ISO 22000 Food Fraud and Authenticity: How Auditors Assess Your FSMS
Food fraud is the economically motivated adulteration, substitution, mislabelling, or counterfeiting of food, and while base ISO 22000:2018 does not mandate a full food fraud program, GFSI-recognized schemes built on it — notably FSSC 22000 — require a documented food fraud vulnerability assessment and mitigation plan that auditors verify. For food businesses, understanding where food safety management ends and food fraud prevention begins is essential to passing an audit and protecting product authenticity across the supply chain.
This guide explains what food fraud and authenticity mean in practice, how they differ from food defense, where they fit within ISO 22000 and FSSC 22000, and exactly what an auditor examines when assessing your controls.
What Food Fraud and Authenticity Mean
Food fraud is a deliberate act carried out for economic gain. Someone dilutes, substitutes, mislabels, or counterfeits a product to increase profit or reduce cost, usually without regard to whether the result is safe. Common forms include:
- Dilution — extending a genuine ingredient with a cheaper substance (for example, adding water or a filler to a concentrate).
- Substitution — replacing a high-value ingredient with a lower-value one, such as swapping one fish species or oil for another.
- Mislabelling — making false claims about origin, species, grade, or production method.
- Counterfeiting — copying a brand, packaging, or certification to pass off an imitation as genuine.
Authenticity is the flip side of fraud. It is the assurance that a product is genuinely what it claims to be — that its stated origin, species, composition, and processing method are true. When authenticity controls are strong, fraudulent product is far harder to introduce and far easier to detect.
Both concepts matter because food fraud can be a safety hazard as well as a commercial and reputational one. An undeclared substitution may introduce an allergen or a contaminant that the food safety management system (FSMS) was never designed to catch.
Food Fraud vs Food Defense (VACCP vs TACCP)
These two terms are frequently confused, and auditors expect organizations to distinguish them clearly.
- Food fraud is economically motivated. The intent is financial gain, and the tool used to manage it is a food fraud vulnerability assessment — sometimes called VACCP (Vulnerability Assessment and Critical Control Points). It leads to a mitigation or prevention plan.
- Food defense addresses intentional, malicious contamination — deliberate harm, sabotage, or terrorism. The tool used to manage it is a threat assessment, sometimes called TACCP (Threat Assessment and Critical Control Points).
Both sit alongside — but are distinct from — the HACCP hazard analysis, which addresses unintentional biological, chemical, and physical hazards. A mature food safety program treats all three as complementary layers.
How Food Fraud and Authenticity Fit ISO 22000 and FSSC 22000
This is where accuracy matters most, because the requirements differ depending on which scheme you certify against.
ISO 22000:2018 is the international FSMS standard. It builds on HACCP principles and prerequisite programs (PRPs) and uses risk-based thinking throughout. However, base ISO 22000:2018 does not by itself mandate a dedicated food fraud vulnerability assessment or a formal food defense program. Organizations certified only to ISO 22000 may address fraud through general risk management, but the standard does not prescribe a full program.
FSSC 22000 is a GFSI-recognized certification scheme built on ISO 22000 plus sector-specific prerequisite programs and additional requirements. Unlike base ISO 22000, FSSC 22000 does require certified organizations to conduct and document:
- A food fraud vulnerability assessment and a corresponding mitigation plan, and
- A food defense threat assessment and plan.
Other GFSI-recognized schemes (such as BRCGS and SQF) carry comparable requirements. So when a client asks whether they “need” a food fraud program, the honest answer is: it depends on the scheme. If your customers or markets expect GFSI recognition — and many retailers do — FSSC 22000 and its food fraud and food defense requirements are typically the relevant benchmark.
For a foundation in the underlying methodology, many organizations first establish HACCP certification and strong ISO 22000 certification before layering on GFSI-scheme requirements.
The Food Fraud Vulnerability Assessment
The vulnerability assessment is the analytical core of any credible food fraud program. Its purpose is to identify where in your materials, products, and supply chain fraud is most likely to occur, and how significant the impact would be. A practical assessment typically works through the following steps:
- Map materials and products. List raw materials, ingredients, packaging, and finished products, along with their suppliers and supply routes.
- Assess vulnerability factors. For each material, consider the drivers of fraud — price volatility, complexity of the supply chain, ease of adulteration, history of fraud in that commodity, geographic and economic pressures, and the reliability of the supplier.
- Evaluate opportunity and detectability. Determine how easy it would be to introduce fraud and how likely existing controls are to catch it.
- Prioritize the risks. Rank materials so that mitigation effort focuses where vulnerability is highest.
- Build the mitigation plan. Assign specific, proportionate controls to significant vulnerabilities — for example, supplier approval and audits, certificates of analysis, mass-balance checks, authenticity testing, and tighter specifications.
- Review and update. Reassess when suppliers, materials, markets, or fraud intelligence change, and at planned intervals.
The output is not a one-off document. It is a living assessment supported by a mitigation plan that names the controls, the owners, and the verification activities that keep fraud out.
What an Auditor Checks
When an auditor assesses food fraud and authenticity controls — most rigorously under FSSC 22000 or another GFSI scheme — they are looking for evidence that the program is real, current, and effective rather than a paper exercise. Expect the auditor to review:
- The vulnerability assessment itself — its scope, methodology, and whether it covers all relevant materials and products.
- The mitigation plan — whether identified vulnerabilities are matched to proportionate, documented controls with clear responsibility.
- Supplier controls — approval processes, supplier questionnaires and audits, specifications, and how supply chain changes are managed.
- Testing and verification — authenticity or species testing, certificates of analysis, mass-balance reconciliation, and traceability exercises that confirm what is claimed.
- Records and traceability — the ability to trace a product one step back and one step forward, and to demonstrate that controls were actually performed.
- Review and improvement — evidence that the assessment is reviewed after incidents, intelligence changes, or at defined intervals.
Auditors also check that food fraud and food defense are addressed as distinct topics, that responsibilities are assigned, and that staff understand the difference between fraud, defense, and conventional food safety hazards. A clear understanding of the ISO audit procedure helps organizations prepare the right records in advance, and companies that want this expertise in-house often send their audit leads through ISO 22000 lead auditor training.
Building Resilience Against Food Fraud
Passing the audit is the minimum; the goal is genuine resilience. Organizations that manage fraud well tend to share several habits:
- Supply chain transparency. They know their suppliers, their suppliers’ suppliers where it matters, and the routes their materials travel. Shorter, better-understood chains are harder to compromise.
- Intelligence-led review. They monitor commodity-specific fraud trends and adjust their vulnerability assessment as risks shift, rather than treating it as an annual formality.
- Layered verification. They combine documentary checks (certificates, specifications) with physical and analytical checks (testing, mass balance) so a single weak control does not expose the whole system.
- Robust prerequisite programs. Strong PRPs and good manufacturing practices reduce opportunity throughout the operation. Facilities pursuing cGMP certification often find these foundations reinforce fraud controls.
- A culture of authenticity. Staff at every level understand why authenticity matters and feel able to raise concerns.
Resilience is built through continual improvement — the same plan-do-check-act discipline that underpins the wider FSMS. Each incident, near miss, or audit finding becomes an input to a stronger next cycle.
How IAS Supports Your Certification
Integrated Assessment Services (IAS) certifies organizations to ISO 22000 and related food safety standards, helping food businesses demonstrate that their management systems — including their approach to food fraud and authenticity — meet recognized requirements. Through structured, independent auditing, IAS helps organizations confirm that their vulnerability assessments, mitigation plans, supplier controls, and verification records stand up to scrutiny.
IAS also offers practitioner training, including ISO 22000 internal auditor training, so that internal teams can build and maintain these programs with confidence. You can review upcoming courses on the training schedule, explore the full range of standards on the ISO certification hub, or contact us to discuss certification for your organization. IAS has a formal group-company association with Empowering Assurance Systems (EAS), which provides certification and inspection services internationally.
