FSSC 22000 Version 7 requires a documented food defence threat assessment and a food fraud vulnerability assessment with mitigation plans, and BRCGS Issue 9 requires the same under sections 4.2 and 5.4. Both expect the assessments to be reviewed when something changes, not just annually. In practice most sites run a TACCP and VACCP workshop once a year, score the threats and vulnerabilities in a spreadsheet, agree a mitigation plan and file it. Twelve months later the spreadsheet is opened, the dates are updated and it is filed again. Auditors have learned to look for the review that follows a real change: a new supplier, a new country of origin, a price spike in a raw material, an incident at a competitor, a disgruntled employee. If the assessment did not move when the world did, it is not a live assessment.
What the two assessments actually cover
Food defence (TACCP, threat assessment critical control points) is about deliberate contamination by people with intent, inside or outside the business. It looks at access, personnel, processes, product and the site’s attractiveness as a target, and it produces controls such as access restriction, tamper evidence and pre-employment checks. Food fraud (VACCP, vulnerability assessment critical control points) is about economically motivated adulteration, substitution, dilution, mislabelling and counterfeiting in the supply chain. It looks at each raw material’s history of fraud, its price volatility, the complexity of its supply chain and the strength of supplier controls, and it produces controls such as testing, specification tightening and supplier audits.
What the records have to show
For each assessment: the team and their competence, the methodology and scoring, the threats or vulnerabilities identified with their scores, the mitigation measures with owners and dates, the review triggers, and the record of every review including the ones that changed nothing and why. For food fraud specifically, the auditor will pick a high-risk material such as honey, olive oil, spices, fruit juice concentrate or fish, and ask to see the vulnerability score, the horizon scanning that fed it and the mitigation in place.
Why the assessments go stale
Because the information that should trigger a review lives elsewhere. The new supplier is approved in the supplier file. The price spike is in purchasing. The incident at a competitor is in the news. The resignation is in HR. None of those reach the spreadsheet, so the spreadsheet does not change. The fix is structural: link the assessments to the records that should move them.
What the ASCloud tools do
The food defence and food fraud tools, available from the ASC shop at R750 per site per year each, hold the assessments with their scoring, mitigation plans and review history. They are linked to the supplier records on ASCloud, so a new supplier or a new material prompts a vulnerability review for that material, and a supplier whose certificate lapses raises the vulnerability score until it is renewed. Horizon scanning notes, such as fraud alerts and price movements, are logged against the material and feed the next review. Access control and personnel changes logged on the site prompt a threat review. Every review is recorded with its outcome, so the auditor sees an assessment that moved when the risk did.
Keeping the workshop, losing the filing
The annual workshop is still worth doing, because it brings purchasing, HR, security and quality into one room. What changes is that the workshop reviews a live assessment with a year of logged triggers and reviews behind it, rather than reopening a spreadsheet nobody has looked at since the last audit.
Assessments that move when the risk does
TACCP and VACCP linked to your suppliers, materials and site changes, with every review recorded. R750 per site per year each, from the ASC shop.
Frequently asked questions
Can we load our existing TACCP and VACCP spreadsheets?
Yes. The current assessments are loaded as the baseline and the tool takes over the reviews from there.
Do we still need a food fraud mitigation plan document?
The tool generates the plan from the assessment, with owners and dates. It is the same document, kept current.
Does ASC run TACCP and VACCP training?
Yes. ASC offers overview and implementation courses on food defence and food fraud, and the tools run what the courses teach.
How does horizon scanning work?
The quality team logs fraud alerts, price movements and incidents against the material.