Premises Portal

Checklist

The documents Martyn’s Law requires: the complete checklist

Martyn’s Law never hands venues a single list of paperwork. The requirements sit across the Act, the statutory guidance and the notification regulations. This checklist puts them in one place: 24 records, labelled by what the law actually asks of each, at each tier.

Last verified against the Act and official guidance on 2 September 2026 · Reviewed fortnightly

How to read the labels

Each document carries one of four labels per tier, because the same document can change status between tiers. Where a document has the same label at both tiers, it is shown once:

Goes to SIA Goes to the SIA: the regulator receives this, as information entered in its form, as a statement inside the compliance document, or as the document itself Held as proof A legal duty exists; this document is the evidence you would show an inspector. Not submitted Good practice Nothing requires this record to exist; it strengthens every proof n/a Not required for this tier

Standard tier venues have real duties but almost nothing to hand over: there is no statutory requirement to prepare or submit a compliance document at the standard tier. Enhanced tier premises must prepare, maintain and submit one.

1. Required from every venue in scope

DocumentBoth tiers
Scope and Tier AssessmentThe building and any other land, whether it is wholly or mainly used for a Schedule 1 use, the tier conclusion and reasoning, and any Schedule 2 exclusion.Held as proof
Attendance CalculationThe greatest number reasonably expected at the same time in connection with the Schedule 1 use, the method used, and confirmation staff are included.Held as proof
Supporting Capacity EvidenceTicket data, footfall, fire capacity figures, historic attendance, room capacities, booking records.Good practice
Attendance Assessment ApprovalSign-off of the figure and method by the responsible person.Good practice
Responsible Person DeclarationLegal and trading names, contacts, company or charity number, basis of control, effective dates.Held as proof
Control and Responsibility RegisterEveryone with control of some part of the premises, what each controls, and anyone subject to the s.8 coordination duty where premises form part of other qualifying premises.Held as proof
Coordination AgreementHow responsible persons and other parties coordinate procedures and measures. No written agreement is required by law; recording one is good practice.Good practice
Landlord and Operator ResponsibilitiesThe split of duties for shared or leased premises.Good practice
Contractor Responsibility MatrixSecurity, FM and other contractors mapped to what they deliver.Good practice
Authorisation to SubmitWritten authority for an agent to submit to the SIA. Where an agent submits, the notification must confirm their authority (SI 2026/793, reg. 5).Good practice
Licences and Permissions RegisterPremises licences, TENs, safety certificates: type, reference, issuer, dates, status.Held as proof
Licence and Certificate CopiesCopies held as verification evidence; the notification asks for information about them, not the documents themselves.Good practice
SIA Notification and Amendment LogSubmitted notifications, dates, references, acknowledgements and corrections. Three months from commencement for premises already responsible; 28-day clocks for later changes and corrections (SI 2026/793). The information goes in the SIA’s form; this log is your proof it went.Goes to SIA

2. Public protection procedures

DocumentStandardEnhanced
Public Protection Procedures PlanThe four procedure categories of s.5(3), followed when there is reason to suspect an act of terrorism is occurring or about to occur at or near the premises: evacuating; moving people to a place where there is less risk of physical harm; preventing entry or exit; providing information. The guidance calls these evacuation, invacuation, lockdown and communication. The duty is appropriate procedures so far as reasonably practicable. At standard tier that means procedures, not paperwork; at enhanced tier only a statement of the procedures travels, inside the compliance document, and the operational plan stays with you.Held as proofGoes to SIA

3. Supporting evidence every venue should hold

DocumentStandardEnhanced
Roles and Responsibilities MatrixWho decides, who acts, deputies and out of hours cover.Good practiceHeld as proof
Emergency Contact and Escalation ListEmergency services, management, landlord, contractors, neighbours.Good practiceGood practice
Staff Briefing and Awareness RecordsInductions, briefings, acknowledgements, refreshers. The guidance treats training records as a necessary element of the enhanced-tier compliance document.Good practiceHeld as proof
Testing and Exercise RecordsDrills, desktop exercises, communications tests, actions and completion.Good practiceGood practice
Review and Change LogReviews after changes to layout, ownership, attendance, staffing or lessons learned.Good practiceGood practice

4. Enhanced tier only

DocumentStandardEnhanced
Senior Individual DesignationRequired only where the responsible person for enhanced premises is an organisation (s.10). The notification includes their details and date of designation.n/aHeld as proof
Compliance DocumentThe central statutory document (s.7): procedures in place, measures in place or proposed, and assessments of how each reduces harm and vulnerability. The one document that goes to the SIA in full; revisions within 30 days.n/aGoes to SIA
Public Protection Measures ScheduleEvery measure across the four s.6 categories: monitoring; movement; physical safety and security; security of information. Hold securely.n/aHeld as proof
Training and Competence RecordNeeds assessment, delivery evidence, competence checks, refreshers.n/aHeld as proof
Deferred Measures and Action PlanMeasures proposed but not yet in place are statutory compliance-document content; deferral reasons and interim mitigations are guidance recommendations.n/aHeld as proof

Standard tier

19 of 24 in scope

Enhanced tier

24 of 24 in scope

Three details that catch venues out

A sensible filing structure: venue identity and scope · responsible persons and governance · attendance assessment · licences and permissions · SIA notifications · public protection procedures · public protection measures · training and staff awareness · testing and exercises · coordination and contractors · actions and improvements · reviews and version history. Sensitive material (plans, CCTV coverage, response arrangements) should sit behind strict role-based access: the guidance says information in the compliance document should be held securely, minimising the risk that it could help someone plan or carry out an attack (para 8.67).

If you host a qualifying event

Events at enhanced tier premises are not qualifying events: your premises duties already cover them. The qualifying events regime (s.3) exists for large events elsewhere: 800 or more people expected at the same time at some point during the event, entry checked by payment, tickets or passes, or membership of a club or similar body, at premises that are not already enhanced duty premises. The event’s premises can be a building or just land, which is how outdoor sites come into scope, and events at places of worship and most education premises are excluded.

A qualifying event brings two records of its own: an SIA notification on 14-day clocks running from the date the event is first publicised, or from commencement day for events already publicised by then (SI 2026/793), and an event compliance document. The responsible person is whoever has control of the premises for the event, which may be the organiser rather than the venue. If that is not you, your part is coordination under s.8, and the Control and Responsibility Register above is where that lives.

Premises Portal turns this checklist into a live status report: what the law requires at your tier, what you hold, and what is missing. Coming 2027. Start with the full venue guide.