Food defense assumes someone means to cause harm. Food fraud assumes someone means to make money – by substituting a cheaper ingredient, diluting a product, mislabeling its origin, or passing off a counterfeit as the real thing. The two get confused constantly, partly because they sound alike and partly because both show up as risk assessments a GFSI-recognized scheme will ask to see. They are not the same document, they do not cover the same threats, and a plan built for one does not satisfy the other.
VACCP and TACCP: Two Names, Two Different Threats
TACCP (Threat Assessment Critical Control Point) is the food defense methodology – it looks at intentional, malicious acts against your product: sabotage, extortion, tampering meant to cause harm or damage a brand. VACCP (Vulnerability Assessment Critical Control Point) is the food fraud methodology – it looks at economically motivated adulteration, where the person responsible isn’t trying to hurt anyone, just trying to profit by passing off something other than what the label says. Same acronym pattern, same general idea of walking your process for weak points, but a different motive drives a different assessment.
Economically Motivated Adulteration
Economically motivated adulteration, or EMA, covers a familiar set of patterns: substituting a lower-cost ingredient for the one on the label, diluting a product with a cheaper filler, concealing a quality defect, mislabeling origin or grade, counterfeiting packaging or certification marks, and diverting product through grey-market channels outside its intended distribution. None of it requires intent to sicken anyone – it requires an opportunity, an economic incentive, and a low chance of getting caught. That combination is exactly what a food fraud vulnerability assessment is built to find before a supplier or a commodity market gives someone the opening.
Why GFSI-Recognized Schemes Require Both
GFSI-recognized schemes such as BRCGS, SQF, and FSSC 22000 each require a documented food fraud vulnerability assessment, separate from the TACCP-style threat assessment covered on the food defense side. Scheme auditors treat it as a standing requirement, not a one-time exercise – they expect to see it revisited as ingredients, suppliers, and countries of origin change, not filed once during initial certification and left alone.
What a Vulnerability Assessment Has to Cover
A food fraud vulnerability assessment works through recognized fraud categories – substitution, dilution, concealment, unapproved enhancement, mislabeling, counterfeiting, and grey-market diversion or theft – and rates each one against your own raw materials, suppliers, and countries of origin. Commodities with a history of adulteration (think honey, olive oil, spices, seafood species substitution) or long, opaque supply chains carry more weight than a single-source ingredient you buy direct from the producer. The output isn’t a pass/fail; it’s a rated list of where your supply chain is thin, feeding into mitigation – testing, supplier verification, tighter specifications – wherever the rating crosses a threshold you’ve set.
Where Food Fraud Programs Fail
- There is no separate food fraud vulnerability assessment at all – it got folded into the food defense plan, or skipped because the facility assumed food defense already covered it.
- The assessment was done once, at initial certification, and never revisited as suppliers, ingredients, or sourcing countries changed.
- It’s a generic, industry-level document instead of one rated against the facility’s own raw materials and actual suppliers.
- Higher-risk findings sit in the document with no mitigation attached – the vulnerability was identified and then nothing changed.
The Companion Piece, Not the Same Piece
If you haven’t already, it’s worth reading what a food defense plan has to cover alongside this one – the two are constantly asked for together, constantly confused with each other, and rated by an auditor as two separate line items. Knowing which threat each one addresses is most of the battle in keeping them straight.
How HACCP Builder Helps
A Food Fraud Vulnerability template ships as part of the Sub Plan library – covering all eight recognized fraud categories, from substitution and dilution to counterfeit and grey-market diversion, with a rating scale and a mitigation threshold you define. It’s a structured starting document, not a blank form, and it stays with the rest of your program rather than living as a separate file. Customizable checklists cover the broader set of programs that sit outside a traditional HACCP plan – food fraud and food defense risk assessments among them – described in more detail on the GFSI-recognized schemes page.
What This Is, and What It Is Not
This is a structured written program, not a scoring engine. HACCP Builder gives you a well-built starting document and a place to keep your ratings and mitigation decisions together – it does not decide your risk ratings for you or research your suppliers automatically. The judgment about which commodities and suppliers are actually vulnerable is still yours; the blank page is not.
Contact HACCP Builder to see how a food fraud vulnerability assessment fits into your own program.
We can be reached at (866) 577-4030 ext. 800 or via email at [email protected]. Leave us a message or book a free demo today!





