Brian Sims
Editor
Brian Sims
Editor
THE TERRORISM (Protection of Premises) Act 2025 rests the entire duty on a single named individual. In most organisations, that individual hasn’t yet been identified or has otherwise been handed the accountability without the authority to act on it. Here, Simon Legrand highlights the governance gap that the sector doesn’t appear to be discussing.
Most of the Martyn’s Law coverage so far has outlined what the duty requires. Notification, procedures, tiers, thresholds. These are the right areas for discussion, but they skip the prior one. Who in your organisation shoulders the responsibility?
The Act of Parliament answers plainly. The duty falls on a ‘Responsible Person’: the individual or body in control of the premises. For a great many in-scope organisations, that means one named human being who’s personally accountable for whether the premises comply with the law. Not a committee. Not ‘the security team’. An individual whose name, role and accountability the Act of Parliament expects to be documented and current.
Read your own structure against that standard and the gap tends to appear pretty quickly. In many organisations, the role has never been formally assigned. In others, it has drifted along to whomever seemed closest to the building. A facilities lead. A duty manager. Sometimes a head of security who already owns ten other risks. The name goes on the form and everyone moves on without anyone asking whether that person can actually discharge the responsibilities they’ve just been given.
Governance problem
That’s the real problem. It’s a governance-related one, not a technical one. Accountability has been placed. Authority has not followed it.
Picture the person whose name is on the form. They cannot commission a survey without sign-off they don’t control. They cannot mandate training across departments that don’t report to them. They cannot compel the estate changes their own procedures assume.
If an incident happens, none of those limits will protect them as the Act of Parliament doesn’t distribute the duty in proportion to the power each person holds. It names one accountable individual and leaves the organisation to make that accountability real.
Consider what discharging the duty actually involves. Public protection procedures have to be written, briefed and rehearsed. Staff across the site have to be trained and kept current. Where the Enhanced Tier applies, measures have to be in place so far as is reasonably practicable (a phrase that will be read after any incident with the full benefit of hindsight).
None of that is deliverable by someone without a budget line, without standing at Board or governance level and without the authority to require other departments to co-operate. Yet that’s exactly the position many nominated ‘Responsible Persons’ are in. They hold the liability and can influence, at best, a fraction of what determines whether they’re exposed.
Time to fix
There is time to fix this situation and that’s worth stressing. The Act of Parliament received Royal Assent in April last year, but its requirements are not yet in force and no official commencement date has been fixed.
We maintain a weekly tracker of the verified position as the widely quoted April 2027 deadline is a floor, not a fact. The absence of a date is not a reason to wait, though. It’s the window in which the governance can be ensured calmly, rather than in a scramble when the regulations finally land.
The work for a security and risk professional over the coming months is less about hardware and more about lines of accountability. Three moves do most of the heavy lifting.
Name the ‘Responsible Person’ explicitly, in writing, and take that decision to the Board, the trustees or the governing body so that it’s owned at the top and not simply delegated downwards. Then empower the role. Give it a budget, a reporting line and the authority to convene facilities, Human Resources (HR), operations and communications. Remember that a lockdown plan HR and operations professionals have never seen isn’t a plan.
Finally, make the procedures honest. They must reflect what your site can actually do rather than what a template says it should. A procedure that assumes capabilities you don’t have is a liability wearing the costume of compliance. For reference, the tiers and the ‘Responsible Person’ duty are set out in full in our Martyn’s Law guide.
Changing the conversation
For years, security managers have struggled to have protective security taken seriously at Board level. Martyn’s Law changes that conversation. It’s a statutory mandate with a name and a face (ie Figen Murray OBE) behind it. That affords security managers the platform to ask for the resourcing, the culture and the seat at the table they’ve probably wanted for years.
Those organisations that treat it as a form to file will name a ‘Responsible Person’ and leave them stranded. The ones that treat it as a governance question will use it to build something that actually protects people.
Start by asking who the ‘Responsible Person’ is in your organisation. If you cannot answer that question without hesitating, you’ve found your first task.
Simon Legrand MCIM is Founder of Fyrfly Systems (www.fyrflysystems.com)
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM