Martyn’s Law Signals a New Era of Security Compliance for Event Organizers
The UK’s Martyn’s Law is redefining how organizations responsible for public venues and events approach security. New statutory guidance issued ahead of the law’s expected...
The UK’s Martyn’s Law is redefining how organizations responsible for public venues and events approach security. New statutory guidance issued ahead of the law’s expected commencement in 2027 makes clear that counterterrorism preparedness is no longer viewed as a specialist security function but as a core compliance responsibility embedded within governance, operational planning, and risk management.
Named after Martyn Hett, who was killed in the 2017 Manchester Arena terrorist attack, the Terrorism (Protection of Premises) Act 2025 introduces legal duties for organizations responsible for publicly accessible premises and qualifying events. Rather than prescribing identical security measures for every venue, the legislation adopts a proportionate, risk-based framework based on venue capacity and operational risk.
For compliance professionals, the significance extends well beyond physical security.
The guidance represents a fundamental shift from reactive incident response to preventive governance. Organizations are expected to identify foreseeable terrorist risks, document decision-making processes, allocate clear responsibilities, train staff, test emergency procedures, and demonstrate that reasonable and proportionate measures have been implemented before an incident occurs. Compliance therefore becomes evidence of preparedness rather than merely adherence to statutory requirements.
One of the most important governance issues concerns accountability. Modern events often involve venue operators, promoters, production companies, security contractors, catering providers, and local authorities. The guidance makes clear that organizations cannot assume security responsibility belongs solely to another party. Instead, responsibilities must be explicitly allocated, documented, coordinated, and regularly reviewed. Failure to clarify ownership creates both operational and regulatory risk.
Another defining feature is the principle of “reasonably practicable” compliance. Organizations are not expected to eliminate every conceivable risk or expose staff to unnecessary danger. Instead, regulators will assess whether measures taken are proportionate to the venue, threat environment, operational realities, and available resources. This aligns Martyn’s Law with established risk-based compliance models already familiar in health and safety, anti-money laundering, and operational resilience.
Documentation is likely to become one of the strongest indicators of compliance maturity. Risk assessments, evacuation and lockdown procedures, staff training records, governance meetings, contractor responsibilities, communication protocols, and incident response exercises may all become important evidence during inspections, regulatory reviews, civil litigation, or public inquiries. Good documentation is no longer administrative housekeeping—it is part of an organization’s legal defence.
The legislation also reflects the growing convergence between security, enterprise risk management, business continuity, and corporate governance. Counterterrorism preparedness is no longer viewed solely through the lens of physical security teams. Boards, compliance officers, legal counsel, facilities managers, HR, operations, and executive leadership all have roles in building organizational resilience.
Beyond the United Kingdom, Martyn’s Law may influence regulatory thinking internationally. Governments are increasingly placing legal responsibility on organizations to anticipate foreseeable threats rather than simply react after incidents occur. Similar trends are already evident in cyber resilience, critical infrastructure protection, and operational resilience regulations across multiple sectors.
Analysis
Martyn’s Law represents a broader evolution in compliance philosophy.
Historically, organizations focused on complying with minimum legal obligations. Increasingly, regulators expect businesses to demonstrate proactive governance, continuous risk assessment, documented accountability, and organizational resilience.
For multinational organizations operating venues, stadiums, hotels, convention centres, shopping centres, universities, entertainment facilities, or major public events, the legislation offers an important governance model. Terrorism preparedness is becoming an enterprise-wide risk rather than a standalone security function.
The law also reinforces an emerging regulatory expectation: organizations must be able to explain not only what decisions were made but why they were made, who approved them, and how they were implemented. Governance, documentation, and accountability are becoming as important as physical security measures themselves.
Ultimately, Martyn’s Law demonstrates that modern compliance extends beyond preventing regulatory breaches. It is about building organizations capable of protecting people, maintaining operational continuity, and demonstrating resilience under scrutiny.
Compliance Takeaway
Organizations responsible for publicly accessible venues should begin preparing well before Martyn’s Law takes effect. Compliance should include comprehensive terrorism risk assessments, clearly documented governance structures, defined ownership of security responsibilities, staff awareness training, tested emergency response procedures, contractor coordination, and robust recordkeeping. Boards should treat protective security as an enterprise risk requiring continuous oversight rather than a one-time compliance exercise. Early preparation will not only support regulatory compliance but also strengthen organizational resilience, public confidence, and legal defensibility following any future security incident.



No Comment! Be the first one.