Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Food Fraud and Food Defense governance document cover page.

Food Fraud and Food Defense: Why They Are Not the Same

Food fraud and food defense are routinely treated as the same discipline, and the two words are often used interchangeably in the same sentence. They are not the same. They have different motivations, need different assessments, produce different plans, and under FSSC 22000 they are separate requirements that both have to be met.

Conflating them is how a site ends up with one document that satisfies neither.

What this guide covers

food fraud explained
Food fraud and food defense share some controls, but the motive is opposite and so is the strategy.

Food fraud versus food defense: the actual difference

The distinction is motive.

Food fraud Food defense
Motivation Economic gain Intent to cause harm
Typical actor A supplier, an intermediary, or an insider A disgruntled individual, an intruder, an ideological actor
Typical method Substitution, dilution, mislabelling, counterfeiting, origin misrepresentation Deliberate contamination or damage
Assessment type Vulnerability assessment Threat assessment
Detected by Authenticity testing, mass balance, price monitoring Access control, surveillance, tamper evidence
FSSC clause 2.5.4 2.5.3

An economically motivated actor wants the product to pass. Someone intending harm wants it to fail. Those opposite goals produce opposite control strategies, which is why a single combined assessment tends to be weak at both.

What FSSC 22000 requires for food fraud

Requirement 2.5.4 has three parts, and applies to all food chain categories.

The vulnerability assessment and the mitigation plan must be developed and maintained by personnel with appropriate knowledge and competence — a named competence requirement that is audited. The plan must be implemented, supported by the FSMS, legally compliant, cover the processes and products in scope, and be kept up to date. And for subcategory FII, brokers and traders must additionally ensure their own suppliers hold a food fraud mitigation plan.

Under Version 7 there is a second layer. Food fraud prevention now also sits in the common prerequisite programme standard, at clause 16.3. Both layers apply — see our guide to the 2025 ISO 22002 prerequisite programmes.

Running a food fraud vulnerability assessment

Assess every raw material, ingredient, processing aid and packaging item. The fraud types to consider are well established: dilution, substitution, concealment, unapproved enhancement, mislabelling, grey-market diversion, counterfeiting and origin misrepresentation.

What raises vulnerability, in rough order of usefulness:

  • Economic driver — a large or volatile price gap between the genuine material and a plausible substitute
  • Historical evidence — known food fraud in this material, species, region or supply route
  • Detectability — whether any routine test would identify the adulteration
  • Chain length and transparency — intermediaries, brokers, no visibility past the first tier
  • Complexity — blended, processed or powdered materials where original identity is lost
  • Supply disruption — shortage, poor harvest, sanctions, export restriction

Record the information sources you consult and consult them on a schedule, not just at the annual review. Regulatory alert systems, horizon-scanning databases, trade association intelligence and commodity price data are all legitimate inputs.

The single most reliable food fraud indicator

An offer materially below the prevailing market price. It is not subtle and it does not require a database subscription.

Build a price check into the purchasing process and record it. If a commodity is scarce and one supplier is quoting well under everyone else, that is either a genuine advantage they can explain or it is the thing your food fraud programme exists to catch. Ask which, and write down the answer.

What FSSC 22000 requires for food defense

Requirement 2.5.3 mirrors 2.5.4 structurally: competent personnel for the threat assessment and plan, an implemented plan supported by the FSMS covering the scope in question, and for FII, supplier assurance that they hold plans of their own. Food defense also now appears in the prerequisite standard at clause 16.2.

The threat assessment looks at where deliberate contamination would do most damage. Give particular attention to points where a contaminant would disperse through a large quantity of product with no subsequent step to detect or remove it — bulk vessels and silos, mixing and dosing, water and ingredient dosing systems, post-lethality handling of ready-to-eat product, and open-product areas with unsupervised access.

Do not neglect the systems side. Malicious computer hacking affecting process control, recipe management, traceability or labelling systems is explicitly within scope, and a labelling system that can be altered without authority is a food defense vulnerability as much as a propped-open door.

Insider access is the shared blind spot

Both disciplines under-weight the same thing. Food fraud assessments concentrate on the supply chain and food defense assessments concentrate on the perimeter, while the actor with the most opportunity in either case is someone with legitimate routine access and no need to force anything.

Practical controls that address both: pre-employment screening proportionate to access, a leaver process that removes access the same day, dual control on critical dosing, tamper-evident closures on bulk vessels, and a reporting route people will actually use.

Where food fraud has a food safety consequence

A useful reframe. Because it is economically motivated, it is tempting to treat this as a commercial problem. It frequently is not.

An undeclared allergen introduced through substitution is a food safety failure. A species substitution breaks a dietary claim. An unapproved additive used to improve appearance may be a legal breach. A diluted ingredient can change a preservation system and therefore shelf life.

So when suspected food fraud is found, assess safety separately from authenticity. Hold the material and any product made from it, determine the extent using traceability and mass balance, obtain authenticity testing from a competent laboratory, and only then decide on withdrawal.

Verification that works for both

Traceability and mass balance do more work here than any other control. Mass balance in particular is arithmetic rather than judgement: reconcile the quantity of a claimed material received against the quantity of product sold carrying that claim, over a defined period.

A balance that consistently shows more output claimed than input received is the clearest possible indicator that something is wrong upstream. It requires no specialist knowledge and no laboratory, and it is easy to leave undone precisely because nothing prompts it.

For food defense, verification looks different: test one element of the plan annually — an access control test, an unannounced perimeter check, a challenge of the visitor procedure, or a desktop incident exercise — and record what it found.

Building both plans without duplicating work

  1. Keep the assessments separate. One combined spreadsheet satisfies neither requirement properly.
  2. Record who produced each, and what makes them competent. This is explicitly audited.
  3. Run the food fraud vulnerability assessment across materials; run the threat assessment across process steps and access points.
  4. Share the mitigations where they genuinely overlap — supplier assurance, tamper evidence, access control, awareness training.
  5. Check both plans against the four tests: implemented, supported by the FSMS, legally compliant, covering the scope, kept current.
  6. For subcategory FII, write the supplier plan requirement into the supplier agreement rather than chasing it annually by questionnaire.
  7. Review both at least annually and on any alert affecting a material, species, region or route you use.

The FSSC 22000 Toolkit keeps the two apart deliberately — separate assessment procedures and worksheets, separate plans, competence records for the personnel producing each, and a shared supplier assurance record for the FII requirement.

What auditors look for in these two plans

The questions are predictable, which makes them easy to prepare for honestly.

Who wrote this, and what makes them competent? Both requirements name the competence obligation explicitly, so an assessment with no recorded author and no evidence of their knowledge fails on its own terms regardless of quality.

Show me the assessment behind this mitigation. Controls that appear in the plan but trace back to no scored vulnerability read as generic good practice rather than as a response to your own risk picture.

What changed at the last review? An assessment reviewed annually with no changes across three cycles suggests the review is a signature rather than a reassessment — particularly for a supply base that has certainly moved in that time.

How would you know? For each significant vulnerability, what would actually detect it? If the honest answer is “nothing we currently do”, that is a legitimate finding to have recorded and accepted, and a much better position than an undocumented assumption that testing would catch it.

Where is the mass balance? For any claim on pack, the Scheme requires verification systems including traceability and mass balance. This is the question sites are least ready for, because the arithmetic is simple and either it has been done or it obviously has not.

Both requirements are category-scoped in part — check your food chain categories — and Version 7 moved both into the prerequisite standard as well.

>Frequently asked questions on food fraud and food defense

Can one person own both food fraud and food defense?

They can, provided their competence covers both, and that competence is recorded. But the skill sets differ — food fraud leans on supply chain, commodity markets and analytical detectability, while food defense leans on physical security, personnel screening and systems access. Most sites end up with a small team rather than one person.

Does a food fraud assessment need to cover finished products?

It needs to cover the products and processes within your certification scope. In practice most of the vulnerability sits upstream in materials, but counterfeiting and grey-market diversion are finished-product risks and belong in the assessment where relevant.

How often should the assessments be reviewed?

At least annually, and on any of these triggers: a new material or supplier, a change in supply route or origin, a commodity price shock or shortage, a fraud alert affecting something you use, a customer challenge to authenticity, or an adverse mass balance.

Where can I read the requirements themselves?

Part 2, clauses 2.5.3 and 2.5.4 of the FSSC 22000 Scheme, published free by the Foundation at fssc.com. Between them they run to about half a page, and reading the original is the fastest way to see how deliberately the two are kept apart.

The takeaway

Treat food fraud and food defense as two disciplines that share some controls, not one discipline with two names. Assess materials for economic vulnerability and process points for deliberate harm. Record who did the work and why they were competent to do it. Run mass balance on your claims, because it is free and it catches what testing does not. For how these sit among the other requirements, see our guides to the 18 Additional Requirement groups and FSSC 22000 certification.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.