V5 Ultimate
Ultimate
PricingResourcesCompany
Start free trial
HomeGlossaryTACCP / VACCP
Compliance · The complete guide

TACCP / VACCPThreat Assessment Critical Control Points / Vulnerability Assessment Critical Control Points

In short

TACCP (Threat Assessment Critical Control Points) addresses deliberate, ideologically or criminally motivated contamination of food — sabotage, tampering, terrorism. VACCP (Vulnerability Assessment Critical Control Points) addresses economically motivated adulteration and fraud — substitution, mislabelling, counterfeiting, dilution.

Read the full summary

Both are required by GFSI schemes (BRCGS Issue 9, SQF Edition 9, FSSC 22000 v6); FDA's Intentional Adulteration rule (21 CFR Part 121) covers TACCP-territory for FSMA-covered facilities.

3,300 words · ~15 min read
On this page
  1. 01TACCP and VACCP — different threats, different defences
  2. 02Regulatory landscape
  3. 03TACCP methodology
  4. 04FSMA IA — Key Activity Types (KATs)
  5. 05VACCP methodology
  6. 06Risk scoring — making it defensible
  7. 07Common mistakes
  8. 08How V5 Ultimate handles TACCP / VACCP
On this page · 8 sections
  1. 1TACCP and VACCP — different threats, different defences
  2. 2Regulatory landscape
  3. 3TACCP methodology
  4. 4FSMA IA — Key Activity Types (KATs)
  5. 5VACCP methodology
  6. 6Risk scoring — making it defensible
  7. 7Common mistakes
  8. 8How V5 Ultimate handles TACCP / VACCP
AI · Explain it for MY operation

How does TACCP / VACCP apply to your shop floor?

Pick your industry and scale — Ask V5 rewrites the definition in your context, gives a worked example, and shows what V5 does on day one.

Your scale

01TACCP and VACCP — different threats, different defences

TACCP and VACCP are sister disciplines that emerged from PAS 96 (BSI) and were rapidly adopted by the GFSI-benchmarked schemes after the 2008 melamine-in-milk fraud and the 2013 European horsemeat scandal. They share methodology (structured assessment, scoring, mitigation, review) but address fundamentally different actor motivations:

  • TACCP — Threat: someone deliberately wants to harm consumers, embarrass the brand, or extort the company. Motivation is ideological, criminal, political or psychological. Defence is access control, surveillance, supply-chain integrity, employee vetting, incident response.
  • VACCP — Vulnerability: someone wants to make money by adulterating or misrepresenting food. Motivation is financial. Defence is supplier qualification, raw-material testing, mass-balance, authenticity testing (DNA, isotope, NIR), price-monitoring.
One-sentence summary

TACCP defends the food supply from people who want to harm consumers; VACCP defends it from people who want to cheat them.

02Regulatory landscape

  • FDA FSMA Intentional Adulteration rule (21 CFR Part 121) — TACCP-territory regulation, mandatory for most US food-processing facilities (excluding very small, certain animal-food, etc.). Requires identification of Key Activity Types (KATs), mitigation strategies, monitoring, corrective actions, verification, training, records and a written Food Defense Plan.
  • FDA FSMA Preventive Controls (21 CFR Part 117) — includes economically motivated adulteration (EMA) as a hazard requiring a preventive control where it has the potential to cause illness or injury. Addresses the food-safety face of VACCP-style adulteration.
  • GFSI-benchmarked schemes (BRCGS, SQF, FSSC 22000, IFS) all require documented TACCP and VACCP assessments, mitigations, and periodic review (annually at minimum).
  • EU — no single horizontal regulation but Regulation (EU) 2017/625 on official controls and the EU Food Fraud Network coordinate cross-border investigations.
  • UK — FSA's NFCU operates a national food-crime function; PAS 96 remains the practitioner reference.

03TACCP methodology

  1. Assemble the TACCP team — operations, security, HR, IT, QA, supply-chain.
  2. Identify the threats — sabotage by current/former employee, tampering by consumer or visitor, malicious contamination, cyber-attack on process control, supply-chain interception, ideological or extortion attack.
  3. Identify vulnerable points — receiving docks, storage tanks, mixing vessels, exposed conveyors, packaging lines pre-seal, warehouses, transport, retail.
  4. Score each threat × vulnerable point — likelihood and impact, typically 1-5 scales with anchored definitions.
  5. Design and implement mitigations — physical (locked vessels, CCTV, fencing, access cards, tamper-evident packaging), procedural (visitor escorts, two-person rule for sensitive vessels), and personnel (background checks, anti-fraud training).
  6. Test the defences — table-top exercises, mock incidents, supplier penetration tests.
  7. Review — minimum annually and on any significant change (new ingredient supplier, new line, security incident, regulatory change).
  8. Maintain a Food Defense Plan (FSMA IA mandate; GFSI-acceptable artefact).

04FSMA IA — Key Activity Types (KATs)

FDA's IA rule identifies four KATs where intentional adulteration would most plausibly cause wide-scale public-health harm. Each KAT must be evaluated at every covered facility:

  • Bulk liquid receiving and loading — tankers, IBCs.
  • Liquid storage and handling — silos, tanks, bulk hoppers.
  • Secondary ingredient handling — large-quantity ingredient hold-add into a batch.
  • Mixing and similar activities — high-throughput batch mixers, blenders.

For each KAT the facility documents the vulnerability assessment (using FDA's three elements: potential public-health impact, degree of physical access, ability to contaminate successfully), the actionable process steps, and the mitigation strategy. Mitigations must be implementable and verifiable.

05VACCP methodology

  1. Build the ingredient inventory — every raw material, packaging item and supplied service.
  2. For each, identify potential adulterants based on history (e.g. melamine in dairy, methanol in olive oil, sudan dyes in spices, horse in beef).
  3. Score vulnerability — economic incentive, supply-chain complexity, supplier history, geopolitical situation, ease of detection, historical incidents, market price volatility.
  4. Use credible sources — RASFF (EU rapid-alert), HorizonScan, USP Food Fraud Database, NFCU, internal supplier-history.
  5. Design mitigations — supplier audits, raw-material authenticity testing (DNA-PCR, stable-isotope, NIR/Raman fingerprinting), mass-balance reconciliation, price-anomaly monitoring, dual-sourcing for high-vulnerability raws, allergen-statement verification.
  6. Verify and review — at least annually, and on any signal (price spike, RASFF alert, supplier change, geopolitical disruption).
VACCP without testing is theatre

A VACCP plan without periodic raw-material authenticity testing on the high-vulnerability ingredients is not a control — it is a documentation exercise. GFSI auditors increasingly press for evidence that the lab work actually happens.

06Risk scoring — making it defensible

Both assessments use likelihood × impact matrices, typically 5×5 with anchored definitions. The single most common audit finding is unanchored scales — "likelihood: medium" with no frequency definition, "impact: high" with no harm or financial definition. Use concrete anchors:

ScoreLikelihood anchorImpact anchor (illness)Impact anchor (financial)
1 — NegligibleNo credible scenarioNo measurable health impact<USD 10k
3 — ModerateCredible scenario, 1+ industry precedent in 10 yrOutpatient treatmentUSD 100k–1M
5 — SevereActive intelligence or recent incidentHospitalisation or fatality>USD 10M / brand-ending

07Common mistakes

  • Conflating TACCP and VACCP into one assessment — different threat actors, different defences.
  • No FSMA IA Food Defense Plan despite being a covered facility.
  • VACCP with no authenticity-testing programme — vulnerabilities scored but never verified.
  • Annual review skipped after "no incidents" — incidents elsewhere in the industry still warrant review.
  • No employee training on the food-defence programme.
  • Risk-scoring scales unanchored; "medium" means whatever the assessor felt.
  • Cyber-attack on process control omitted from TACCP — increasingly a top threat for MES/SCADA-controlled plants.

08How V5 Ultimate handles TACCP / VACCP

TACCP / VACCP in V5

V5's Food Safety module stores TACCP and VACCP assessments as first-class records alongside the HACCP / Food Safety Plan, with anchored scoring scales, FSMA-IA KAT templates pre-loaded, and the Food Defense Plan auto-rendered into a PDF aligned with 21 CFR Part 121. Mitigations link to the controls that operationalise them — CCTV camera IDs, access-control roles, supplier-authentication test methods, mass-balance reconciliation tasks. Periodic-review tasks fire annually and on trigger events (new supplier, ingredient price-anomaly above threshold, RASFF alert pulled in via integration). Every assessment, mitigation and review is Part 11 e-signed and ready for BRCGS / SQF / FSSC 22000 audit.

Frequently asked questions

Q.Are TACCP and VACCP the same thing?+

No. TACCP addresses intentional harm (sabotage, terrorism, tampering); VACCP addresses fraud (economically motivated adulteration). They share methodology but the actor motivation and the controls differ.

Q.Is TACCP required by FDA?+

FDA's Intentional Adulteration rule (21 CFR Part 121) is functionally TACCP-territory. Most US food-processing facilities above the very-small threshold must have a written Food Defense Plan.

Q.How often must TACCP and VACCP be reviewed?+

At least annually, and on any significant change — new supplier, new ingredient, new line, security incident, RASFF alert, geopolitical disruption affecting a high-vulnerability supply chain.

Q.Who should be on the TACCP / VACCP team?+

TACCP — operations, security, HR, IT, QA, supply-chain, plus a board-level sponsor. VACCP — QA, procurement, R&D, finance, supply-chain. Some plants run a single combined team; others split. Either is acceptable provided coverage is documented.

Q.What test methods are used for VACCP authenticity?+

Driven by the suspected adulterant — DNA-PCR for species substitution (meat, fish), stable-isotope ratio mass spectrometry for geographic origin and organic claims, NIR/Raman/FTIR spectroscopy for fingerprint comparison, HPLC for marker compounds, and emerging applications of NMR and machine-learning chemometric analysis.

Primary sources

  • PAS 96:2017 — Guide to protecting and defending food and drink from deliberate attack (BSI)
  • 21 CFR Part 121 — Mitigation Strategies to Protect Food Against Intentional Adulteration (FSMA IA rule)
  • FDA — Mitigation Strategies to Protect Food Against Intentional Adulteration Guidance (multi-chapter)
  • GFSI Benchmarking Requirements v2024 — food defence and food fraud
  • BRCGS Global Standard Food Safety Issue 9 — clauses 4.2 + 5.4
  • SQF Food Safety Code Edition 9 — clauses 2.7.1 + 2.7.2

Further reading

  • HACCP
    The hazard analysis TACCP/VACCP run parallel to.
  • HARPC
    The FSMA preventive-control framework.
  • BRCGS
    GFSI scheme mandating both assessments.
  • SQF
    GFSI scheme mandating both assessments.
  • FSSC 22000
    GFSI scheme mandating both assessments.
  • Supplier qualification
    Where VACCP closes the loop with controls.
Software that covers TACCP / VACCP
V5 Ultimate SQF
SQF Edition 9 system elements (2.1–2.9) and food-safety fundamentals modeled as live workflow. SQFI published Edition 10 in March…
V5 Ultimate BRCGS
BRCGS Food Safety Issue 9 fundamental requirements, HACCP, food safety and quality management, site standards, product control,…
V5 Ultimate FSSC 22000
FSSC 22000 version 6 wraps ISO 22000 (FSMS), ISO/TS 22002 sector PRPs and eleven additional requirements — food fraud, food…

Explore this topic

TACCP / VACCP sits inside this topic cluster in our glossary. Every neighbour is one click away.

Food safety & GFSI
16 related entries

HACCP, FSMA, allergen control and the GFSI-recognised certification schemes.

HACCPCCPHARPCPCQIFSMA 204KDECTE21 CFR 117Allergen ControlSSOPGFSISQFBRCGSFSSC 22000ISO 9001MoCRA
Talk to us about TACCP / VACCP

Want to see how TACCP / VACCP could fit into your own records and workflows? Explore the related V5 pages or talk to our team about what applies to your operation.

Start free
Back to glossary
Where this term comes up
Food ProcessingBakery & ConfectioneryMeat & SausageIngredients & Dry Mixes
Inside V5
  • → Score your compliance gap — then download the validation pack.
  • → Document control — one version in force, every change signed and explained.
  • → QMS — quality records next to the work they concern.
Regulatory anchors
  • 21 CFR Part 121
  • BRCGS Issue 9
  • SQF Edition 9
Related terms
  • → HACCP
  • → HARPC
  • → BRCGS
  • → SQF
  • → FSSC 22000
  • → CCP
  • → PCQI
  • → FSMA 204
  • → KDE
  • → CTE
  • → 21 CFR 117
  • → Allergen Control
  • → SSOP
  • → GFSI
  • → ISO 9001
  • → MoCRA

Next step

Try V5 with your own records, or ask a question first. Ask V5 opens with an editable question; nothing is sent until you choose to.

Start your free trial Browse all features
V5 Ultimate
Ultimate

Warehouse, quality and manufacturing software for regulated operations.

ProductIndustriesPricingResourcesSecurity & TrustCompanyLegal centre

© V5 Ultimate