A load comes in. Your receiving tech has a clipboard, a COA, and about four minutes before the next truck pulls up. That four-minute window is your food fraud control. Everything your supplier verification program says on paper either holds up here or it doesn't.
If that scenario sounds familiar, you're not alone. And if it makes you a little uneasy, it should.
What food fraud actually costs when you catch it late
Food fraud isn't an abstract compliance problem. It's a supply chain problem with a very concrete cost curve.
There's a principle sometimes called the 1-10-100 rule that anyone who's been through a product hold understands intuitively. Catching a non-conforming load at the dock might cost you a few hours of delay and an awkward call to your supplier. Producing product with that load before you catch the problem costs 10 times more. A recall costs 100 times more. Companies have paid tens of millions to clean up problems that started with a load that passed receiving because no one had the tools, time, or documentation to flag it.
The math isn't complicated: the gap between $1 and $100 is almost always what happened at receiving.
A quality manager at a Midwest dairy co-op learned this the hard way. When a mock audit surfaced a documentation gap in incoming ingredient verification, the team discovered their receiving staff couldn't define what a COA was or what they were supposed to be checking it against. This was a systemic gap that had been invisible because no one had built the verification step into the receiving workflow itself. The $1 moment had been missing entirely.
The fraud types most likely to reach your dock undetected
Food fraud is intentional. Someone made a decision to substitute, dilute, mislabel, or misrepresent what's in that container. That's what separates it from a food safety failure, where something went wrong in a system. Food fraud is the system working exactly as the fraudster intended.
Estimates from food fraud researchers at Michigan State University and the Food Standards Agency put the annual global cost anywhere from $10 billion to $40 billion. The range is that wide because most food fraud is never detected at all.
The categories where your receiving team is most exposed:
- Substitution: High-value species or ingredients swapped for cheaper alternatives. Pollock sold as cod, skate flesh punched into scallop-shaped medallions. Studies examining restaurant menu accuracy in North America have found seafood mislabeling rates in the range of 20–30%, figures that vary by region and testing method but consistently point in the same direction.
- Dilution: Premium liquids cut with lower-cost fillers. Olive oil extended with sunflower or palm oil. Honey blended with corn syrup. You won't see it. The COA may not show it either, unless your spec requires testing that actually catches it.
- Counterfeiting and mislabeling: Organic labels on non-organic product. Halal or kosher certifications that don't hold up. Expiry dates that have been quietly revised.
- Certificate forgery: Less common now with e-certification, but altered documents still circulate, especially from supply chains that cross multiple international borders and brokers.
The commodities with the highest current fraud risk tend to be the expensive ones: olive oil, saffron, honey, coffee, seafood, and high-demand spices. When prices spike hard (cocoa was up dramatically over the past two years; coffee and olive oil have seen the same pressure), fraud risk spikes with them. Commodity price volatility should trigger a review of your vulnerability assessment for those inputs, not just your procurement budget.
What your receiving verification actually needs to catch
When a load arrives, your receiving team should be able to answer four questions before accepting it:
- Does the COA match the purchase order specs for this ingredient, including identity, concentration, and any allergen declarations?
- Is the supplier on your approved supplier list, and is their approval current?
- Is there anything on the COA, including lot code, production date, and supplier identifier, that doesn't reconcile with what's on the truck?
- If this load were pulled for an audit six months from now, could you find the COA and the receiving record in under five minutes?
Most plants can answer question one most of the time. Questions two through four are where it gets harder.
A craft brewery QA lead ran into this problem at scale. Their team was verifying COAs daily against a Word-format specification document. Every shift, someone was manually comparing numbers, and every shift, there was exposure to transcription error and human fatigue. The verification was happening, but it wasn't reliable enough to defend on audit day, and it didn't produce any trend data that would let purchasing know a supplier was slipping before the third or fourth bad load.
That last part matters more than most QA managers get credit for. Supplier quality management isn't just about rejecting non-conforming loads. It's about building enough data over time that you can have a substantive conversation with purchasing before the problem becomes a hold or a recall. If your receiving data doesn't feed into a supplier scorecard, you're starting that conversation from scratch every time.
What a defensible receiving verification actually looks like
One operation that got this right was a specialty ingredients manufacturer. Their receiving team ran a checklist on every load, tested against PO specs, with a clear escalation path when something didn't match. That's the $1 version of fraud prevention done correctly. It's not complicated, it's disciplined, documented, and repeatable.
The checklist isn't the hard part. The hard part is making it stick across every shift, with every receiver, for every load. And making sure that when you reject a load, there's a documented corrective action workflow. Your purchasing team, your supplier, and your food safety plan all need a record of what happened and why.
For ingredient categories that carry higher fraud risk, the depth of that verification should match the risk. Verifying an olive oil COA isn't the same process as verifying a seafood species. For high-risk commodities, random testing matters. Checking supplier databases for fraud history matters. Knowing whether your supplier's GFSI certification actually covers the fraud types you're worried about is worth understanding, because GFSI certification schemes, depending on the standard, may address food fraud more broadly, while FDA's Economically Motivated Adulteration (EMA) framework focuses specifically on fraud that creates a food safety hazard. Check your specific GFSI scheme requirements to know where your gaps are.. Non-safety fraud may need separate program elements depending on your regulatory environment.
There's also an organizational reality here that most food safety content glosses over. Your receiving data doesn't automatically translate into purchasing behavior. QA managers know this. You can flag the same supplier three times and still be overruled on cost grounds. The only way to change that dynamic is to make the trend visible and documented so that purchasing is working from the same information you are. That's a supplier scorecard conversation, and it requires data from receiving to be meaningful.
The audit retrieval problem nobody talks about until it's too late
Your auditor asks for three COAs from six months ago. What happens next in your facility?
If the answer is "someone starts searching email attachments," that's the real food fraud vulnerability. Not because the COAs don't exist, but because a document you can't find in five minutes might as well not exist on audit day.
The webinar poll that generated this piece showed the number one thing slowing QA teams down was keeping supplier approvals and documents current. The second was pulling proof together quickly on audit day. Those are the same problem at two different points in time.
Building a supplier onboarding process that captures approval documentation upfront, then connects it to receiving records over time, means you're not rebuilding the evidence file every time you get audited. You're maintaining it continuously, and that's what separates a food fraud program that's documented but not used from one that would hold up if an auditor walked in tomorrow.
What to do with this
Start with your highest-risk commodity inputs. Pick the three ingredients on your approved supplier list that would give a fraudster the best economic motive: expensive, hard to distinguish from substitutes, sourced through brokers or imported. Ask whether your receiving verification for those three could actually catch a common substitution.
Then check your COA retention and retrieval: try to pull a specific supplier's COA from four months ago right now and see how long it takes.
If you want to hear a former Canadian federal food safety official, with decades of auditing experience in seafood, meat, and high-risk commodity categories, walk through which commodity categories carry the highest fraud risk right now and what a defensible receiving verification actually looks like under audit conditions, the webinar is worth the hour. Freeman Libby covered which common substitutions are hardest to detect at the dock, how to structure your vulnerability assessment for current market conditions, and how to think about the EMA gap in your FSMA food safety plan.
Watch the full FSMA Friday webinar on food fraud risk →