Food Fraud Vulnerability Assessment: What FSSC 22000 Version 7 Requires
Food fraud vulnerability assessment became a mandatory requirement under FSSC 22000 Version 7, released in May 2026 and fully effective for all certified organisations. Businesses preparing for certification should also understand the FSSC 22000 V7 Transition Common Mistakes Companies Must Avoid to identify common implementation gaps, reduce audit risks, and ensure a smooth transition to the latest scheme requirements.
This article explains what a food fraud vulnerability assessment is, what FSSC 22000 v7 specifically requires, and how to build one that holds up under a GFSI-recognised certification audit.
What Is a Food Fraud Vulnerability Assessment?
A food fraud vulnerability assessment is a systematic evaluation of where and how your food products, ingredients, or processes could be vulnerable to deliberate adulteration, substitution, mislabelling, counterfeiting, or misrepresentation for economic gain. The formal term for this type of fraud is economically motivated adulteration (EMA). It is distinct from accidental contamination and from food defence, which addresses intentional harm with malicious rather than financial intent.
Understanding the differences between food fraud vs food defense is essential, as FSSC 22000 Version 7 requires organizations to implement controls for both risks as part of a comprehensive food safety management system.
The output of a food fraud vulnerability assessment is a documented analysis of your supply chain vulnerabilities, ranked by likelihood and impact, with control measures assigned to each significant vulnerability. This document, together with your monitoring and verification procedures, forms your food fraud mitigation plan. Under FSSC 22000 Version 7, both the vulnerability assessment and the mitigation plan must be in place and auditable.
Common examples of food fraud that Malaysian food manufacturers should assess include adulterated palm oil or cooking oil, mislabelled species in seafood products, diluted or substituted spices and seasonings, fraudulent halal status claims in ingredient supply chains, and false country of origin declarations on imported raw materials.
Businesses new to the scheme may also benefit from understanding the difference between ISO 22000 and FSSC 22000, as FSSC 22000 builds upon ISO 22000 by introducing additional requirements such as food fraud prevention, food defense, and food safety culture.

What FSSC 22000 Version 7 Specifically Requires for Food Fraud
FSSC 22000 Version 7 elevated food fraud from a recommended additional requirement to a mandatory element of the food safety management system. Under the FSSC 22000 v7 scheme requirements, certified organisations must meet the following obligations:
- Explicit Competence Requirements: Having a written plan on file is no longer enough. V7 explicitly mandates that the personnel responsible for developing, maintaining, and reviewing the food fraud vulnerability assessment and mitigation plan must demonstrably possess the competence, training, and knowledge to do so.
- Conduct a documented food fraud vulnerability assessment covering all raw materials, ingredients, packaging materials, and outsourced processes. The assessment must evaluate vulnerability factors including the history of fraud for each ingredient, economic opportunity for adulteration, detection difficulty, and supply chain complexity.
- Develop and implement a food fraud mitigation plan that assigns specific control measures to each vulnerability identified as significant. Controls must be practical, verifiable, and monitored.
- Integrate food fraud controls into the food safety management system so that changes to suppliers, ingredients, or processes trigger a review of the vulnerability assessment.
- Verify the effectiveness of mitigation measures through documented verification activities, including supplier audits, authenticity testing, and certificate of analysis reviews.
How to Conduct a Food Fraud Vulnerability Assessment Under FSSC 22000 v7
A food fraud vulnerability assessment under FSSC 22000 Version 7 follows a structured process. One of the GFSI-recommended approach is the SSAFE (Safe Supply of Affordable Food Everywhere) vulnerability assessment tool, which is accepted by FSSC 22000 auditors and available publicly.
- List all raw materials, ingredients, and packaging. Include every input that could be adulterated, substituted, or mislabelled. Do not exclude items because they seem low-risk at first glance. Palm oil, spices, seafood, dairy ingredients, and honey are frequently targeted globally.
- Assess vulnerability factors for each item. The SSAFE tool evaluates four factors: the historical record of fraud for the ingredient, the economic motivation to commit fraud, the ease of detection if fraud occurs, and the complexity of the supply chain. Score each factor and calculate an overall vulnerability rating.
- Identify significant vulnerabilities. Items scoring above your defined threshold are classified as significant vulnerabilities requiring a control measure. Your threshold must be documented and justified.
- Assign control measures. For each significant vulnerability, assign a practical control. Examples include supplier audits, certificate of analysis requirements, authenticity testing for high-risk ingredients, approved supplier lists with verification procedures, and third-party laboratory testing at incoming goods inspection.
- Document and implement the mitigation plan. Record all controls, assign responsibility, define monitoring frequency, and integrate the plan into your existing food safety management system. Controls that exist only on paper will not pass an FSSC 22000 v7 audit.
- Review when changes occur. Any change to a supplier, ingredient, or sourcing region must trigger a review of the relevant vulnerability assessment entries. FSSC 22000 v7 auditors will ask when the assessment was last reviewed and what triggered the review.
Food Fraud Risks Specific to Malaysian Food Manufacturers
Malaysian food manufacturers face food fraud vulnerabilities that reflect the local supply chain environment. Auditors conducting FSSC 22000 v7 certification audits in Malaysia are familiar with these and will assess whether your vulnerability assessment has addressed them.
- Palm oil and palm-based ingredients. Malaysia is a major palm oil producer and exporter. Adulteration with cheaper oils or misrepresentation of grade and origin are documented fraud risks in this supply chain. If your product contains palm derivatives, your vulnerability assessment must address this explicitly.
- Seafood species substitution. Mislabelling of fish species is one of the most globally documented forms of food fraud. Malaysian seafood processors and exporters should assess substitution risk for all species in their product lines.
- Spices and seasonings. Turmeric, chilli powder, and pepper are high-risk categories globally for dilution, substitution, and adulteration with Sudan dyes. Malaysian food manufacturers using spice inputs from multiple suppliers should treat these as significant vulnerabilities.
- Halal ingredient integrity. For FSSC 22000 certified manufacturers also holding halal certification from the Department of Islamic Development Malaysia (JAKIM), the supply chain integrity of halal-declared ingredients is both a religious obligation and a food fraud risk. Fraudulent halal status in imported ingredients is a documented issue in global supply chains.
- Imported raw materials. Country of origin fraud and quality substitution in imported ingredients are risks that must be assessed for any input sourced outside Malaysia, particularly from regions with less rigorous food safety regulation.
Food Fraud Controls is An Audit Requirement Under FSSC 22000 v7
FSSC 22000 Version 7 has removed any ambiguity about food fraud controls. They are mandatory, they must be operational, and they will be assessed during your certification audit. Malaysian food manufacturers that treat the food fraud vulnerability assessment as a documentation exercise rather than a functioning management tool will face non-conformities. Building the assessment properly from the start, using an accepted methodology like the SSAFE tool and integrating controls into daily operations, is the only approach that consistently passes audit.
If you’re still deciding which food safety certification best suits your business, explore our comparisons of HACCP vs FSSC 22000 and BRCGS vs FSSC 22000 to understand their requirements, benefits, and suitability for local and export markets.
Ready to get FSSC 22000 certified and open export markets? Contact Connext Consulting.
Frequently Asked Questions
What is VACCP in food safety?
VACCP stands for Vulnerability Assessment and Critical Control Points. It is the systematic process for identifying and controlling food fraud risks in your supply chain, specifically adulteration or misrepresentation motivated by economic gain. VACCP is distinct from HACCP, which addresses accidental or unintentional food safety hazards.
What is the difference between VACCP and TACCP?
VACCP (Vulnerability Assessment and Critical Control Points) addresses food fraud, deliberate adulteration for economic gain. TACCP (Threat Assessment and Critical Control Points) addresses food defence, intentional contamination for malicious purposes such as extortion or terrorism. FSSC 22000 v7 requires controls for both, but they use different assessment methodologies and address different threat actors.
Who should conduct the food fraud vulnerability assessment?
FSSC 22000 v7 requires a multidisciplinary team eg: VACCP team with expertise across purchasing, production, quality, legal, and regulatory affairs. The team needs direct knowledge of your supply chain and ingredient sourcing. External consultants are often involved to ensure the assessment methodology is accepted by auditors.
Is food fraud vulnerability assessment mandatory under FSSC 22000 Version 7?
Yes. FSSC 22000 Version 7made food fraud vulnerability assessment a mandatory requirement. Organisations must have a documented assessment, a mitigation plan with assigned controls, and evidence that the plan is reviewed when supply chain changes occur.
How often should the food fraud vulnerability assessment be reviewed?
At minimum annually, and immediately whenever there is a change in suppliers, ingredients, sourcing regions, or product formulation. FSSC 22000 v7 auditors specifically check what triggered the most recent review, a review done only on a fixed calendar schedule with no change-triggered reviews is a common non-conformity finding.






