
The responsible person under Martyn’s Law is the individual, organisation or company that controls qualifying premises or a qualifying event and must meet the duties in the Terrorism (Protection of Premises) Act 2025. The key test is control, not ownership, so the responsible person may be a tenant, venue operator, event organiser, charity, school trust, business owner or company, depending on who manages the premises or event when the public are present.
For many UK organisations, the new duty can feel difficult to understand at first, especially where buildings, events or public spaces are shared. isecurity Solutions is a trusted UK provider of commercial and domestic security systems, helping homes and businesses stay protected around the clock with CCTV, intruder alarms, fire safety, access control and construction site monitoring. Our team designs reliable, tailored solutions backed by responsive service and modern remotely monitored technology.
This information is general guidance and not legal advice. If your control arrangements are complex, shared or disputed, it is sensible to take legal advice before making final decisions.
Martyn’s Law uses the term responsible person to identify who must comply with the Act. The law does not simply point to the person whose name is on the Land Registry, because the person who owns a building may not be the person who controls how it is used by the public.
If you run a shop in a leased unit, manage a community hall, operate a hotel, organise a large event or control a public venue, you may be the responsible person even if you do not own the building. A useful starting point is to ask who decides how the premises are used, when they open, how staff work and how public access is managed.
If you are still getting to grips with the wider duty, the plain English overview of What is Martyn’s Law UK explains the background, tiers and purpose of the legislation in more detail.
Section 4 of the Terrorism (Protection of Premises) Act 2025 explains who is responsible for qualifying premises and qualifying events. It uses control as the central test, which means the regulator will look at who has real authority over the premises or event, not just who owns the property.
For qualifying premises, the responsible person is the person who has control of the premises in connection with their relevant Schedule 1 use. Schedule 1 covers premises such as shops, restaurants, entertainment venues, education settings, places of worship, healthcare premises and similar public facing locations.
For qualifying events, responsibility sits with the person who has control of the event while it is taking place. This matters because an event organiser may be responsible even where the land or venue is owned by somebody else.
Official government guidance on the Act and the regulator role is available through GOV.UK Martyn’s Law guidance, which is useful if you need the statutory position from the source.

The main rule is that the responsible person is usually the party with operational control. Operational control means having the practical power to run the site or event, make decisions, manage staff, control access, set procedures and influence how people are protected.
Ownership may still matter where the owner also operates the premises. However, owning the building does not automatically make someone responsible under Martyn’s Law if another organisation controls the relevant public facing use.
For example, a landlord may own a retail unit, but if a tenant runs the shop, manages opening hours, employs staff and controls customer access, the tenant is likely to be the responsible person for that shop. The landlord may still have other legal duties, but Martyn’s Law responsibility follows control of the qualifying activity.
The responsible person for qualifying premises is the person or organisation that controls the premises in connection with a specified public facing use and meets the relevant capacity threshold. This means the answer depends on who runs the activity that brings the public into the premises.
This control test is practical rather than theoretical. Ask who runs the public facing operation, who sets the site rules, who trains the team, who manages daily procedures and who could actually make security improvements happen.
Standard tier premises are generally those where it is reasonable to expect that 200 to 799 individuals may be present at the same time. The responsible person for standard tier premises must meet proportionate public protection procedure duties.
These procedures are not about turning every cafe, church hall or community venue into an airport. They are about having sensible plans for evacuation, invacuation, lockdown and communication if a terrorist incident occurs nearby or at the premises.
Enhanced tier premises are generally those where it is reasonable to expect 800 or more individuals may be present at the same time. The responsible person has more detailed duties because larger venues usually have more complex risks, more staff, more visitors and more movement across the site.
Enhanced tier requirements can include documenting public protection measures, considering physical security, assessing vulnerabilities, training staff and coordinating with relevant parties. If your site is large, busy or complex, early planning is far easier than trying to make changes under pressure later.
Security planning may include access control, monitored CCTV, intruder alarms and staff alert procedures, all tailored to the way your site actually works. iSecurity Solutions supports public facing organisations with practical business security systems that fit daily operations and help teams respond with confidence.
Where premises have more than one public facing use, the responsible person depends on who controls the relevant Schedule 1 use and how the site is managed in practice. A hotel might include a restaurant, bar, conference space and leisure facilities, while a school may host community events after hours.
The Act looks at the relevant Schedule 1 use and who controls the premises in connection with that use. Where there are multiple uses, the principal use and the way control is divided become important.
If one company operates the entire building, identifying the responsible person may be straightforward. If different parts are operated by different tenants or organisations, responsibility may sit with different parties for different areas or activities.
The responsible person for a qualifying event is the person or organisation that controls the event during the time it takes place. This is different from premises responsibility because event control may be temporary and may sit with an organiser rather than the usual site operator.
A qualifying event is not judged only by who owns the land or building. It is judged by who controls the event, including entry, staffing, layout, crowd management, ticketing, security arrangements and emergency procedures.
Qualifying events are also treated differently from standard tier premises. The focus is on who controls the event during the relevant period, how public access is arranged and how many people are reasonably expected to attend. If you control the gates, the event plan, the team and the public movement, you may be the responsible person.
Event control takes priority over land ownership when deciding who is responsible for a qualifying event. For example, if a local authority owns a park but a private organiser hires it for a paid festival and controls entry, staffing and the event plan, the organiser is likely to be the responsible person for that event.
The landowner may still have contractual requirements, health and safety duties or responsibilities for the wider site. However, Martyn’s Law looks closely at who controls the qualifying event itself during the relevant period.
A venue owner may be the responsible person where it keeps operational control of the event, but an external organiser may be responsible where it takes control of the venue for the event. Venue hire arrangements can cause confusion, so the contract and the day to day arrangements should be clear.
If the venue owner keeps full operational control, provides staff, manages entry, controls safety procedures and runs the event, the venue owner may be the responsible person. If the event organiser takes over the venue, provides the operating team and controls the public event, the organiser may carry the responsibility.
The contract should reflect reality, but it cannot rewrite the facts. If a document says one thing while day to day control says another, the regulator is likely to look at what actually happens on the ground.
More than one person or organisation may have responsibility where control is shared across larger sites, shared premises or events involving several delivery partners. In these cases, the responsible parties should cooperate and clearly record who controls each area, procedure and activity.
Joint responsibility does not mean every tenant in a shopping centre is automatically responsible for the whole centre. A tenant may be responsible for its own unit, while the centre operator may be responsible for common areas if it controls them.
Coordination is vital where duties overlap. Shared radio procedures, evacuation routes, staff briefings, CCTV coverage, access routes and emergency communication plans all work better when people agree them before there is a problem.
If the responsible person is an organisation rather than an individual, enhanced tier duties include appointing a senior individual. This person must be senior enough to influence decisions, secure resources and keep compliance under proper review.
The senior individual is not appointed so everyone else can step away from the issue. Their role is to help ensure the organisation takes the duties seriously, assigns responsibilities properly and keeps oversight at senior level.
The senior individual requirement applies because larger organisations can lose clear accountability across teams, departments and committees. Martyn’s Law expects clear ownership within the organisation, especially where duties affect budgets, staffing, security systems, training, contractors and the way the public move through a site.
The appointed senior individual should be someone with enough authority to make sure compliance actually happens. This may be a director, trustee, partner, senior manager, chief operating officer, facilities lead or another person with suitable influence.
The best choice is not always the person with the most senior job title. It is the person who understands the operation, can secure resources, can challenge weak procedures and can keep the board or leadership team properly informed.
A responsible person can delegate tasks, but cannot delegate the legal responsibility itself. This is important because many organisations use contractors, consultants, security providers and venue teams to help them meet practical duties.
For example, you can ask a security company to install CCTV, support access control, advise on suspicious behaviour, help with staff training or monitor alarms. You can also ask a facilities manager to maintain records and arrange exercises.
However, if you are the responsible person, you remain accountable for making sure the duties are met. Delegation is useful and often essential, but it does not remove the legal duty from the person or organisation with control.
For smaller organisations building their first compliance plan, the Martyn’s Law compliance checklist gives a practical way to think through actions, evidence and next steps.
Common edge cases under Martyn’s Law are usually solved by applying the control test to the real facts. The following examples show how responsibility can work in typical UK premises and events.
Where a tenant operates a public facing business from leased premises, the tenant will often be the responsible person for that business use. The landlord may own the property, but ownership alone is not usually enough.
If the landlord controls shared entrances, reception areas, car parks, service yards or common evacuation routes, the landlord or managing agent may have responsibility for those areas. The answer may therefore be split between tenant controlled and landlord controlled spaces.
In a shopping centre, individual retailers may be responsible for their own units if they control them. The shopping centre operator may be responsible for malls, entrances, common areas and shared public spaces under its control.
In multi occupancy premises, responsibility may be divided between tenants, managing agents, landlords and site operators. The practical question is who controls each area, each procedure and each public facing activity. One party might control a shop unit, another might control the shared lobby and another might manage wider estate security arrangements.
This is why coordination matters so much. A lockdown message from one shop is not helpful if the centre announcement system gives different instructions, so shared plans should be agreed and tested.
Places of worship, schools, colleges, hotels and mixed use venues may have different responsible persons at different times, depending on who controls the qualifying use when the public are present.
A church may control regular services, while an external organiser may control a ticketed concert in the same building. A school trust may control education use, while a sports club hiring the hall may control a public event outside school hours.
Temporary event hire needs careful attention because control can change for a short period. If an organiser takes over a venue, controls admission, provides staff and manages the event plan, they may become the responsible person for that qualifying event.
Good hire agreements should set out security roles clearly, including crowd control, searches, communications, emergency routes, CCTV use, incident reporting and liaison with police or local authorities where needed.
The Security Industry Authority, known as the SIA, is the regulator for Martyn’s Law. Responsible persons may need to notify the SIA about qualifying premises or qualifying events, depending on the tier and circumstances.
The SIA’s role includes supporting compliance, gathering information, issuing guidance and taking enforcement action where necessary. It will expect responsible persons to understand their duties, keep suitable records and review arrangements when circumstances change.
Notification should not be treated as a one time admin task. If control changes, the use changes, capacity changes or the site moves into a different tier, the responsible person should review the details and update the SIA where required.
SSAIB and Insurance Approved security support can help the responsible person show that security systems have been designed, installed and maintained to a recognised standard. It does not transfer legal responsibility, but it can strengthen evidence, support insurer confidence and help organisations put practical protection measures in place.
For premises where intruder alarms, CCTV, access control or monitored systems form part of the security plan, using an accredited provider helps avoid weak spots and poor workmanship. Where police response is required for an alarm system, insurers may also ask for an approved system and a Police Response URN, which is a unique reference number used for police response eligibility.
iSecurity Solutions provides tailored systems for commercial and domestic sites across the UK, including CCTV, intruder alarms, access control, fire safety solutions and monitored protection for higher risk or multi site environments. The aim is simple: reliable equipment, clear advice and responsive support that helps protect people, property and daily operations.
If you are unsure who the responsible person is, a structured review can help you ask the right questions. It will not replace legal advice in complex cases, but it can make the decision clearer and easier to evidence.
The responsible person under Martyn’s Law is the party with control of qualifying premises or a qualifying event. The law is designed this way because the person with control is usually the person best placed to reduce risk, train staff and make practical decisions.
For most organisations, the safest approach is to map control honestly, record your reasoning and avoid assuming that ownership, job title or contract wording gives the full answer. If you control the public facing activity, you should assume you may have duties and take advice where the position is unclear.
Martyn’s Law is not about panic or paperwork for the sake of it. It is about helping public places prepare better, respond faster and protect people in a way that is proportionate to their size, use and risk.