Overview
ISO 22380:2018 - Security and resilience: Authenticity, integrity and trust for products and documents - provides general principles to identify and manage product fraud risk and to design cost‑effective countermeasures. Applicable to all organizations (public or private, any size), the standard promotes a common understanding of product‑related fraud, from situational analysis through profiling, risk assessment and the selection, implementation and evaluation of bespoke controls.
Key Topics
- Evaluation of situational context
- External factors (marketplaces, supply chains, legal/regulatory, social and economic drivers) and internal factors (governance, capabilities, information flows, culture) that influence product fraud opportunity.
- Use of the crime‑opportunity triangle (fraudster, vulnerable target, weak guardianship) and rational choice concepts to assess vulnerability.
- Classification of intentions, motives and activities
- Distinguishes deceptive vs non‑deceptive products and categorizes motives (recreational, occasional, occupational, professional, activism).
- Catalogues types of product fraud (e.g., counterfeiting, adulteration, tampering, IPR infringement, re‑introduction of stolen goods) and their potential consequences.
- Profiling and risk assessment
- Guidance on profiling fraud scenarios and conducting structured risk assessments tailored to product types, supply chain nodes and threat actors.
- Selection and implementation of countermeasures
- Strategic approaches and selection criteria that incorporate cost‑effectiveness and ROSI (return on security investment) vs. assessed risk level.
- Effectiveness assessment
- Monitoring and review of countermeasure performance to ensure continuous improvement.
- Supporting materials
- Informative annexes provide examples of profiling, risk assessment, countermeasures and decision making for security investment.
Applications
ISO 22380:2018 is practical for organizations seeking to protect product authenticity, integrity and consumer safety. Typical users include:
- Brand owners and manufacturers establishing anti‑fraud strategies
- Supply chain and logistics managers evaluating vulnerable nodes
- Quality assurance, compliance and risk management teams conducting product fraud risk assessments
- Security and resilience professionals designing countermeasures and calculating ROSI
- Regulators, customs, and law enforcement involved in product safety and anti‑counterfeiting
Use cases include preventing counterfeit parts in critical industries, reducing public health risks from adulterated goods, and prioritizing investments in detection, traceability and deterrence measures.
Related Standards
Keywords: ISO 22380:2018, product fraud risk, countermeasures, product authenticity, supply chain security, fraud risk assessment, ROSI, product integrity.