Complete a terrorism risk assessment

Record threat areas, assess against the ProtectUK categories, capture mitigations and set the review date that keeps it alive.

Applies toMain platformWeb
Needscompliance.manage

The risk assessment is where the compliance record stops being administrative and starts being about your actual building. It is also the document most likely to be read closely by someone external.

Before you start

Have these ready.

  • The compliance.manage permission.
  • Someone competent to assess — this is a judgement exercise, not a form-filling one.
  • Floorplans, so threat areas can be recorded against real geometry.
  1. 01

    Open the risk assessment

    The terrorism risk assessment records who assessed, when, the assessment categories from ProtectUK guidance, and a threat level overview.

    Field or controlWhat it does
    Assessed ByThe competent person who carried out the assessment.
    Assessment DateWhen it was carried out.
    Next Review Date (Annual)When it must be revisited. Set it, and diarise it outside the system too.
    MassComs terrorism risk assessment screen showing assessment categories, threat areas and mitigation status.
    Terrorism risk assessmentMassComs terrorism risk assessment screen showing assessment categories, threat areas and mitigation status.
  2. 02

    Work through the assessment categories

    The categories follow ProtectUK guidance. Assess each honestly — an assessment that finds nothing is not a good assessment, it is an unfinished one.

  3. 03

    Record site-specific threat areas

    Threat areas are the parts of your premises with specific vulnerability. They can be recorded with a threat level and, importantly, against a floor plan image so the location is unambiguous.

    Recording a threat area against the plan is far more useful than describing it in prose. It also connects the assessment to the same geometry your evacuation routes use.

    Threat area detail is sensitive. Control who can see the assessment and be careful about what ends up in widely shared exports.

  4. 04

    Record mitigation measures

    For each threat area, record the protection measure category under the Act, the mitigation measures themselves, and how they reduce vulnerability or risk of harm.

    Field or controlWhat it does
    Protection Measure Category (Act s.6)The category of measure under the legislation.
    Mitigation MeasuresThe specific measures, one per line.
    Mitigation StatusImplemented or Planned. Be honest — planned is a legitimate state.
  5. 05

    Set threat levels realistically

    Threat levels run from low to critical. A document where everything is critical conveys no information and a document where nothing is conveys no assessment.

  6. 06

    Diarise the review

    Set the Next Review Date and treat it as a commitment. An assessment past its review date is a visible failure.

    Confirm it worked

    Every threat area has a mitigation, a status and a review date, and the overall assessment has a next review date in the future.

Troubleshooting

When it does not go to plan.

SymptomUsual causeFix
No threat areas recorded.The assessment was started and not completed.An assessment with no threat areas is not an assessment. Complete it with someone competent.
Mitigations are all Planned.Nothing has been implemented yet.That is a legitimate starting state. Give each planned measure an owner and a date so the next review shows movement.

Good to know

Small details that prevent big confusion.

  • This document is where an external reviewer will look first for evidence of genuine thought.
  • Recording threat areas against floorplans connects the assessment to your operational geometry.
  • An honest assessment showing open risks with owners is stronger than a tidy one showing none.

Was this guide clear?

Help us make the next version better.