See it on your sites
A personalised walkthrough with your locations, teams and data.

A hotel hosting a wedding on Saturday, a corporate conference on Tuesday, and a community fundraiser the following weekend is not running the same venue three times. It is running three different events, each with its own crowd profile, its own layout, its own risk.
Martyn’s Law recognises that. The question is whether your compliance process does.
The Terrorism (Protection of Premises) Act, now law, places a statutory duty on venues to have proportionate, documented and practised protective security measures in place. The specific requirements depend on your tier, based on capacity, but the principle holds across the board: you cannot treat venue security as a fixed procedure that gets reviewed once a year and filed away.
For standard duty venues (200 to 799 capacity), the requirements focus on having documented procedures and ensuring staff are trained to follow them. For enhanced duty venues (800 capacity and above), the bar is higher: a formal security plan, regular risk assessments, and evidence that procedures are being followed and updated.
Both tiers require something that many venues are not currently set up to do well: ongoing, documented compliance, not a one-time exercise.
A hotel ballroom, a community hall, a conference centre: these spaces do not host one type of event. They host dozens, often with different layouts, different crowds, different levels of risk, and different security needs.
A wedding reception with 300 guests has different ingress and egress dynamics than a ticketed political conference with the same attendance. A children’s activity day has different risk considerations than an evening comedy event. A corporate dinner with a high-profile speaker may require additional protective measures that a standard Saturday function does not.
If your Martyn’s Law compliance is built around a single venue risk assessment document, completed once and revisited annually, it almost certainly does not reflect what actually happens in your venue week to week.
This is the core challenge for dynamic venues. Compliance cannot be a static document. It needs to be a live operational discipline.
The venues that will manage Martyn’s Law well are the ones that treat it the same way they treat food safety, licensing compliance, or fire safety: as an ongoing operational responsibility with clear ownership, regular checks, and evidence of completion.
In practical terms, that means:
Event-level risk assessment, not just venue-level. Each event should be assessed against its specific profile: expected attendance, ticket type (open or controlled), likely crowd behaviour, layout configuration, supplier access, and any specific factors that increase or change the risk picture. This does not need to be a lengthy process for every wedding booking, but it does need to be a structured one.
Staff who know what to do, and evidence that they do. Martyn’s Law requires that staff understand their role in the event of an incident. That means documented training, completed before the event, with a record that it happened. Not a verbal briefing. Not an assumption that last month’s training still applies to this weekend’s new casual staff.
Documented procedures that reflect actual layouts. If your venue reconfigures for different events, your security and evacuation procedures need to reflect those configurations. A plan that shows emergency exits for a banquet layout may not be accurate for a theatre-style conference setup.
Clear escalation routes when something changes. When a last-minute change to guest numbers, layout, or event type alters the risk picture, there needs to be a process for reviewing and updating the compliance position before the event goes ahead. Not after.
Proof of completion, not just completion. Enhanced duty venues in particular need to be able to demonstrate to the Security Industry Authority that their procedures are being followed. That means records: who completed what, when, and in response to what event profile.
There is a business case here that goes beyond avoiding regulatory risk.
Event bookers, particularly corporate clients, are increasingly asking venues about their security and compliance posture. A conference organiser booking a venue for 600 delegates needs to know that the space has a credible protective security plan. A wedding couple may not ask the question directly, but they are choosing a venue they trust with one of the most important days of their lives.
Venues that can demonstrate a structured, evidence-based approach to Martyn’s Law compliance are in a stronger position. Not just because they are managing risk, but because they are building a verifiable record of professional venue management that differentiates them from venues that are treating the legislation as a box-ticking exercise
Most venues are already overstretched. Event coordinators are managing bookings, suppliers, client expectations, and a hundred operational details for every event. Adding a layer of compliance administration on top of that, without the right systems, creates either a compliance gap or an administrative burden that nobody can sustain.
The answer is not more paperwork. It is a smarter process: event-level risk assessments built into the booking workflow, training records that update automatically, task allocation that ensures the right people complete the right checks before every event, and a clear audit trail that proves it all happened.
Serve First helps dynamic venues build exactly that: a compliance process that keeps pace with your event calendar, gives venue managers clear direction on what needs to happen before each event, and gives senior leadership the visibility to know it is being done.