top of page

Food Defense vs Food Fraud: Protecting Consumers, Supply Chains and Product Integrity

Updated: Jul 28

What happens when a threat to food safety is not accidental, but deliberate?

Most food safety programs are designed to prevent unintentional biological, chemical, physical and allergen hazards. However, food businesses must also prepare for deliberate acts that may compromise products, facilities, operations and supply chains.


Food defense and food fraud address two different types of intentional risk. Food defense protects food and related operations against malicious acts intended to cause harm or disruption. Food fraud, on the other hand, involves deliberate deception carried out primarily for economic gain.


An individual may intentionally contaminate a product to harm consumers, interrupt operations or damage a company’s reputation. A supplier, trader or other party may substitute, dilute, mislabel or misrepresent a product to increase profit. Although the motivations differ, both situations can result in unsafe products, regulatory action, financial losses, supply-chain disruption and long-term damage to consumer trust.


Understanding the difference between food defense and food fraud is therefore essential for organizations seeking to protect consumers, strengthen supply-chain resilience and maintain brand integrity.


Key Takeaways
  • HACCP mainly addresses accidental and unintentional food safety hazards.

  • Food defense uses a threat assessment to evaluate intentional malicious attacks.

  • Food fraud uses a vulnerability assessment to evaluate economically motivated deception.

  • FSSC 22000 requires separate food defense and food fraud controls.

  • Effective programs depend on multidisciplinary teams, documented assessments, mitigation measures, verification and regular review.

  • Procurement, supplier approval, security, traceability and authenticity testing all contribute to risk reduction.



Food Safety, Food Defense and Food Fraud: What Is the Difference?

Although these three areas are related, they address different causes and motivations.

Area

Primary cause or motivation

Main objective

Common approach

Food safety

Accidental or unintentional contamination

Control biological, chemical, and physical hazards

Hazard Analysis and Critical Control Point  (HACCP)

Food defense

Intentional malicious action intended to cause harm or disruption

Protect people, products, facilities and operations against deliberate attacks

Threat assessment, including  (TACCP)

Food fraud

Intentional deception primarily for economic gain

Reduce substitution, dilution, counterfeiting, misrepresentation and similar fraudulent activities

Food fraud vulnerability assessment, including Vulnerability Assessment and Critical Control Points (VACCP)

HACCP, remains essential for controlling unintentional food safety hazards. However, HACCP cannot replace a food defense threat assessment or a food fraud vulnerability assessment because the intentions, opportunities and methods involved are different.


TACCP and VACCP are widely used industry approaches, but FSSC 22000 does not require every organization to use only one prescribed tool. The organization must select a defined and appropriate methodology that fits its products, processes and risks.


What Is Food Defense?

Food defense is the effort to protect food, ingredients, feed, packaging and related operations against intentional adulteration, malicious tampering, sabotage and other deliberate attacks, which may compromise product safety.

The U.S. Food and Drug Administration describes food defense as protecting food from intentional adulteration or tampering. The FDA’s food defense initiatives help facilities prevent, prepare for, respond to and recover from intentional acts affecting the food supply. (U.S. Food and Drug Administration)

Potential food defense threats may include:


  • Deliberate contamination of ingredients or finished products

  • Tampering with open products, processing equipment, or utilities

  • Sabotage of production, storage, or distribution operations

  • Unauthorized access to sensitive areas

  • Malicious actions by employees, contractors, or visitors

  • Interference with labels, records, or traceability information

  • Cyber-enabled disruption affecting production or control systems

  • Attacks intended to cause public fear, consumer harm, or business interruption

Food defense is not limited to installing gates, guards or surveillance cameras. A complete program must examine how an attacker could access a product or process, where deliberate contamination could occur, how much harm could result and whether existing controls are sufficient.


What Is a Food Defense Threat Assessment?

A food defense threat assessment is a structured process used to identify and evaluate potential intentional threats associated with an organization’s products, processes, facilities and supply chain.

Under FSSC 22000 Version 6, organizations must conduct and document a food defense threat assessment using a defined methodology. Appropriate mitigation measures must then be developed and implemented for threats determined to be significant.


A threat assessment should help the organization answer the following questions:

  • Who may have the motivation to harm or disrupt the organization?

  • What products, processes, utilities or areas could be targeted?

  • How could an attacker gain access?

  • How might intentional contamination or sabotage be carried out?

  • What could be the potential public-health and business impact?

  • How likely is the activity to be detected?

  • Which existing controls reduce the opportunity for an attack?

  • What additional mitigation measures are needed?


FSSC guidance recommends a logical, systematic and risk-based approach. Common methodologies include TACCP, CARVER+Shock and the FDA Food Defense Plan Builder, although the final method must be appropriate to the organization.

Not every identified threat will automatically require a new mitigation measure. The organization should evaluate the significance of each threat based on factors such as likelihood, impact, accessibility, detectability and the effectiveness of existing controls.


What Should a Food Defense Plan Include?

A food defense plan converts the findings of the threat assessment into documented responsibilities, controls and response procedures.


An effective plan should include:

  1. Scope and responsibilities: Define which products, processes, locations, personnel and supply-chain activities are covered.

  2. Food defense team: Assign personnel with relevant knowledge from departments such as quality assurance, production, security, human resources, engineering, information technology, warehousing, logistics and senior management.

  3. Documented threat assessment: Record the assessment methodology, identified threats, risk ratings and justification for determining significance.

  4. Mitigation measures: Implement controls appropriate to the identified threats. These may include:

  5. Restricted access to sensitive areas

  6. Visitor and contractor controls

  7. Employee authorization procedures

  8. Secure ingredient, chemical and packaging storage

  9. Tamper-evident or tamper-resistant systems

  10. CCTV and security monitoring

  11. Control of keys, access cards and passwords

  12. Inventory reconciliation

  13. Protection of water, air, electricity and other utilities

  14. Reporting procedures for suspicious activities

  15. Monitoring and verification: Define how the organization will confirm that mitigation measures are being implemented and remain effective.

  16. Corrective actions and incident response: Establish procedures for control failures, suspected tampering, unauthorized access and other food defense incidents.

  17. Training and awareness: Personnel should understand their responsibilities, recognize unusual behavior and know how to report concerns.

  18.  Review and continuous improvement: Review the plan whenever significant changes, emerging threats, incidents or control failures occur. FSSC guidance states that the food defense plan should include mitigation measures, verification, incident-management procedures, responsibilities, record keeping, corrective actions and continuous improvement. It should also be supported by the organization’s food safety management system.


The FDA Food Defense Plan Builder follows a comparable structure, including vulnerability assessment, mitigation strategies, monitoring, corrective actions and verification. The tool was developed for facilities addressing U.S. Intentional Adulteration Rule requirements, so its regulatory scope should not automatically be applied to every Philippine business. (U.S. Food and Drug Administration)


What Is Food Fraud?

Food fraud involves the deliberate and intentional substitution, addition, tampering or misrepresentation of food, ingredients, feed, packaging, labels or product information for economic gain.

Codex Alimentarius recognizes food fraud as a global and transnational concern that can affect consumer health, local agri-food economies and public confidence in the food supply. (FAOHome)

Common forms of food fraud include:

  • Diluting a high-value ingredient with a cheaper material

  • Substituting one species, variety, grade or origin for another

  • Adding undeclared substances to improve apparent quality

  • Concealing deterioration or inferior product characteristics

  • Falsifying country-of-origin or traceability information

  • Making false organic, allergen-free, Halal, sustainability or authenticity claims

  • Counterfeiting branded products or packaging

  • Relabelling expired or unauthorized products

  • Selling stolen goods or unauthorized production overruns

  • Misrepresenting composition, production methods or certifications


Although the principal motivation behind food fraud is normally economic gain, the consequences can include direct or indirect food safety risks. Undeclared allergens, unauthorized additives, toxic substitutes and false traceability information may expose consumers to hazards that the legitimate manufacturer did not anticipate.


What Is a Food Fraud Vulnerability Assessment?

A food fraud vulnerability assessment evaluates where a business may be exposed to economically motivated deception.


Under FSSC 22000 Version 6, organizations must conduct and document a food fraud vulnerability assessment using a defined methodology. The assessment must cover the processes and products within the organization’s scope. Significant vulnerabilities must be addressed through appropriate mitigation measures and a documented food fraud mitigation plan.


A food fraud vulnerability assessment should consider factors such as:

  • Economic attractiveness of committing fraud

  • Historical fraud incidents involving the material or sector

  • Current market shortages and price movements

  • Availability and geographic origin of the material

  • Ease of substitution, dilution or adulteration

  • Difficulty of detecting fraudulent activity

  • Availability of suitable authenticity testing

  • Supply-chain length and complexity

  • Number of brokers, traders or intermediaries

  • Access to ingredients, finished products, labels and packaging

  • Supplier history and length of the commercial relationship

  • Use of spot buying or emergency procurement

  • Supplier certification and independent control systems

  • Strength of traceability and mass-balance controls


FSSC guidance identifies economic vulnerability, historical information, detectability, supply-chain access, supplier relationships, independent certification and supply-chain complexity as important assessment factors.


Vulnerability levels may change when there are crop failures, geopolitical disruptions, ingredient shortages, sudden price increases, new suppliers, changes in formulation or shifts in consumer demand. For this reason, assessments should be reviewed regularly and after significant changes.


How Can Food Businesses Reduce Food Fraud Risks?

Food fraud cannot be controlled through laboratory testing alone. Testing can support verification, but it should be part of a wider supplier, procurement, traceability and risk-management system.


  1. Strengthen supplier approval: Verify supplier identity, business legitimacy, technical capability, certifications and food fraud controls. Supplier approval requirements should reflect the vulnerability of the material being purchased.

  2. Improve product and raw-material specifications: Specifications should clearly define identity, composition, grade, origin, processing method, allergen status, authenticity requirements and acceptable test criteria.

  3. Map the supply chain: Understand where the material originates, how many parties handle it, where ownership changes and where it is stored, repacked, blended or substantially processed.

  4. Apply risk-based authenticity testing: Use appropriate test methods for high-risk ingredients, products and claims. The type and frequency of testing should be based on the assessed vulnerability and limitations of the chosen method.

  5. Monitor market conditions: Material shortages, low harvest yields, rapid price increases, trade restrictions, conflict, transportation disruptions and sudden changes in demand may increase the economic incentive to commit fraud.

  6. Improve traceability and mass balance: Compare purchasing records, production volumes, yields, inventory movements and sales records to identify unexplained discrepancies.

  7. Control labels and packaging: Secure access to labels, branded packaging, printing files, rejected materials and unused packaging to reduce counterfeiting and unauthorized production.

  8. Control emergency purchasing: Urgent procurement should not bypass minimum supplier approval, specification, authenticity and traceability requirements.

  9. Verify the mitigation plan: Verification may include supplier audits, origin checks, authenticity testing, specification review, mass-balance exercises, traceability tests, internal audits and management review.


FSSC guidance recommends integrating food fraud controls into the wider food safety management system, including training, internal audits, management review, corrective actions, record keeping and continuous improvement.


Why These Programs Matter to Business Continuity

A food defense attack or food fraud incident may affect more than one product batch. The impact can extend across an entire facility, supply chain or brand.

Possible consequences include:

  • Consumer illness or injury

  • Product withdrawal or recall

  • Production stoppage

  • Loss of customer approval

  • Supply interruption

  • Failed certification or customer audits

  • Contract termination

  • Investigation and legal expenses

  • Loss of export or market access

  • Reputational damage

  • Reduced customer and employee confidence


Food fraud can also compromise traceability even when an immediate health hazard has not yet been identified. When an organization cannot confirm a material’s identity, origin or chain of custody, it may no longer be able to demonstrate that the affected product is safe or authentic.


Food defense and food fraud programs therefore support business continuity, supply-chain resilience and brand protection—not only regulatory or certification compliance.


FSSC 22000 Food Defense and Food Fraud Requirements

FSSC 22000 Version 6 requires separate documented processes for food defense and food fraud mitigation.

For food defense, the organization must:

  • Conduct and document a threat assessment

  • Use a defined methodology

  • Identify and evaluate potential threats

  • Determine which threats are significant

  • Implement appropriate mitigation measures

  • Maintain a documented food defense plan

  • Establish verification procedures

  • Keep the plan current and supported by the food safety management system


For food fraud, the organization must:

  • Conduct and document a vulnerability assessment

  • Use a defined methodology

  • Identify and assess potential vulnerabilities

  • Determine which vulnerabilities are significant

  • Implement appropriate mitigation measures

  • Maintain a documented food fraud mitigation plan

  • Establish verification procedures

  • Keep the plan current and supported by the food safety management system

These requirements apply separately because malicious attacks and economically motivated fraud involve different motivations and methods.


FSSC 22000 Version 7 Transition

Foundation FSSC published FSSC 22000 Version 7 in May 2026. Audits against Version 6 may continue only until April 30, 2027. Version 7 upgrade audits will be conducted from May 1, 2027, through April 30, 2028

Food defense and food fraud remain important requirements under FSSC 22000. Version 7 specifically requires the food defense threat assessment, food defense plan, food fraud vulnerability assessment, and food fraud mitigation plan to be developed and maintained by personnel with appropriate knowledge and competence. These plans must also be implemented, supported by the organization’s food safety management system, kept up to date, and aligned with applicable legal requirements.


To support organizations throughout the transition, the IFSA training will cover the relevant requirements of both FSSC 22000 Version 6 and Version 7. The program will explain the current Version 6 requirements, highlight the key updates introduced in Version 7, and guide participants in applying food defense and food fraud controls based on their organization’s certification status and upgrade schedule.


This makes the training relevant for organizations currently operating under Version 6, as well as those already preparing for their transition to Version 7. Organizations are also encouraged to coordinate with their certification bodies to confirm their applicable audit and upgrade timelines.


Food Defense and Food Fraud in the Philippines

Republic Act No. 10611, or the Food Safety Act of 2013, strengthened the Philippine food safety regulatory system to protect consumer health and facilitate market access for locally produced food and food products. 


The law provides the broader national framework for food safety. However, it does not automatically require every Philippine food business to obtain FSSC 22000 certification or implement a specific TACCP or VACCP methodology.


An organization’s specific food defense and food fraud obligations may depend on:

  • Applicable Philippine regulations

  • Export-market requirements

  • Customer and retailer standards

  • Contractual obligations

  • Certification-scheme requirements

  • Product and supply-chain risks

  • Internal corporate policies


Strong food defense and food fraud programs can nevertheless support compliance, supplier management, traceability, incident preparedness and confidence in product authenticity.


These programs are particularly valuable for businesses that:

  • Supply multinational or export customers

  • Operate under FSSC 22000 or another recognized certification program

  • Use imported or high-value ingredients

  • Work with brokers or complex supplier networks

  • Make origin, authenticity, allergen, religious or sustainability claims

  • Produce large batches distributed across wide markets

  • Are entering new markets or onboarding new suppliers


Strengthen Your Food Defense and Food Fraud Program with IFSA

The Institute for Food Safety Advancement invites food-industry professionals to its Food Defense and Food Fraud Online Training, an intensive two-day webinar designed to help organizations identify intentional threats, assess fraud vulnerabilities and develop practical mitigation plans.

Day 1: Food Defense

Date: August 19, 2026

Time: 9:00 AM–5:00 PM, GMT+8

Format: Live online webinar


Areas Covered
  • What is food defense?

  • The role of food defense in food safety

  • HACCP, TACCP and VACCP

  • Food defense threat identification and assessment

  • Assessment of significant threats

  • Selection of mitigation measures

  • Development of a food defense plan

  • FSSC 22000 Version 6 food defense requirements


Day 2: Food Fraud

Date: August 20, 2026

Time: 9:00 AM–5:00 PM, GMT+8

Format: Live online webinar


Areas Covered
  • What is food fraud?

  • Relevance and significance of food fraud

  • Food fraud incidents and industry lessons

  • Food fraud vulnerability assessment

  • Factors influencing vulnerability

  • Identification of significant vulnerabilities

  • Food fraud mitigation planning

  • FSSC 22000 Version 6 certification requirements

  • FSSC 22000 Version 7 certification requirements


What Participants Will Learn

By the end of the training, participants are expected to be able to:


Food Defense
  • Explain food defense and its role in protecting the food supply

  • Understand its importance to business continuity and brand reputation

  • Identify possible attackers, motivations, opportunities and methods

  • Conduct a risk-based food defense threat assessment

  • Determine which threats may be significant

  • Select appropriate mitigation measures

  • Develop, implement and maintain a documented food defense plan


Food Fraud
  • Explain the difference between food fraud and food defense

  • Identify potential fraud involving ingredients, products, packaging and claims

  • Conduct a food fraud vulnerability assessment

  • Assess economic incentives, detectability, supplier risks and supply-chain complexity

  • Prioritize significant vulnerabilities

  • Strengthen procurement and supplier controls

  • Develop and maintain a food fraud mitigation plan

  • Improve supply-chain resilience against fraudulent activity


Who Should Attend?

The training is recommended for professionals working in:

  • Food safety management

  • Food defense and food fraud teams

  • Quality assurance and quality control

  • Production and operations

  • Purchasing and procurement

  • Supplier management and vendor accreditation

  • Supply chain and logistics

  • Warehouse and distribution

  • Security and facilities management

  • Internal audit

  • Regulatory affairs and compliance

  • Technical services and research and development

  • Raw-material authenticity and product compliance


Because food defense and food fraud require multidisciplinary knowledge, organizations are encouraged to involve participants from both technical and business functions.


About the Resource Speaker

The training will be led by Ms. Mari Mojica, a food safety specialist and consultant with three decades of technical and managerial experience in the food industry.


Her professional experience includes food manufacturing, plant sanitation, quality assurance, management-system auditing, production, supplier management, product development, technical training, product evaluation, troubleshooting, coaching, problem-solving and resource planning.

Participants will learn through technical discussions, practical examples, interactive exercises and relevant case studies that connect food defense and food fraud principles with actual food-industry operations.


Training Inclusions

Participants will receive:

  • Live instructor-led online training

  • Soft copy of learning materials

  • Practical examples and case discussions

  • Opportunities to ask technical questions

  • Official Certificate of Completion upon meeting the seminar requirements


Registration Rates

Registration option

Rate

Regular – Food Defense

₱5,699

Regular – Food Fraud

₱5,699

Group – Food Defense, minimum of three participants

₱4,699 per participant

Group – Food Fraud, minimum of three participants

₱4,699 per participant

Regular package – Both seminars

₱10,198

Group package – Both seminars

₱8,198 per participant

Applicable ticket-service fees may be added during checkout.


Early-Bird Discount

Register and complete payment on or before August 5, 2026, to receive ₱500 off a regular individual seminar ticket:

  • Use code FD19 for Food Defense

  • Use code FF19 for Food Fraud

Group registrations and package deals are also available.

For assistance with group packages, consolidated registration or billing, contact sales@ifsa.com.ph.

Do not wait for a serious incident, failed audit, customer complaint or supply-chain disruption before examining your organization’s exposure.


Join IFSA’s Food Defense and Food Fraud Online Training on August 19 and 20, 2026, and strengthen your organization’s ability to protect consumers, products, operations and brand trust.


Frequently Asked Questions

What is the difference between food defense and food fraud?

Food defense addresses intentional malicious actions intended to harm consumers, an organization or the food supply. Food fraud involves intentional deception carried out primarily for economic gain. Because their motivations differ, they require separate assessments and mitigation plans.


Is HACCP enough to manage food defense and food fraud?

No. HACCP primarily addresses accidental and unintentional food safety hazards. Organizations need a separate food defense threat assessment and food fraud vulnerability assessment to address deliberate acts.


What is TACCP?

TACCP means Threat Assessment and Critical Control Points. It is a risk-based approach commonly used to identify intentional threats, potential attackers, vulnerable processes and appropriate food defense measures.


What is VACCP?

VACCP means Vulnerability Assessment and Critical Control Points. It is commonly used to evaluate exposure to economically motivated food fraud, including substitution, dilution, counterfeiting, tampering and misrepresentation.


Does FSSC 22000 require a food defense plan?

Yes. Under FSSC 22000 Version 6, an organization must conduct a documented threat assessment and maintain a documented food defense plan containing mitigation measures and verification procedures.


Does FSSC 22000 require a food fraud vulnerability assessment?

Yes. FSSC 22000 Version 6 requires a documented food fraud vulnerability assessment covering the processes and products within the organization’s scope. Significant vulnerabilities must be addressed through a documented mitigation plan.


Does every identified threat or vulnerability require a new control?

Not necessarily. The organization should assess each identified issue and determine whether it is significant. Mitigation measures should prioritize threats and vulnerabilities classified as significant through the organization’s defined methodology.


Is the training only for FSSC 22000-certified businesses?

No. It is also relevant to organizations preparing for certification, responding to customer requirements, improving supplier controls or strengthening existing food safety, security and business-continuity programs.


Will participants receive a certificate?

Yes. Participants who complete the applicable seminar requirements will receive an Official Certificate of Completion from the Institute for Food Safety Advancement.


Can a company register several participants?

Yes. Group rates are available for a minimum of three participants. Package options are also available for organizations sending participants to both seminars.


How can participants register?

Choose the appropriate regular, group or package ticket and complete the online registration form. The form serves as a reservation. An IFSA representative will contact the registrant through email with the Statement of Account and payment instructions. Registration is officially confirmed after payment has been successfully processed.


Check out IFSA's Upcoming Events in August

Ensure the safety of your food products by mastering the fundamentals of an effective sanitation program.


Event Title: Intensive Technical Webinar on Fundamentals of a Food Plant Sanitation Program

Date: August 25, 2026

Platform: Zoom Meeting


Resource Speaker: Mr. Guilberto Veluz



Strengthen your auditing skills and drive continuous improvement in your organization!


Event Title: Face-to-Face Training on Effective Internal Audit

Date: August 27-28, 2026

Venue: GH Tower, San Juan City

Resource Speaker: Ms. Emelita Alegre


Click Here to Register: Effective Internal Audit


Editorial Team:


Written by John Kevin Castro

Marketing Director

Institute for Food Safety Advancement (IFSA)


Technically Reviewed by Angela Kristel Dalao, RMic, PFT

Managing Director

Institute for Food Safety Advancement (IFSA)


PUBLICATION DATE:

July 27, 2026

Comments


© 2026 Institute for Food Safety Advancement, Corp. All Rights Reserved.

bottom of page