Articles
Martyn's Law: Why Governance Matters
When that loop works, the rest of the implementation has something solid to stand on.
By Danni Grant ·
Over the last few weeks, the conversations I’m having about Martyn’s Law have widened. Hospitals, universities, colleges, retail estates and some significant UK event programmes. Very different settings, with very different operational demands, all working through what this means for them.
One subject keeps coming back. Governance.
When I say governance, I mean something quite practical. It’s how something identified at a premises reaches the person who can make a decision about it, and how that decision gets back to the people who need to act on it.
When that loop works, the rest of the implementation has something solid to stand on. Without it, you can have people working incredibly hard while an important issue sits unresolved between them.
The law doesn’t use the word governance
First, I want to be clear about something. Martyn’s Law doesn’t require you to have a governance structure. You won’t find the word anywhere in the Act.
What the Act does require is that the responsible person for qualifying premises ensures appropriate public protection procedures are in place, so far as is reasonably practicable (section 5).
Those two words, in place, matter.
You could fill in a template this afternoon and have procedures written down by tonight. But would your staff know them? Would they understand their own part in them? Have they ever been tried?
The Home Office’s statutory guidance is direct about this. If the staff responsible for carrying out procedures haven’t been informed of them or trained in how to implement them, it’s likely to be difficult to demonstrate that appropriate and reasonably practicable procedures are in place (paragraph 7.52). It also asks the responsible person to consider how procedures will be tested and practised, to make sure they’re fit for purpose (paragraph 7.28).
Standard Tier premises have no legal requirement to document their procedures. However, the guidance says the responsible person should, and that without it, demonstrating compliance to the SIA may be difficult (paragraph 7.32). SIA inspectors will be able to do more than read a document, too. They can observe what’s happening on the premises and require people on the premises to explain relevant documents (paragraph 9.5).
There’s one more point that I don’t think gets enough attention. The Act says that acting in accordance with the statutory guidance can be relied on as tending to show you haven’t breached a requirement (section 27(5)). Much of what the guidance recommends isn’t a legal requirement in itself. Following it is part of how you evidence your approach.
For Enhanced Tier premises and qualifying events, the Act goes further. Measures must be assessed and kept under review (section 6). A compliance document must be kept up to date and provided to the SIA (section 7). And where the responsible person is an organisation, a senior individual must be designated (section 10).
So, the law doesn’t mandate governance. But the outcomes it does require are very hard to achieve, or to evidence, without it. For me, governance is how you know your procedures are more than paper.
This is our approach, and this is why
Much of my career was spent in policing, where policy and process are often quite black and white. Formulaic, by design. Information is passported from one place to another and stored. And when something goes wrong, one of the first things that happens is a review of the policy or process that was meant to prevent it.
Public inquiries and reviews following terrorist attacks have shown that policy can fail. Having a process written down didn’t always mean it was understood, followed, or right for the situation it eventually met.
That experience shapes the one document I’d encourage every organisation to have. The Act doesn’t mandate it. It simply sets out this is our approach to Martyn’s Law, this is how we’ve approached the legal requirement, these are the actions we’ve taken, and this is why.
For me, the why matters most. A template will show which procedures exist, but it won’t explain the thinking behind them.
People move on. The responsible person may stay the same for years, but the individuals working within it change. A new facilities manager, a new governor or a new head of security will inherit whatever has been left for them. If all they inherit is a set of procedures, they have no way of knowing what was considered, what was ruled out, or what assumptions the decisions rested on. If they inherit the reasoning, they have a foundation to build on, and a sound basis for reviewing it when circumstances change.
The guidance points in the same direction. It suggests recording the rationale where a procedure is judged not to be appropriate or reasonably practicable (paragraph 7.24). For Enhanced Tier premises and qualifying events, the compliance document must include an assessment of how the procedures and measures may be expected to reduce risk and, for measures, vulnerability (section 7). An approach document goes further than both, by choice. In my experience, it’s one of the most valuable things an organisation can write.
Returning to the college
In an earlier blog, I wrote about working across a further education college estate. That work has moved on well. Scoping is nearly complete, working groups are in place, and we’re now supporting briefings for governors.
That last step is more significant than it might sound. Where premises are used by a college in the further education sector in England, the Act names the college’s governing body as the responsible person (Schedule 1, paragraph 15(2)). For those buildings, the responsibility the legislation creates sits with the governors as a body.
So I’d want a governor to be able to ask how the work is progressing and get an answer that means something. Which parts are complete? What are we still working through? Is anything holding us up? What do you need from us?
That’s a far more useful conversation than simply being told that Martyn’s Law is being dealt with. There’s more to share on this work in a future case study.
Being clear about responsibility
Every qualifying premises has a responsible person. The Act defines who that is, so it isn’t a matter of choice (paragraph 6.1). It’s most likely to be a company or an organisation rather than a named individual (paragraph 6.2). Tasks can be delegated, but legal responsibility can’t be handed to a contracted service provider (paragraph 6.1).
If an organisation brings in outside support, it remains liable, and the guidance says it should be satisfied that the support is suitable, properly resourced and effectively delivered (paragraph 6.7). That applies to us as consultants as much as anyone, and I think it’s exactly the right test.
Within that, I’d look for a few things in practice. Someone clearly owns the work. The people doing it know what they can decide and what needs to go further. There’s a route up when something needs approval, resources or advice, and a route back so that the person who raised a concern hears what was decided, and when.
The guidance makes a similar point about the procedures themselves. It asks the responsible person to consider the key roles in each one, including who will decide what action to take and who has the authority to start a procedure (paragraph 7.28). If that clarity is needed on the day, it’s worth building it into how the work is run long before then.
Someone also needs to keep it all under review. The guidance says procedures should stay up to date as the premises and their operation change, with a periodic review that could be annual depending on the circumstances (paragraph 7.29).
What this means in your environment
For a single premises, the people overseeing the work and those carrying it out may work alongside each other every day. Across a national estate, that relationship is much less direct, and senior leaders need a way to understand progress across many locations, including where individual premises need more help.
The guidance recognises that one responsible person may cover several premises, giving the examples of a chain of restaurants or shops, and a governing body for an educational or medical trust. Where that’s the case, it asks the responsible person to consider how the requirements can be met at each individual premises, avoiding a one-size-fits-all approach (paragraph 6.6). Good governance helps an organisation stay consistent without losing sight of what makes each site different.
In a hospital, decisions about procedures need input from people who understand patient care and how different parts of the site operate. In education, the people supporting students may identify considerations that wouldn’t be obvious from a building plan. An events programme brings questions about how organisers, venues and delivery teams work together, and who needs to know when arrangements change.
Existing management arrangements may already provide a good place for these conversations, and I’d start there.
No single answer
Governance means different things to different organisations, and I think that’s how it should be.
The Act sets legal minimum requirements, designed to be proportionate (paragraph 2.11). What’s reasonably practicable depends on the circumstances of the premises, including the resources available (paragraph 7.23). For a small venue with one manager and a handful of staff, a clear owner, a simple record of decisions and a regular conversation may be all that’s needed. That can be entirely appropriate.
At the other end, I’m working with clients who are choosing to go well beyond what the law requires. They’re putting huge effort into documenting what they’ve done and why, including the options they’ve considered and set aside. Nobody has told them to. They’ve decided that’s the standard they want to hold themselves to.
The guidance leaves room for that. It recognises that protective security can be put in place in advance of, in addition to, or alongside the Act’s requirements (paragraph 2.12). For larger or more complex Standard Tier premises, it also suggests they may want to consider the additional considerations on procedures written for Enhanced Tier premises and qualifying events (paragraphs 7.31 and 8.2 to 8.6).
I don’t think either is the right answer for everyone. What matters is that the arrangements fit the organisation, and that whatever is written down reflects what actually happens.
Culture sits alongside all of this. The guidance describes a security culture as a set of values, shared by everyone in an organisation, that shape how people think about and approach security. It says a good one takes effort to build and cascades from the top down (paragraphs 2.12 and 7.10).
Governance can give the work a structure, but it’s culture that decides whether people actually use it. Every route and record can be in place, but if a member of staff doesn’t feel able to raise a concern, or doesn’t believe anything will happen if they do, the loop breaks at the first step.
Taking time to listen
Governance depends on information, and much of the information that matters can’t be found on a spreadsheet. It sits with the people who use the buildings every day.
That’s why I place so much value on getting onto an estate and spending time with people in their own environment. Walking a building helps. So does sitting down and asking someone to talk you through their day. What changes outside normal hours? Who else uses the space? What are they concerned about?
A cup of tea is usually my only request at that point.
If someone who works in a building says a proposed procedure will be difficult to carry out, I want to understand why. Last time, I wrote about communication during an incident. There’s a conversation to have well before that, about whether the people developing the arrangements have heard from those who will be expected to use them.
I want people to feel able to ask questions, including the ones they think they should already know the answer to. I’m still asking questions myself. As we bring in colleagues from the wider GCG team to support implementation, that approach matters to me. Whatever expertise we bring, we need to understand the organisation and work with the people who know it.
What would I ask you?
If I were sitting with your organisation now, I’d want to understand how the work connects across it.
Who is doing the practical work? Who is overseeing it? How does something identified at one premises reach the person who can make a decision about it? And how does that decision get back to the people who need to act on it?
In my first blog, I asked whether your people would know what to do if something happened tomorrow. Last time, I asked whether they’d know what to say. I’d add a third question now. If one of them spotted a problem today, would it reach someone who could fix it?
If the answer is yes, governance is doing its job.
In my next blog, I’ll look at what happens when governance has to stretch further, across divisions and borders, and between the many organisations that come together to deliver an event.
Download this article (PDF, 238KB)
See all articles.