On an event day, a stadium, arena, racecourse, exhibition hall, or festival site may look like one operation to the public. Operationally, it is a temporary system assembled from several organisations.
The venue operator may control the building and permanent systems. A promoter or organiser may control the event. A security contractor may manage searching and guarding. A stewarding company may manage sections of the crowd. Caterers, production teams, broadcasters, medical providers, transport operators, tenants, volunteers, and emergency services may each possess information and authority that the others need.
Every participant may have a competent plan. The response can still fail at the interfaces between them.
The Terrorism (Protection of Premises) Act 2025, commonly called Martyn’s Law, makes this interface problem impossible to dismiss as a contractual detail. The Act creates duties for qualifying premises and events, identifies responsibility through control, and expressly requires co-operation and co-ordination in specified circumstances. As of September 2026, the Security Industry Authority expects the regime to come into force in spring 2027, although the commencement date remains subject to the formal process.1
Preparation should therefore do more than produce a compliant document for each organisation. It should establish how the event will operate as one response system when facts are incomplete, authority is changing, and different parts of the site may require different actions.
Start with the legal architecture, but do not stop there
Under current guidance, premises that can reasonably expect between 200 and 799 people to be present at the same time will generally fall within the standard tier. Premises that can reasonably expect 800 or more will generally be enhanced tier. A qualifying event will generally involve 800 or more people, public access controlled through tickets, passes, invitations, or membership, and premises that are not already enhanced-tier premises. Staff count towards the number present.1
All in-scope premises and events must have appropriate and reasonably practicable public protection procedures addressing evacuation, invacuation, lockdown, and communication. Enhanced-tier premises and qualifying events must also consider public protection measures intended both to reduce physical harm and to reduce vulnerability to an attack. Enhanced dutyholders must document their procedures and measures, assess how they achieve those objectives, and provide the required document to the regulator.2
These thresholds and documents matter, but they are not the most difficult operational issue. The harder question is who controls what.
The responsible person for premises is the person with control of the premises in connection with the relevant use. For a qualifying event, it is the person with control of the premises for the purposes of the event. The Act’s explanatory notes make clear that responsibility cannot simply be delegated to contracted services. A guarding company providing door staff, for example, is unlikely to become the responsible person merely because it performs an important security function.3
Where more than one person is responsible for the same premises or event, they are jointly responsible and must work together. The Act also requires co-ordination where qualifying premises sit within other qualifying premises, and co-operation from certain people who have control over aspects of enhanced premises or event space without being the responsible person.3
The practical implication is important. A contract can allocate tasks, standards, and commercial liabilities, but it cannot make operational interdependence disappear. The responsible person still needs to know whether the contractor can receive a warning, make the required decision, communicate with its staff, and provide reliable information back into command.
An event changes the operating system of the premises
A fixed venue has permanent exits, control rooms, fire systems, access arrangements, and trained staff. An event temporarily changes how those assets are used.
The build introduces contractors, vehicles, temporary structures, and restricted routes. Opening brings staff and early arrivals into different parts of the site. Ingress creates queues outside the secure perimeter and pressure at transport nodes. During the performance or match, the population becomes concentrated and lighting, noise, or production effects may alter communication. An interval changes crowd distribution. Egress moves large numbers towards public space and transport at once. Breakdown restores construction and vehicle risks while public-facing staffing reduces.
This means an emergency plan cannot assume a single, stable population or command arrangement. It should identify how control, information, and available resources change through the event lifecycle.
The useful planning unit is not simply “the stadium” or “the concert”. It is the combination of phase, zone, population, hazard, and responsible organisations. At 14:00, a concourse may be a contractor work area. At 19:30, it may hold thousands of spectators. At 22:30, it may become an egress route. The physical map is unchanged, but the response problem is not.
This is one reason generic procedures can become misleading. “Evacuate the premises” sounds decisive until the team asks where the threat is, which exits remain safe, where the external crowd will move, and whether an adjacent transport hub or public space is itself affected.
Evacuation, invacuation, and lockdown are situational choices
Martyn’s Law deliberately includes four public protection procedures rather than assuming evacuation is always the answer. The Home Office statutory guidance says planners should consider where an attack may be coming from and how procedures work together, because several may be needed simultaneously or in sequence. It also expects the unfolding situation to be assessed so that actions can change as circumstances develop.2
At a large site, apparently contradictory instructions may therefore both be correct. One zone may need to move away from an internal threat. Another may need to remain secured because the danger is outside. People approaching the premises may need to be diverted, while those already inside move to a safer internal area. Staff may need information that should not yet be broadcast publicly because they must first open a route, close a gate, or prevent movement towards danger.
The command challenge is not to select one verb for the whole site. It is to maintain a common understanding of which procedure applies to which population, in which zone, on whose authority, and until what condition changes.
Plans should therefore define the decision logic behind procedures, not just their names. Who can initiate an immediate local action? Which decision must be escalated to event control? How is the source and reliability of a report recorded? What happens if control cannot be contacted? Who can amend an instruction after emergency services arrive? How are people outside the ticketed perimeter considered?
Those questions make a procedure usable. Without them, trained personnel may wait for authority that has not been assigned, or different contractors may act rationally according to incompatible plans.
Communication is a control function, not an announcement
The statutory guidance describes communication as providing information that alerts people to danger and gives instructions where it is safe to do so. It specifically distinguishes information for the public from information for staff, recognises that instructions depend on the procedure being activated, and asks larger premises and events to consider whether people in different locations can actually be reached.2
This is a more demanding requirement than owning a public-address system.
An event may communicate through radios, PA announcements, screens, mobile notifications, social media, stewards, signage, control-room calls, and face-to-face commands. Each channel reaches a different audience, at a different speed, with a different degree of assurance. A radio message may reach supervisors but not every steward. A PA announcement may be inaudible outside, inaccessible to some attendees, or unsuitable for a covert staff action. Social media can travel far beyond the event and may remain visible after circumstances change. Mobile messaging can target a defined group, but delivery cannot be assumed.
Effective planning begins with the action required, then selects the audience and channel. It also separates sending from effect. The fact that control transmitted an instruction does not prove that a contractor’s supervisor received it, that stewards understood it, or that the public complied.
HSE event guidance advises organisers to agree emergency roles with emergency services, plan official public messages, pre-agree wording for show-stop announcements, and test communications equipment before the event.4 Pre-agreed wording reduces delay, but it cannot cover every situation. Staff also need a disciplined way to distinguish an approved instruction from a rumour, report failed delivery, and ask for clarification without overwhelming the control room.
Shared situational awareness must be deliberately constructed
Different organisations see different parts of the incident. CCTV operators may observe movement without understanding why it is happening. Stewards may hear reports that have not reached control. Police may hold threat information that cannot be shared in full. Medical teams may see an emerging casualty pattern. Transport operators may know that the intended evacuation area is becoming congested. Social-media teams may detect public reports before their accuracy is established.
More information does not automatically produce a common picture. Reports can be duplicated, delayed, stripped of source, or treated as confirmed when they are still assumptions.
The Joint Emergency Services Interoperability Principles provide a useful discipline, even though they are doctrine for emergency responders rather than a substitute for a venue’s legal duties. JESIP emphasises co-location, communication, co-ordination, joint understanding of risk, and shared situational awareness. It defines that awareness as a common understanding of the circumstances, immediate consequences, implications, available capabilities, and organisational priorities.5
Venue and event teams can apply the same logic before responders arrive. They can use plain language, record the source and confidence of information, agree the lead for each decision, and make organisational limitations visible. The aim is not to force every organisation onto one radio channel. It is to make sure that different communications create one decision picture.
This becomes particularly important at the transfer of command. HSE notes that when emergency services declare a major incident, police may take authority over one part of an event while leaving other areas under the organiser’s control.4 “The police have taken over” is therefore not a sufficient operating assumption. Event control needs to know the geographical and functional extent of that authority, which venue decisions remain active, and how the two command structures will exchange information.
Contractors should be tested as part of command, not treated as headcount
Security officers, stewards, production personnel, caterers, cleaners, medical providers, and volunteers are often the people closest to the public. Their response cannot be inferred from the existence of a contract or induction record.
For each critical role, the organiser and venue should understand who supervises it during an incident, how instructions are authenticated, what action can be taken without further permission, and how completion or failure is reported. If a contractor supplies staff through several layers, that chain must still work at operational speed.
The interface is most vulnerable where ordinary management and emergency authority differ. A catering supervisor may manage employees day to day but receive evacuation instructions from event control. A production manager may control a performance but not the public response. A security contractor may advise on lockdown while the statutory responsible person retains the relevant responsibility. Emergency services may later assume command over part of the site.
These are not arguments for centralising every decision. Local action can be essential. They are arguments for making the boundaries explicit and ensuring that information travels across them.
Exercises should reveal friction, not rehearse the plan’s preferred story
An exercise that follows the written plan exactly can demonstrate familiarity. It cannot show how the system handles uncertainty.
HSE recognises table-top exercises as a way to establish the effectiveness of an emergency plan.4 For complex venues, the most valuable scenarios test the interfaces that documents tend to smooth over. The first report should be incomplete. Two sources should disagree. A radio talk group should fail. A supervisor should be unavailable. A neighbouring premises should take an action that changes the safe route. One part of the site should need an instruction that would be unsafe elsewhere. Police control should cover only part of the footprint. A plausible social-media post should conflict with verified information.
The assessment should examine decisions and information flow, not theatrical performance. Did staff state what they knew and what they were assuming? Was authority clear? Could control identify which organisations had received the instruction? Were public and staff messages consistent without being identical? Did the team notice that the population and safe routes had changed? Was an action assigned to a named role and followed to completion?
An exercise should leave an evidential improvement record. Observations need owners, due dates, and a method for checking that the revised control works. Otherwise, lessons identified become lessons merely recorded.
The evidential record is part of operational control
Enhanced-tier premises and qualifying events will need documented procedures and measures, but evidence should not be created solely for later inspection. A structured incident record helps the team operate in real time.
It should distinguish the original report, verified facts, working assessments, decisions, instructions, acknowledgements, actions, and unresolved issues. It should also identify the authority under which an important decision was taken and record when that authority changed.
This chronology supports shift handovers, prevents repeated work, and gives the incoming emergency services a clearer account. Afterwards, it allows reviewers to assess whether a decision was reasonable on the information available at the time, rather than judging it with hindsight.
The Security Industry Authority says its regulatory approach will combine support with risk-based assessment, desk-based review, and inspection, focusing on whether those in scope took reasonable steps in their particular circumstances.1 A pile of generic documents will be weaker evidence than a clear relationship between the site context, chosen procedures, staff awareness, exercises, operational records, and completed improvements.
Where AtlasNXT can support the operating model
No platform determines the responsible person, makes a procedure reasonably practicable, or replaces trained command. Technology can, however, reduce the fragmentation that appears when several organisations must act together.
AtlasNXT can provide an authorised operational view connecting an incident, affected areas, relevant personnel, targeted communications, acknowledgements, assigned activity, and event history. Teams can use different groups for venue staff, contractors, managers, and other operational audiences rather than relying on one undifferentiated broadcast. Location and remit information can help responders understand which people or teams may be relevant to a particular zone, subject to the organisation’s privacy and access rules.
Used well, that shared record supports three things that paper plans cannot do alone: it helps the response team keep its picture current, helps instructions reach defined audiences through an established process, and preserves the chronology needed for handover and review.
The platform should be configured around the venue’s command design, not the other way round. Roles, authorities, groups, zones, escalation points, and data access should be agreed with the venue, organiser, and relevant providers before the event. The purpose is not to pretend that several organisations have become one. It is to ensure they can operate as one response system when it matters.
Martyn’s Law establishes a legal minimum for preparedness. The more important test will occur in the first minutes of a real incident, when the public sees one venue but the response still depends on many organisations. Authority lies in making those interfaces visible, rehearsed, and operationally accountable before pressure exposes them.
Book an AtlasNXT demonstration to explore how a shared incident and communications picture could support your venue or event operation.
References
3. Terrorism (Protection of Premises) Act 2025, Explanatory Notes, sections 4 and 8
4. Health and Safety Executive, Planning for incidents and emergencies at events
5. Joint Emergency Services Interoperability Principles, Principles for joint working



