How to write an event security plan: template and review checklist

An event security plan defines the security risks, responsibilities, controls and response arrangements for a particular event. It should reflect the venue, attendance, activities, operating periods and current threat environment, rather than relying on a generic plan copied from another event.

This guide provides a practical event security plan template and a checklist for reviewing whether the plan is clear, supported by evidence and ready for operational use.

Write a security plan - how to guide - man outside a building on site doing a security plan

Event security plan template

Download the editable Event Security Plan Template to work through the 14 sections below, including document control, assumptions, responsibilities, supporting evidence, outstanding actions, approval and controlled annexes.

Event security plan review checklist

Use the companion review workbook to record findings and evidence, manage outstanding actions, document scenario tests and retain the review, approval and version history. The workbook does not calculate a compliance or approval result.

 

Security plan, risk assessment or emergency plan?

These documents are related, but they serve different purposes.

Document Purpose
Security risk assessment Identifies the people and assets requiring protection, the relevant threats and vulnerabilities, the level of risk and the measures needed to manage it.
Event security plan Turns that assessment into defined responsibilities, controls, communications and operating arrangements for the event.
Emergency plan Sets out what people should do when a serious incident or emergency occurs, including command, communications, evacuation, casualty arrangements and liaison with emergency services.

The security risk assessment should inform the security plan. The security plan should then connect with the event’s emergency plan and other operational arrangements.

See SIRV’s guide to completing a security risk assessment for more detail.

Event security plan template

The following structure can be adapted to suit the event’s size, complexity and risk profile. A small local event will not require the same level of detail as a major festival, stadium event or high-profile gathering.

1. Event and document details

Record:

  • Event name, location and organiser
  • Event dates and operating hours
  • Build, rehearsal, public-opening and breakdown periods
  • Expected attendance, including staff and contractors
  • Maximum number of people expected at the same time
  • Plan owner, author, reviewers and approver
  • Document version and approval date
  • Distribution list and access restrictions
  • Related plans, risk assessments and procedures

The plan should make clear which version is current and who is authorised to approve changes.

2. Scope and assumptions

Define what the plan covers and its limits.

Include:

  • Areas included and excluded
  • Public and restricted operating periods
  • Assumed attendance and audience profile
  • Known concurrent events or nearby activities
  • Dependencies on the venue, contractors or external agencies
  • Any temporary structures or off-site areas
  • Assumptions that would require the plan to be reconsidered if they changed

An assumption should not be presented as a confirmed fact. Where information remains unavailable, record the uncertainty and identify who must resolve it.

3. Roles, responsibilities and decisions

Name the people or organisations responsible for:

  • Overall event security
  • Venue security
  • Event safety
  • Control-room supervision
  • Incident command
  • Stewarding and guarding
  • Accreditation and access control
  • Crowd and traffic management
  • Contractor management
  • First aid and casualty arrangements
  • Communications
  • Emergency-service liaison
  • Approving changes to the plan

Record who has authority to make important decisions, including delaying an opening, stopping an activity, changing access arrangements, evacuating, invacuating or locking down an area.

Contact details may need to be held in a controlled operational annex rather than in the widely distributed plan.

4. Threat and security risk assessment

Summarise or link to the event’s current security risk assessment.

It should consider:

  • The people and assets requiring protection
  • Relevant intentional and accidental threats
  • Site and event vulnerabilities
  • The likelihood and potential consequences of each risk
  • Existing controls
  • Further measures or actions required
  • The person responsible for each action
  • The date by which it must be completed

The assessment should reflect the particular event. Attendance, VIPs, publicity, location, access routes, crowd density and activity outside the protected perimeter may all affect the risk.

5. Perimeter, entry and access control

Explain:

  • The event perimeter and controlled areas
  • Public entry and exit points
  • Accreditation, ticket or identity checks
  • Search and screening arrangements
  • Prohibited items
  • Staff, contractor, performer and vehicle access
  • Lost, stolen or duplicated passes
  • Access for emergency services
  • Accessible entry and exit arrangements
  • How queues and crowds outside the perimeter will be managed
  • What happens if an access-control measure fails

The plan should connect each stated control to an owner, operating procedure and supporting evidence.

6. Crowd, vehicle and contractor arrangements

Cover:

  • Expected crowd numbers and movement
  • Arrival, departure and transport peaks
  • Queue and capacity management
  • Separation of pedestrians and vehicles
  • Deliveries and vehicle movements
  • Parking and hostile-vehicle considerations
  • Contractor access and supervision
  • Temporary works and restricted areas
  • Interfaces between the organiser, venue and suppliers
  • Escalation when conditions differ from the plan

Where another document contains the detailed arrangement, link to its approved version rather than repeating an incomplete summary.

7. Control room, communications and escalation

Define:

  • The location and operating hours of the control room
  • Who supervises it
  • Information sources available to the team
  • Radio channels and call signs
  • Emergency and fallback communication methods
  • Information-recording arrangements
  • Escalation thresholds
  • Who receives significant updates
  • How decisions and actions are recorded
  • How information will be shared with emergency services

Test radios, public-address systems and other essential communication equipment before the event.

8. Incident command and emergency-service liaison

Explain the event’s command structure and how it connects with external agencies.

Include:

  • Operational, tactical and strategic responsibilities where relevant
  • Who initially leads an incident
  • How command may be transferred
  • Where responding agencies should report
  • Emergency access and rendezvous points
  • Information that will be available to responders
  • How the event team will support, and where necessary hand over to, the emergency services
  • How decisions, actions and changes in command will be recorded

The structure should be proportionate and understood by the people expected to use it.

9. Emergency arrangements

Set out the arrangements for foreseeable security and safety emergencies, including where relevant:

  • Alerting the emergency services
  • Warning people at the event
  • Evacuation
  • Invacuation
  • Lockdown
  • Managing congestion at exits
  • Protecting people in the immediate vicinity
  • Missing or vulnerable people
  • Suspicious items
  • Security breaches
  • Severe weather
  • Fire or structural failure
  • Loss of power or communications
  • Cancellation or abandonment
  • Reuniting people after an incident

The HSE’s event guidance recommends that an emergency plan be proportionate to the risks and address actions such as moving people away from danger, summoning emergency services, managing casualties and liaising with authorities.

10. First aid and casualty arrangements

Record:

  • First-aid and medical providers
  • Treatment locations
  • Access and routes for ambulances
  • Casualty reporting arrangements
  • Responsibility for coordinating the medical response
  • Arrangements for a major or multiple-casualty incident
  • Welfare and support after a serious event
  • How information about casualties will be handled securely

These arrangements should be developed with competent medical and event-safety input.

11. Training, briefings and exercises

Identify:

  • Who requires training
  • Role-specific briefing requirements
  • Terrorism awareness where relevant
  • Procedures for reporting suspicious activity
  • Emergency roles
  • Communication protocols
  • Equipment training
  • Exercise and rehearsal plans
  • Attendance records
  • Gaps identified and actions assigned

Briefing attendance alone does not demonstrate that a procedure is workable. Use exercises and realistic scenarios to test whether people understand their roles and can carry them out.

ProtectUK’s Purple Guide counter-terrorism chapter emphasises that event planning, management, incident response, safety, security and service should be considered together.

12. Supporting evidence

A plan may state that a control exists without showing that it is ready to operate.

Supporting evidence might include:

  • Approved risk assessments
  • Site plans
  • Staffing schedules
  • Contractor competence records
  • Training and briefing records
  • Equipment inspection or test records
  • Exercise reports
  • Communications tests
  • Agency consultation records
  • Approved procedures
  • Licences or permissions
  • Records showing that outstanding actions were completed

Evidence is the part of the record that shows what has actually been done to meet the requirement. The reviewer should therefore distinguish between:

  • A control being mentioned
  • A control being properly described
  • A named person owning it
  • Evidence showing that it has been implemented or tested

13. Outstanding actions

Maintain a clear action list containing:

  • The gap or decision requiring action
  • The person responsible
  • The required completion date
  • Priority
  • Current status
  • Evidence required for closure
  • The person authorised to confirm completion

A plan should not be approved without clearly stating how any accepted outstanding items will be managed.

14. Approval, version control and review

Record:

  • Who reviewed the plan
  • The reviewer’s decision
  • Conditions attached to approval
  • Outstanding actions
  • Approval date
  • Current version
  • Distribution date
  • Next planned review point
  • Events that would trigger an earlier review

Store the plan securely and restrict access according to the sensitivity of its contents. Keep a clear version history so users can identify what changed, why it changed and which version applies.

Event security plan review checklist

The following table can be used when reviewing a draft plan.

Requirement What the plan says Supporting evidence Owner Gap or action Reviewer decision
Document ownership and approval Current author, reviewer, approver and version are identified Approval record and version history Plan owner Complete during review Accept, update or escalate
Scope and assumptions Event, areas, periods and important assumptions are defined Site plan, programme and attendance information Event lead Complete during review Accept, update or escalate
Risk assessment Relevant threats, vulnerabilities and controls are addressed Approved security risk assessment Security lead Complete during review Accept, update or escalate
Roles and authority Operational responsibilities and decision authority are clear Role descriptions and contact arrangements Event director Complete during review Accept, update or escalate
Access and perimeter Entry, accreditation, screening and perimeter controls are described Access plan, pass procedure and staffing plan Security manager Complete during review Accept, update or escalate
Crowds, vehicles and contractors Key movements and interfaces are controlled Crowd plan, traffic plan and contractor records Relevant operational owner Complete during review Accept, update or escalate
Communications and control room Channels, escalation and fallback arrangements are defined Communications plan and equipment-test record Control-room lead Complete during review Accept, update or escalate
Emergency response Command, evacuation, invacuation, lockdown and liaison are addressed Emergency plan and exercise record Emergency-planning lead Complete during review Accept, update or escalate
Medical response First-aid, casualty and ambulance arrangements are defined Medical plan and provider confirmation Medical lead Complete during review Accept, update or escalate
Training and exercises Required people have been briefed and arrangements tested Training records and exercise reports Training owner Complete during review Accept, update or escalate
Supporting evidence Important controls are supported by current records Linked approved documents Plan owner Complete during review Accept, update or escalate
Outstanding actions Gaps have owners, dates and closure evidence Action log Individual action owners Complete during review Accept, conditionally accept or reject

A reviewer should not treat the presence of a heading or statement as proof that the underlying arrangement exists. Where evidence is absent, the plan should record the gap and the action required.

Does Martyn’s Law apply to every event?

No. The Terrorism (Protection of Premises) Act 2025, commonly called Martyn’s Law, has been enacted. As at 5 September 2026, Home Office statutory guidance stated that section 27 had been commenced to enable publication and laying of the guidance, while the Act’s substantive requirements had not yet been commenced. Check the current official guidance before relying on this dated position.

Whether an event is a qualifying event depends on six statutory criteria. In summary, it must take place at premises as defined by the Act; not take place at premises already covered as enhanced-tier premises; be accessible to the public; reasonably expect 800 or more individuals, including staff, to be present at the same time at some point; have measures to check an entry condition; and not take place at excluded premises.

An event security plan and the Act’s future compliance document are not automatically the same thing. Organisations should check the current Home Office statutory guidance and obtain appropriate advice when determining whether particular premises or events fall within scope.

SIRV has also published a practical overview of Martyn’s Law readiness.

Who should write and approve the plan?

The experience required should reflect the event’s scale, complexity and risk. The author may be an internal security or event-safety lead, an external specialist or a team combining several disciplines.

Input may be needed from:

  • The event organiser
  • The venue operator
  • Security and stewarding providers
  • Safety and medical teams
  • Contractors
  • Transport or traffic specialists
  • Local authorities
  • Emergency services

The person approving the plan must understand what that approval means and have the necessary authority. Approval should not be treated as an administrative signature.

How should the plan be tested and reviewed?

Test the plan against realistic scenarios. This may include table-top exercises, practical rehearsals and communication-system tests.

Reviews should also take place when relevant changes occur, such as:

  • A significant change to the event or venue
  • Different attendance or audience characteristics
  • New threat information
  • A change of contractor or responsible person
  • A material change to access, crowd or transport arrangements
  • Lessons from an incident, near miss or exercise
  • Failure of an important control
  • A change in legislation or official guidance

A periodic annual review may be appropriate in some circumstances, but it is not a universal legal rule for every security plan. The review frequency should reflect the event, its risks and the applicable requirements.

Download the editable event security plan template and companion review workbook.

Where can AI assist?

AI may help a reviewer:

  • Check whether expected sections are present
  • Identify gaps or contradictions
  • Compare a plan with agreed requirements
  • Connect statements to supporting evidence
  • Structure questions and feedback
  • Apply a consistent review process across several documents

It should show the reviewer what information supports its findings and where evidence is missing.

AI does not approve the plan, verify that a stated control exists in practice or guarantee legal compliance. Approval remains with the competent or authorised person.

Frequently asked questions

What should an event security plan include?

It should define the event, scope, risks, responsibilities, access controls, crowd and vehicle arrangements, communications, incident command, emergency response, medical arrangements, training, supporting evidence, outstanding actions and approval arrangements.

Who should write an event security plan?

A person or team with experience appropriate to the event’s scale, complexity and risks. Larger or higher-risk events are likely to require contributions from several operational specialists and relevant external agencies.

What is the difference between a security plan and an emergency plan?

The security plan describes how security risks will be managed during the event. The emergency plan concentrates on the response when a serious incident or emergency occurs. They should be consistent and connected.

How often should an event security plan be reviewed?

Review it periodically and after relevant changes, incidents or exercises. Annual review may be suitable in some circumstances, but it is not a universal requirement.

Does Martyn’s Law apply to every event?

As at 5 September 2026, Home Office statutory guidance stated that the Act’s substantive duties had not yet been commenced. Check the current guidance before relying on that position.

Can AI approve an event security plan?

No. AI may support document review by identifying gaps, inconsistencies and missing evidence. Approval must remain with the competent or authorised person.

Review security plans more consistently

Where teams review multiple security plans, a controlled document-evaluation process can help them apply agreed requirements consistently, show the evidence behind each finding and structure feedback for the responsible reviewer.

SIRV AI document evaluation is designed to support that review work while leaving approval with the appropriate person. Contact SIRV to discuss a controlled pilot using your own requirements and sample documents.

"SIRV helped us move beyond basic reporting into a system that actively supports decision-making". Les O'Gorman, Director of Facilities, UCB - Pharma and Life Sciences

css.php