EMA). Unlike a food safety hazard analysis, which focuses on accidental contamination, an FFVA targets intentional deception for financial gain.

The assessment answers three core questions:

  1. Which ingredients are vulnerable? Based on historical fraud data, economic drivers, and supply chain complexity.
  2. How likely is fraud to reach your facility undetected? Based on supplier controls, testing capabilities, and traceability gaps.
  3. What controls reduce that likelihood to an acceptable level? Your mitigation plan, linked directly to the vulnerabilities you identified.

Every GFSI-benchmarked scheme requires this document; the clause that applies to your certificate is set out below. The output feeds directly into your food fraud mitigation plan and should be reviewed at minimum annually, or whenever a material change occurs in your supply chain.

Taxonomy

What are the four types of food fraud?

The four types of food fraud a manufacturer meets most often are adulteration, substitution, mislabelling and counterfeiting. Adulteration adds a cheaper or undeclared substance to the authentic material; substitution replaces the ingredient outright; mislabelling falsifies origin, species, grade or organic status while the product itself stays untouched; counterfeiting replicates a brand’s packaging and identity. GFSI’s own food fraud technical document sets out seven — dilution, substitution, concealment, unapproved enhancement, mislabelling, grey market/theft/diversion and counterfeiting — but these four account for most of what arrives at a factory gate, and they split cleanly into fraud that changes the substance and fraud that changes only the story:

The four types of food fraud — what is falsified, and where THE SUBSTANCE IS CHANGED ONLY THE STORY IS CHANGED Adulteration A cheaper or undeclared substance is added to increase volume or apparent quality. Olive oil diluted with sunflower oil Substitution The ingredient is replaced entirely with a cheaper alternative. Farmed fish labelled as wild-caught Mislabelling Label information on origin, species, grade or organic status is falsified. The product itself may be untouched. Conventional produce claimed organic Counterfeiting A branded product’s packaging and identity are replicated and sold as the genuine article. Fake branded infant formula
The taxonomy the article’s scoring steps depend on: two of the four types change the substance, two only change its story.
The four fraud types a vulnerability assessment has to consider, and why routine specification testing can miss each one. Requirement basis: GFSI Benchmarking Requirements Part III (v7.0, 2017; restated v7.2, 2018) and BRCGS Issue 9 clause 5.4.3.
Type What is done Example Why routine testing can miss it
Adulteration A cheaper or undeclared substance is added to increase volume or apparent quality; dilution is the same move carried out at scale Diluting olive oil with sunflower oil The added substance is often not on the specification's test panel at all, and dilution moves values within specification rather than outside it
Substitution Part or all of the material is replaced with a cheaper alternative Labelling farmed fish as wild-caught A substitute chosen to match the tested parameter passes that parameter
Mislabelling Origin, species, grade, production method or organic status is misstated Claiming conventional produce is organic Nothing in the material is wrong, only the claim about it, so composition testing is blind to it
Counterfeiting A branded product's packaging and identity are replicated and sold as the genuine article Fake branded infant formula Often reaches the market outside approved supply routes, where supplier controls and CoAs may not see it

The European Commission’s monthly reports on EU agri-food fraud suspicions for March and April 2026 (203 and 188 suspicions) put the largest share under implicit claim violations and falsified records rather than substance adulteration, and the products drawing most suspicion were food supplements, fruit and vegetables and fish — a reminder that documentary and claim fraud, not exotic adulterants, is what surveillance actually catches.

Your FFVA should assess vulnerability to all four types for each ingredient or material in scope.

The mandate

Why is a food fraud vulnerability assessment mandatory?

A food fraud vulnerability assessment is mandatory because GFSI requires one of every certification scheme it benchmarks. The two key elements — a documented vulnerability assessment and a documented mitigation plan — were added to Part III of the GFSI Benchmarking Requirements in version 7.0 (2017) and restated in version 7.2 (2018), and GFSI sets out the expectation in its own technical guidance on tackling food fraud through food safety management systems (GFSI, GFSI). BRCGS carries it in clause 5.4 on product authenticity, claims and chain of custody: clause 5.4.3 requires a documented vulnerability assessment on all food raw materials or groups of raw materials to assess the potential risk of adulteration or substitution, and clause 5.4.4 requires the resulting plan to include appropriate assurance and/or testing processes (BRCGS). For a site holding or seeking any GFSI-recognised certification, the assessment is a pass/fail item, not a best practice.

Is regulatory pressure on food fraud increasing?

Border enforcement is rising independently of certification. iComplai’s record of FDA import refusals grows from 9,369 in 2024 to 13,575 in 2025 — a 45 per cent increase in a single year, and nearly double the 7,204 recorded in 2023 (iComplai platform data, as at 2 September 2026). Most of that growth sits in additive, labelling and process-control charges rather than fraud specifically — fraud-categorised refusals rose 13 per cent, to 2,017 — but the direction is the same: the volume of border findings a single supplier can generate against you is climbing fast. A robust FFVA is your first line of defence against both audit nonconformities and regulatory action.

The schemes

Which certification schemes require an FFVA?

BRCGS, FSSC 22000 and SQF all require a documented food fraud vulnerability assessment and a mitigation plan, but each names the requirement in a different clause, and quoting the wrong one at audit is a needless own goal. Here is where the requirement actually sits:

  • BRCGS Food Safety Issue 9 (clauses 5.4.1–5.4.4): requires a documented vulnerability assessment on all food raw materials or groups of raw materials, carried out by personnel who understand food fraud risk, informed by fraud intelligence, reviewed at least annually, with assurance and/or testing where a material is at particular risk. Packaging is handled separately, under 3.5.1 and 5.5.
  • FSSC 22000 v6 (Additional Requirement 2.5.4, vulnerability assessment at 2.5.4.1): mandates a documented procedure to identify and assess potential vulnerabilities to food fraud, and a documented mitigation plan covering the products and processes in scope.
  • SQF Edition 9 (Part B, System Element 2.7.2 Food Fraud): requires a documented food fraud vulnerability assessment covering raw materials, ingredients, packaging and finished product, plus a documented mitigation plan reviewed annually.
  • ISO 22000:2018 on its own: contains no food fraud vulnerability assessment requirement at all, and mentions food fraud only as an example of an external issue in the note to clause 4.1. Sites running ISO 22000 pick the requirement up through FSSC 22000’s additional requirement 2.5.4, which is where the vulnerability assessment and the mitigation plan actually sit.
The method

How do you conduct a food fraud vulnerability assessment?

A food fraud vulnerability assessment is built in seven steps: define the scope, gather fraud intelligence, score each ingredient, evaluate existing controls, prioritise high-risk materials, develop mitigation measures, then document and review. The order matters — each step consumes the output of the one before it, and the seventh feeds back into the first.

The FFVA is a loop, not a form — seven steps, then back to the top 1Define the scope 2Gather intelligence 3Score ingredients 4Controls 5Prioritise high-risk 6Develop mitigation 7Review, update back to 1
Seven steps, and the seventh points back at the first — GFSI expects the assessment reviewed and updated, not filed.

Step 1: Define the Scope

Step 1 fixes what the assessment covers. List every raw material, processing aid, packaging material and finished product that enters your facility, and include traded goods and co-manufactured products. If you operate across multiple sites, clarify whether each site maintains its own FFVA or rolls up to a corporate-level assessment.

Step 2: Gather Fraud Intelligence

Step 2 builds the evidence base every later score rests on. For each item in scope, collect current data on:

  • Historical fraud incidents for that ingredient category (databases: the FoodChain ID Food Fraud Database — formerly the USP/Decernis database — the RASFF Window, the European Commission’s EU Agri-Food Fraud Network monthly reports, HorizonScan, and USP’s free Food Fraud Mitigation Guidance)
  • Economic drivers such as price spikes, supply shortages, geopolitical disruption
  • Regulatory alerts including import refusals, recalls, and enforcement actions
  • Media reports covering emerging fraud patterns and regional trends

This is the most time-intensive step, and where the quality of your assessment is determined. Stale data produces stale risk scores. Automated regulatory monitoring keeps notifications, recalls and border findings flowing in between reviews rather than only at them.

Step 3: Score the Vulnerability of Each Ingredient

Step 3 turns that intelligence into a comparable number. Apply a structured scoring method — the SSAFE food fraud vulnerability assessment tool is widely accepted, but many organisations use a simplified matrix for ingredient risk assessment. At minimum, score each ingredient across two dimensions:

  • Likelihood of fraud occurrence (considering history, economic motivation, supply chain complexity, and ease of adulteration)
  • Likelihood of detection failure (considering your current testing, supplier audits, and traceability controls)

Multiply or combine scores to produce an overall vulnerability rating (e.g., Low / Medium / High / Critical).

Step 4: Evaluate Your Supply Chain Controls

Step 4 asks how likely those controls are to catch fraud if it happens. For each ingredient, document what is already in place:

  • Supplier approval, supplier verification and ongoing monitoring
  • Certificate of Analysis (CoA) verification
  • Analytical testing (identity, authenticity, isotope, DNA)
  • Traceability and mass balance checks
  • Contractual requirements and specifications

Weak controls increase your detection-failure score. Be honest here; auditors will test this.

Step 5: Prioritise High-Risk Materials

Step 5 decides where the mitigation budget goes. Rank ingredients by overall vulnerability score and concentrate resources on those scoring High or Critical: in most facilities a small minority of incoming materials accounts for the bulk of the fraud risk.

Step 6: Develop Mitigation Measures

For every high-risk ingredient, assign specific, measurable mitigation actions. Examples:

  • Switch from CoA reliance to independent third-party testing for high-risk lots
  • Add isotope ratio mass spectrometry (IRMS) testing for honey or olive oil — see our guide to honey adulteration detection and testing methods
  • Require origin-verified supply chain documentation for spices
  • Implement unannounced supplier audits for critical suppliers
  • Establish dual-sourcing with qualified alternates to reduce supply disruption incentives

Step 7: Document, Review, and Update

Your FFVA is a living document. Schedule formal reviews at least annually and trigger ad hoc reviews when:

  • A new supplier is onboarded
  • A fraud alert is issued for an ingredient you use
  • Significant price volatility occurs in a commodity category
  • An audit finding identifies a gap

Document every review with date, participants, changes made, and rationale.

From iComplai

Your vulnerability list ages the moment you sign it off.

An FFVA is a point-in-time judgement, and the evidence behind it — refusals, fraud-flagged notifications, price and origin shifts — moves every week. iComplai watches those signals against your own ingredient list and tells you when a score no longer holds.

See how the screening works
Hot spots

Which ingredients are at highest risk of food fraud?

Honey, olive oil, spices, seafood, meat, coffee and organic produce are the categories most consistently targeted, because each combines high value, a complex supply chain and difficulty of detection. They are a vulnerability list, not an incidence ranking: by notification volume, food supplements and fortified foods currently draw more fraud suspicions than any of them — 202 fraud-flagged RASFF notifications in 2025–26 on iComplai’s record, against 7 for honey — so add supplements to any scope that includes them.

Ingredient Common Fraud Types Red Flags
Honey Adulteration with sugar syrups, geographic origin fraud Price below production cost, unclear origin chain, C4 sugar anomalies
Olive oil Dilution with cheaper oils, false extra virgin claims Price inconsistencies, mixed-origin blends lacking traceability
Spices (oregano, paprika, turmeric, saffron) Bulking with plant matter, synthetic dye addition, species substitution Sudan dyes in paprika, olive leaf in oregano, low volatile oil content
Seafood/fish Species substitution, origin mislabelling DNA mismatch, pricing below market for claimed species
Meat Species substitution, water/protein injection, origin fraud Unusually low pricing, inconsistent protein-to-moisture ratios
Coffee Substitution with cheaper beans, addition of fillers Robusta sold as Arabica, presence of barley or corn starch
Organic products Fraudulent organic certification, conventional sold as organic Pesticide residue presence, certification document inconsistencies

If any of these categories appear in your ingredient list, they should automatically receive heightened scrutiny in your vulnerability scoring. See also our reports on the Opson XIII food fraud crackdown and on dried tomato skins found in red chilli pepper.

The template

What should a food fraud vulnerability assessment template include?

A food fraud vulnerability assessment template needs nine sections: scope and objectives, the assessment team, an ingredient register, a fraud-intelligence summary, a scoring matrix, a control inventory, a risk ranking, a mitigation plan and a review log. Your FFVA document should be audit-ready. At minimum, include the following sections:

1. Scope and Objectives

  • Sites covered, product categories, date of assessment

2. FFVA Team

  • Names, roles, and qualifications of the assessment team (demonstrates E-E-A-T to auditors)

3. Ingredient/Material Register

  • Complete list of all in-scope items with supplier details

4. Fraud Intelligence Summary

  • Sources consulted, date ranges, key findings per ingredient category

5. Vulnerability Scoring Matrix

  • Scoring criteria, scale definitions, and individual scores per ingredient
  • Clearly show the method: likelihood of occurrence x likelihood of detection failure

6. Current Control Inventory

  • Existing controls mapped to each ingredient

7. Risk Ranking

  • Prioritised list from highest to lowest vulnerability

8. Mitigation Plan

  • Specific actions for High/Critical items (see next section)

9. Review Log

  • Dates of reviews, trigger events, changes made, sign-off

Food fraud checklist for quick self-audit:

All raw materials and packaging in scope
Fraud intelligence data is less than 12 months old
Scoring method is documented and consistently applied
High-risk ingredients have specific mitigation actions assigned
Supplier approval programme references fraud controls
Testing programme includes authenticity testing for high-risk items
FFVA has been reviewed within the last 12 months
Review triggered by any material supply chain changes
Document is signed off by a responsible senior manager
Mitigation

What is a food fraud mitigation plan?

A food fraud mitigation plan is the documented set of controls a site puts in place against the vulnerabilities its assessment identified: one entry per high-risk material, naming the fraud scenario, the controls already in place, the gap, the new action, the person who owns it and the date it is due. The vulnerability assessment finds the risk; the mitigation plan is the answer to it, and auditors will expect a direct, traceable link between the two.

Structure your plan around these elements:

For each high-risk ingredient:

  1. Vulnerability identified: State the specific fraud type and scenario (e.g., "Oregano: adulteration with olive leaves, historically prevalent in Mediterranean-sourced supply").
  2. Current controls: What is already in place.
  3. Gap analysis: Where current controls are insufficient.
  4. Mitigation action: Specific, measurable intervention with a responsible owner and deadline.
  5. Verification method: How you will confirm the mitigation is effective (e.g., testing results, audit outcomes).
  6. Review frequency: When this mitigation will be reassessed.

Mitigation actions should be proportionate to risk. A Critical-rated ingredient from a single-source supplier in a high-fraud region warrants aggressive controls: independent lab testing, unannounced audits, mass balance reconciliation. A Medium-rated ingredient with strong traceability and multiple qualified suppliers may need only enhanced CoA verification and periodic spot testing.

Document everything. If it is not documented, it did not happen, at least as far as your auditor is concerned.

Technology

How is AI changing food fraud detection?

AI is changing food fraud detection by moving the intelligence step from periodic to continuous. Traditional FFVAs rely on historical databases, published alerts and manual literature reviews, and by the time a fraud incident appears in a database it has already happened, often months or years earlier — you are scoring vulnerability against yesterday’s data. Machine-read screening covers the same official sources every day, alongside trade data, pricing feeds and news, so a change in an ingredient’s risk profile reaches the assessment when it appears rather than at the next annual review.

AI-powered food fraud detection tools change this by:

  • Aggregating real-time signals across regulatory databases, trade data, pricing feeds, news sources, and supply chain records, continuously rather than at annual review intervals
  • Identifying emerging risk patterns before they become documented incidents, such as price anomalies in a commodity that historically precede fraud spikes
  • Scoring supplier and ingredient risk dynamically so your FFVA reflects current conditions, not last year's snapshot
  • Reducing manual intelligence-gathering time from weeks of research to minutes of automated screening
Predictive screening

What can predictive screening do that a database review cannot?

A database review tells you what has already been reported; predictive screening tells you where the next report is most likely to come from, by watching price moves, trade shifts and notification patterns that historically run ahead of a fraud spike. Regulators are heading the same way: the FDA’s AI Imported Seafood Pilot — now in its third phase, still a pilot and still limited to seafood — shows where they intend to take import targeting, alongside a 45 per cent rise in recorded refusals in 2025. Platforms like iComplai apply AI across a base of more than 7.5 million records — authority notifications, border refusals and monitored media — screening several thousand new food safety signals a day and turning them into food fraud risk prediction that compliance teams can feed directly into their FFVA scoring. Instead of relying on static annual reviews, teams monitor risk continuously and trigger a reassessment when the data shifts.

Whether you use AI-powered tools or maintain a manual process, the principle is the same: your FFVA is only as strong as the intelligence behind it. Fresher, broader, and more granular data produces more accurate vulnerability scores, which produces more targeted mitigation, which produces fewer surprises at audit time and in your supply chain.

FAQ

Food fraud vulnerability assessment FAQ

How often must a food fraud vulnerability assessment be reviewed?

At least once a year, and immediately whenever something changes: a new supplier is onboarded, a fraud alert is issued for an ingredient you use, a commodity sees sharp price volatility, or an audit finding exposes a gap. BRCGS Issue 9 sets the annual minimum explicitly, and every review should be logged with its date, participants, changes and rationale.

What is the difference between an FFVA and HACCP?

HACCP asks what can go wrong unintentionally. A food fraud vulnerability assessment assumes an actor who is trying not to be caught, so it weighs economic incentive, supply-chain opacity and how easily a substitution would pass the tests you actually run. A material can be entirely safe under HACCP and still score as highly vulnerable to fraud.

Does BRCGS Issue 9 require a separate food fraud mitigation plan?

Yes. Clause 5.4.3 requires the documented vulnerability assessment on food raw materials or groups of raw materials, and clause 5.4.4 requires the plan that follows from it, including appropriate assurance and testing processes where a material is at particular risk.

Which ingredients need the closest scrutiny in an FFVA?

Honey, olive oil, spices, seafood, meat, coffee and organic produce are the perennial targets, because each combines high value, a complex supply chain and difficulty of detection. That is a vulnerability list rather than an incidence ranking: by notification volume, food supplements and fortified foods currently draw more fraud suspicions than any of them.

Is the SSAFE food fraud vulnerability assessment tool mandatory?

No. The SSAFE food fraud vulnerability assessment tool is widely accepted and easy to defend at audit, but a simple matrix scoring likelihood of fraud against likelihood of detection failure also meets the requirement, provided the method is documented, applied consistently and supported by current fraud intelligence.

Does ISO 22000 require a food fraud vulnerability assessment?

Not on its own. ISO 22000:2018 contains no food fraud vulnerability assessment requirement and mentions food fraud only as an example of an external issue in the note to clause 4.1. Sites running ISO 22000 pick the requirement up through FSSC 22000 additional requirement 2.5.4, where the assessment and the mitigation plan actually sit.

Where iComplai fits

See the signals before they become findings

iComplai monitors authority notifications, recalls and adulteration signals for your own materials and suppliers, daily.

Talk to iComplai
References

Where these claims come from

  1. GFSI. Tackling Food Fraud Through Food Safety Management Systems (technical document). mygfsi.com
  2. Global Food Safety Initiative. What we do / benchmarking. mygfsi.com
  3. BRCGS. Global Standard for Food Safety — clause 5.4 product authenticity; 5.4.3 vulnerability assessment, 5.4.4 mitigation plan. brcgs.com
  4. U.S. FDA. Economically Motivated Adulteration (Food Fraud) — outside expert cost estimates. fda.gov
  5. European Commission. Monthly reports on EU Agri-Food Fraud suspicions — March 2026 (203 suspicions) and April 2026 (188 suspicions). food.ec.europa.eu
  6. U.S. FDA. The FDA Moves into Third Phase of Artificial Intelligence Imported Seafood Pilot Program (HFP constituent update). fda.gov
  7. FSSC. FSSC 22000 (v6) — additional requirement 2.5.4, food fraud mitigation. fssc.com
  8. SQF Institute. Food Fraud Guidance Document, Edition 9 — system element 2.7.2. sqfi.com
  9. iComplai. Food fraud risk prediction — FDA import refusal counts and RASFF fraud-flagged notification counts quoted above are iComplai platform data, as at 2 September 2026. iComplai food safety intelligence platform
Ömer Korkmaz