Summary

  • The attack occurred at an organisational seam that the public experienced as one place. At 22:31 on 22 May 2017, a suicide bomber detonated an improvised explosive device in the City Room as concertgoers were leaving Manchester Arena and relatives were waiting to collect them. Twenty-two people were killed and many more were injured. The City Room was publicly accessible, part of the Victoria Exchange Complex, connected to the Arena and Manchester Victoria station, but not inside the Arena itself. The official Volume 1 publication record identifies a statutory inquiry into the deaths.

    Its findings show why a boundary on a plan cannot be allowed to become a boundary in attention.

  • Volume 1 found a linked control failure, not one absent guard. The Arena operator, its crowd-management and security contractor, and British Transport Police held different control rights. Risk assessments did not rigorously translate the severe national threat level into event-specific action. Patrols, CCTV coverage, the security perimeter, contractor supervision and police deployment did not form a reliable system. A member of the public raised concern about the attacker shortly before detonation, but the concern did not reach someone able to investigate and change crowd movement in time.

    The inquiry concluded that an effective intervention was highly likely to have reduced death and injury, while acknowledging that the attacker might still have detonated the device.

  • Volume 2 found that bravery coexisted with serious command and interoperability failures. Police officers, venue workers, members of the public, medical personnel and others entered a dangerous scene and saved lives. The institutional response nevertheless performed far below the required standard.

    A police declaration of Operation Plato was not communicated to the ambulance or fire and rescue services; a shared forward command structure was not established promptly; the fire and rescue service did not reach the scene during the period when it could have offered the greatest help; and too few paramedics entered the City Room during the critical phase. The official Volume 2 publication gateway records the two-part report and its emergency-response mandate.

  • The fatal-causation boundary is person-specific. The inquiry did not attribute all 22 deaths to responder failures. It concluded that John Atkinson would probably have survived had the emergency response been better, found a remote possibility that Saffie-Rose Roussos could have been saved under a different rescue operation, and concluded that there was no possibility that the other 20 could have survived the bomber's actions. Those distinct findings must not be collapsed into either “the response caused all deaths” or “the response made no fatal difference.”

  • Volume 3 identified a realistic possibility, not probable or certain prevention. The inquiry found a significant intelligence-handling missed opportunity. Its exact public conclusion was that there was a realistic possibility of obtaining actionable intelligence that might have led to actions preventing the attack. It expressly said that it could not decide on the balance of probabilities, or another evidential standard, that the attack would have been prevented. The Volume 3 publication record also matters because the public report is only the open part of a record that relied substantially on closed evidence.

  • The inquiry is an accountability record, not a criminal trial. It made forceful findings about systems, organisations and individuals, but a statutory inquiry does not determine civil or criminal liability, punish a person or award compensation. That does not weaken its safety findings. It defines their proper use: identify control failures, preserve uncertainty, assign repair ownership and leave legal liability to competent courts or other proceedings.

  • Reform requires more than law, guidance and status labels. The Terrorism (Protection of Premises) Act 2025 places new responsibilities on qualifying premises and events, with enhanced requirements for larger settings and a regulatory role for the Security Industry Authority. As of 17 July 2026, public material showed guidance and implementation work continuing ahead of substantive commencement.

    The accountability standard is therefore a proof chain: named duty holders, mapped shared spaces, trained escalation, working communications, exercised joint command, timed casualty access, family-information controls, recommendation evidence and independent tests of whether the system performs under pressure.

The attack occurred in a public seam, not a simple doorway

The City Room connected several functions. It was an access and egress route for the Arena, a route toward Manchester Victoria station and tram services, a waiting area for people collecting concertgoers, and part of a larger complex whose ownership and operational responsibilities did not align neatly with what a visitor saw. The inquiry's security experts used the term “grey space” for a publicly accessible area outside an event site where ownership or security responsibility is unclear or divided. The term is useful only if it leads to an ownership map. Used as a description without one, it risks normalising ambiguity.

For the public, the relevant system began before the ticket check and extended beyond the Arena doors. A person leaving the concert did not experience an operator's lease, a contractor's statement of work, a railway policing jurisdiction and a local police advisory function as separate safety environments. The crowd moved through one connected place. Protective accountability therefore had to follow foreseeable movement and concentration, not only the formal edge of the licensed venue.

The full Volume 1 report describes the Arena operator as SMG, the retained crowd-management and event-security contractor as Showsec, British Transport Police as the police service for the Victoria Exchange Complex, and Greater Manchester Police as the provider of counter-terrorism security advice to the operator. Those roles were not identical. That made written interfaces more important, not less.

A defensible boundary system would have answered five questions before doors opened. Who owned the terrorism risk assessment for the event and its approaches? Who physically inspected every public route and concealment area? Who confirmed police presence at the period of peak egress? Who received and investigated a suspicious-behaviour report? Who had authority to stop or redirect the crowd? A contract could allocate some of those tasks. A joint operating record still needed to show that no task was assumed by everyone and owned by no one.

This is the first wider lesson. Public venues are often systems of landlords, tenants, operators, promoters, guarding contractors, transport bodies, police forces, local authorities, medical contractors and suppliers. Each may be competent within its own boundary while the interface remains unsafe. The unit of risk assessment should therefore be the public journey through the site, including queues, exits, transport connections, pick-up areas and the immediate vicinity. The unit of accountability should be the control right: who could see, decide, communicate, deploy, stop and verify.

The inquiry separated three questions that should not be merged

The three report volumes answer connected but different questions. Volume 1 examined security arrangements before detonation: venue risk, hostile reconnaissance, perimeter, CCTV, patrols, suspicious behaviour, contractor practice and policing. Volume 2 examined preparation and response after detonation: emergency calls, declaration, command, joint working, zoning, responder access, treatment, evacuation, hospitals, care and the circumstances of each death. Volume 3 examined radicalisation, preparation and whether intelligence or policing action might have prevented the attack.

These questions use different counterfactuals. A venue-security counterfactual asks what likely would have happened if the attacker had been identified and the exiting audience redirected. An emergency-response counterfactual asks whether earlier treatment or evacuation would have changed a particular person's outcome. An intelligence counterfactual asks whether a missed investigative action might have produced information that could have enabled disruption. The strength of one conclusion cannot be transferred to another.

Volume 1 used strong language about likely harm reduction after a timely venue intervention. Volume 2 reached a probability conclusion for one person and a remote-possibility conclusion for another. Volume 3 refused to say on the balance of probabilities that the attack would have been prevented. Saying simply that “the attack was preventable” erases those evidential differences. Saying that prevention was unknowable and therefore no institution can be held accountable erases the inquiry's identified missed opportunities. Accurate accountability preserves both the failure and the uncertainty.

There is also a difference between causal responsibility for the deliberate attack and public-safety accountability for institutional controls. The bomber caused the explosion and intended mass harm. The inquiry kept that responsibility central while examining whether organisations should have detected the threat, reduced exposure or improved rescue. Institutional scrutiny does not transfer authorship of the attack. It tests duties that exist precisely because malicious actors create risks the public cannot manage alone.

Volume 1 found multiple missed opportunities, not a guarantee of perfect prevention

The attacker's presence in the City Room was not visible to every worker throughout the evening, and the inquiry did not criticise every person who passed him or failed to identify him on appearance alone. That restraint matters. Suspicion cannot be reconstructed solely with hindsight, and security staff cannot be expected to treat every unfamiliar person as a threat. The failure arose when several stronger indicators and control opportunities accumulated without producing an effective response.

The attacker had conducted reconnaissance, spent extended periods in a CCTV blind area on the mezzanine and returned as the concert approached egress. A Showsec pre-egress check did not adequately inspect the mezzanine from a counter-terrorism perspective. British Transport Police officers who were meant to be present around the end of the event were absent from the City Room. Shortly before the explosion, a member of the public expressed concern about the attacker and his backpack to a steward. The concern passed between junior staff but did not reach a supervisor, police officer or control room able to investigate decisively.

The inquiry treated these as linked opportunities. If a competent police officer had received the report, that officer likely would have approached the attacker. If venue control had received a timely credible warning, it could have kept the Arena doors closed and diverted the exiting audience to other routes. Nobody can know how the attacker would have responded. Volume 1 considered it likely that he would still have detonated the device, but highly likely that fewer people would have been killed or injured because exposure would have been reduced.

That is a bounded prevention finding. It does not promise that a patrol, camera or report would have led to arrest. It identifies a more modest and still vital safety objective: detect a developing concern early enough to create options, then use those options to separate a threat from a concentrated crowd. Protective systems should be designed to reduce harm even when complete interdiction is unavailable.

The finding also resists a familiar defence: that no single missed step can be shown to have prevented the final act. Layered safety exists because no single step is certain. Risk assessment should shape the perimeter; the perimeter should shape patrol; patrol should cover camera gaps; staff should know what to report; radio and supervisors should complete escalation; police presence should provide investigative capability; control should be able to alter crowd movement. Accountability attaches when the layers fail to connect, not only when one layer can be proved sufficient by itself.

Risk assessment did not reach the work

The national terrorism threat level was severe, meaning an attack was assessed as highly likely somewhere in the United Kingdom. That did not mean an attack at this particular concert was certain or that every person near the venue was suspect. It did mean that the local security system needed to translate a high national threat into concrete questions about the event, the audience, public approaches, exit timing and shared-space ownership.

Volume 1 found that the Arena operator's general risk assessment did not rigorously identify the steps required to reduce terrorism risk and did not operate as a meaningful planning tool for the concert. Its event-specific assessment omitted terrorism as a hazard and was described as having become a box-ticking exercise. Showsec's documents also did not amount to an adequate assessment of terrorism risk to eventgoers and other members of the public affected by its work, and there was no suitable concert-specific assessment. Communication and coordination between operator and contractor were inadequate.

A risk assessment can contain the words “bomb,” “terrorism” or “explosion” and still fail as a control. The test is whether it changes deployment and decisions. Did it identify the City Room as a crowded publicly accessible exit space? Did it require the mezzanine to be physically checked? Did it identify the CCTV blind area and allocate a compensating patrol? Did it specify the time at which police presence was essential? Did it assign radio holders and supervisor coverage? Did it define a threshold for holding the doors and diverting egress? If not, risk language remained separate from operations.

The problem was not that the organisations lacked every form of security activity. Search and access controls existed inside the event boundary; briefings mentioned vigilance; police and security organisations had worked together before; the operator had received counter-terrorism advice. The accountability failure was the conversion layer between general awareness and event-specific execution. Information existed in documents and professional relationships, but it did not reliably become a timed, observed and signed-off control set.

This distinction matters to smaller venues and service providers. A venue with fewer resources does not need a complex intelligence function. It does need a proportionate route from threat advice to the actual shift: which spaces matter, which behaviours or items require escalation, who has a radio, who makes the decision, how visitors are moved safely, and how completion is recorded. An elaborate template that no one uses is weaker than a concise control sheet that is briefed, rehearsed and verified.

Patrols, CCTV and perimeter were one defence system

The City Room's mezzanine included an area that was not adequately covered by CCTV. The attacker used that area for concealment. The gap was not simply a camera-specification issue. Key decision-makers did not share a reliable understanding of the blind area, there was no robust process to identify and compensate for blind spots, and patrol arrangements did not ensure effective observation during the period that mattered most.

A camera is not a control merely because it records. Someone must know its field of view, monitor it at the relevant time, distinguish a gap from ordinary coverage, direct a person to inspect the gap and preserve a record of what was found. A patrol is not a control merely because a worker walks through a space. The route, purpose, timing, attention standard, communication route and completion evidence all matter. A perimeter is not a control merely because searches occur somewhere. Its location must prevent the unchecked public area from becoming the highest-concentration vulnerability.

Volume 1 considered that extending the security perimeter and conducting searches before entry into the City Room would have offered stronger assurance than relying only on cameras and patrols within it. That recommendation should not be turned into a universal prescription to create dense queues at every outer boundary. Moving a perimeter can displace risk. The design task is to avoid transferring a large unsearched crowd to another exposed place, while adding layers that improve detection and reduce the number of people concentrated near an unchecked approach.

The mature control is therefore a system model. Map crowd density by time. Map sight lines and camera coverage. Mark public and restricted routes. Define patrol waypoints that change with ingress and egress. Identify where a report can be made without delay. Give control staff authority to pause movement. Test alternative exits for accessibility and capacity. Inspect whether transport operations create new conflicts. Review the system after layout, tenant, construction, timetable or threat changes.

The evidence also warns against assigning technology a role it cannot perform. Better CCTV may reduce uncertainty, but it does not replace trained observation or escalation. Radios may accelerate communication, but a busy channel without priority rules can defeat a junior worker's attempt to report. Screening equipment can support a perimeter, but it does not decide where that perimeter should sit or what happens when a credible concern arises outside it. Each device needs an owner, an operating condition, a failure response and a test.

A public warning was only as strong as its escalation path

One of the most consequential facts in Volume 1 is that a member of the public did what public campaigns often ask: he noticed something that concerned him and told security staff. The warning did not become an effective investigation. The inquiry found the initial response dismissive and later efforts by staff inadequate. One steward lacked a radio; another tried unsuccessfully to communicate but did not persist or use a nearby supervisor. The report identified responsibility at both individual and contractor level.

This is not a reason to build a culture of accusation or profiling. The inquiry rejected criticism of people who did not identify the attacker merely from his appearance at earlier points. Effective suspicious-behaviour reporting is behaviour- and context-based, supported by training and handled respectfully. The control failure was not the absence of certainty. It was the absence of a reliable route for uncertainty to reach someone who could check it.

An escalation design should assume that the first recipient is junior, busy and unsure. It should provide more than one route: a priority radio phrase, a supervisor contact, a control-room channel and direct access to police where appropriate. It should require acknowledgement, location, reporter contact, time, action owner and closure. If the primary channel is occupied, the procedure must specify the alternate. If the report is assessed as benign, the outcome should be recorded without punishing the worker or member of the public for raising it in good faith.

Training should therefore test the social pressure as well as the words. A staff member may fear embarrassing a visitor, disrupting an event, being accused of discrimination or being criticised for a false alarm. Supervisors must explicitly authorise proportionate checking and make clear that good-faith escalation is expected. Exercises should include ambiguous cues, channel congestion and a decision about crowd movement. Completion is demonstrated when the report reaches an accountable decision-maker within the required time, not when staff pass an e-learning module.

Policing responsibility could not be inferred from proximity

British Transport Police provided policing for the Victoria Exchange Complex, including the City Room. Greater Manchester Police supplied counter-terrorism security advice to the Arena operator and later became central to the emergency response. The venue operator and contractor needed to know what police deployment would be provided for each event. Police, in turn, needed a written assessment and deployment plan that reflected the terrorism threat and the importance of egress.

Volume 1 found that BTP's approach did not adequately keep terrorism risk at the forefront of deployed officers' minds. Officers who should have been in the relevant area were elsewhere around the end of the concert. The report linked this not only to individual conduct but to organisational planning, briefing, supervision and culture. It recommended an experienced officer at events in addition to inexperienced personnel and treated patrolling egress areas before the end of a concert as mandatory because of the security risk.

The accountability principle is broader than this specific deployment. Advice is not operational ownership. A police counter-terrorism adviser can identify risks without assuming the operator's duty to implement controls. A transport police force can hold territorial responsibility without the venue contractor being relieved of observation and reporting. A venue can purchase security services without outsourcing its obligation to define the task, inspect performance and coordinate neighbours. Each organisation needs to record both what it owns and what it relies on others to provide.

Reliance should be confirmed, not assumed. Before an event, a joint record should state police numbers or response posture where disclosure is appropriate, security posts, public-space patrol, control-room contacts, escalation routes, decision authority and fallback arrangements. Sensitive operational detail need not be published. It must be available to the people who need it and tested against absence, radio failure, a changed transport pattern and simultaneous demands.

The first hour became a shared-picture failure

After detonation, the problem changed immediately. The relevant question was no longer only whether the attacker could be intercepted. Responders had to establish what had happened, whether any continuing threat existed, where the hazardous and usable areas were, which service was leading, how casualties would be reached, where ambulances would load, how hospitals would be warned and how families would receive reliable information.

The Volume 2-I report records extraordinary individual courage and important successes. BTP officers at the complex moved into the City Room; many GMP officers mobilised; members of the public and venue staff helped injured people; medical workers treated casualties; hospitals prepared and received patients. The report was explicit that lives were saved. Any account focused only on failure would misstate the evidence and diminish those actions.

Institutionally, however, the emergency services did not create a common operating picture quickly enough. Initial reports varied. Police assessed the possibility of a wider armed attack and declared Operation Plato, the response framework then used for a marauding terrorist firearms attack. That decision had consequences for zoning and which personnel believed they could enter. Yet the declaration was not communicated promptly—or at all by the declaring officer—to the ambulance and fire and rescue services.

Other information suggested that the City Room was safe enough for non-specialist responders, but it did not become a shared and continually reviewed assessment across commands.

The Joint Emergency Services Interoperability Principles required co-location, communication, coordination, shared understanding of risk and shared situational awareness. Those principles existed before the attack. The failure was not lack of doctrine alone; it was that doctrine, plans, training and exercising had not produced reliable behaviour under stress. No early joint forward command post brought commanders together. Control rooms and commanders acted on different fragments. Rendezvous points diverged. Resources accumulated in places that did not match the casualty need.

This is a continuity failure in the strict sense. Each service continued functioning, but the combined public service did not operate as one response system soon enough. Institutional continuity is not measured only by whether individual agencies remain online. It is measured by whether authority, information and resources cross agency boundaries at the speed the incident requires.

A declaration matters only when it travels

North West Ambulance Service declared a major incident early. Greater Manchester Police did not formally declare one until 00:57, although its officers and control structure were plainly responding to a mass-casualty terrorist event. At 22:47, a GMP force duty officer declared Operation Plato. He did not promptly notify the ambulance or fire and rescue services, despite plans and his own aide-memoire requiring that communication. The inquiry described the failure as significant and consequential.

The lesson is not about choosing the perfect label in the first uncertain minutes. Commanders need latitude to respond to incomplete information. The lesson is that a declaration creates obligations: timestamp it, state who made it, communicate it on every required channel, obtain acknowledgements, explain what it changes, review it as facts develop and record when it is lifted or modified. A declaration held inside one control room is not a joint control.

Communication also has to carry meaning. Telling another service that a specialist operation has been declared without sharing the current threat assessment, access route, command location and permitted actions may create caution without coordination. Conversely, sharing that casualties need help without explaining an unresolved threat may expose responders. The joint message must connect threat, location, scale, access, casualties, resources and command—the functions that a structured METHANE message was intended to support.

A resilient system assumes that primary communication will sometimes fail. It uses interoperable talk groups, recorded control-room links, liaison officers, direct commander contacts and a common log. It also sets a time limit: if acknowledgement is not received, escalation moves automatically to another route. Audit should reconstruct what each service knew at each minute without depending on personal recollection months later.

Casualty access and care were command outcomes

Only three paramedics operated in the City Room during the critical period, two of them arriving relatively late in that period. More trained personnel and stretchers were available elsewhere, but command, zoning, rendezvous and communication decisions delayed their effective use. Greater Manchester Fire and Rescue Service resources were directed first to a station away from the Arena and did not arrive at the Victoria Exchange Complex during the phase when their rescue capability could have made the greatest contribution. Casualties were moved on improvised carriers while ambulance stretchers were not brought forward in sufficient number.

These facts should not be used to blame responders who entered, improvised or worked under intense danger. Volume 2 distinguished individual bravery from organisational preparation and command. The point of accountability is to avoid making future rescuers compensate with courage for failures that should have been solved in plans, exercises, equipment positioning and joint decisions.

Casualty access is often described as a medical issue, but it begins with shared risk assessment and command. Who can enter? Along which route? With what protective equipment? Is the area hot, warm or cold, and who can revise that classification? Where is the casualty clearing station? Which exits can carry stretchers? Where are ambulance loading points? Who prioritises scarce clinical capability? A delay at any of those decision points appears downstream as delayed care.

Venue medical provision also matters before public services arrive. The Arena's contracted healthcare provision was not sufficiently prepared, trained or equipped for the scale and nature of the incident. Volume 2 used the concept of a “Care Gap” for the period between injury and effective professional emergency care. Closing that gap requires proportionate trauma capability among event medical staff and selected first responders, accessible equipment, public first-aid education and a plan that integrates on-site providers with the ambulance service.

Family information is another operational control, not an afterthought. A mass-casualty event produces urgent calls, unverified lists, separated groups and pressure for public statements. The command system needs a single casualty-information process, identity verification, hospital reconciliation, family-liaison ownership and rules that prevent families learning sensitive information through rumor or media. Speed matters, but accuracy and humane delivery matter equally. Exercises should test the information flow from scene to hospitals to family support, not only radio traffic among emergency services.

Fatal causation must remain person-specific

The Volume 2-II report examined each of the 22 deaths using pathology, survivability expertise, footage, witness evidence and response chronology. It did not apply one generic conclusion. That specificity is central to both accuracy and dignity.

For John Atkinson, the inquiry found that timely effective treatment to control bleeding within the identified window, or prompt evacuation and hospital arrival before cardiac arrest, probably would have saved his life. It assigned relevant failures to the on-site medical provider and its management, the Arena operator that should have ensured provider competence, the ambulance service's limited public evidence forward deployment, and the absence of firefighters who should have been available for evacuation.

The report did not criticise police officers for failing to provide that treatment under the standards and training then applicable, while recommending improved capability for the future.

For Saffie-Rose Roussos, experts disagreed about whether survival was possible even with the best treatment. The chair concluded that there was a remote possibility she could have been saved if the rescue operation had been different. For the other 20 people, the evidence established that no different emergency response could have enabled survival. The bomber's actions caused their deaths.

Those distinctions prevent two serious errors. The first is to attribute all 22 deaths to institutional response failures, which overstates the inquiry and displaces responsibility from the attacker. The second is to say that response failures were irrelevant because most injuries were unsurvivable. One probable lost life and one remote possibility are not statistical footnotes. They are person-specific findings that define why access, trauma care and evacuation controls require repair.

The same discipline applies to injuries and trauma. Hundreds of people experienced physical or psychological harm, but the public report does not support a single causal allocation for every injury or later outcome. A responsible accountability record states what the inquiry found, recognises the human impact and avoids inventing medical or legal conclusions for individuals whose evidence is not analysed in the cited passage.

Intelligence accountability stops at a realistic possibility

Volume 3 examined whether the Security Service and Counter Terrorism Policing could and should have prevented the attack. It considered the attacker's prior status in the counter-terrorism system, intelligence received before the attack, travel-related information, review processes and information sharing. Much of the decisive evidence was heard in closed session for national-security reasons.

The open Volume 3 report found a significant missed opportunity connected to the handling of intelligence. A Security Service officer did not report one piece of intelligence as promptly as the chair considered necessary. That delay removed an opportunity to take a potentially important investigative action. The chair found that the action was proportionate and should have occurred and that it presented a real possibility of obtaining actionable intelligence.

The counterfactual then branches. Additional intelligence might have caused the attacker's return to the United Kingdom to be treated more seriously. That could have led to surveillance, a port stop or other investigative action. Any of those might have disrupted the plot, produced nothing useful or affected behaviour without preventing the attack. The report expressly declined to decide on the balance of probabilities what would have happened.

The governing phrase is therefore narrow and exact: there was a realistic possibility that actionable intelligence could have been obtained which might have led to actions preventing the attack. “Realistic possibility” is not “probable,” “more likely than not,” “would have,” or “certain.” “Might have led” contains another contingency between information and prevention. Both must remain visible.

The MI5 Director General's response accepted the chair's realistic-possibility formulation, apologised that MI5 had not prevented the attack and said more than 100 improvements had been made since 2017. The apology and reform statement are significant institutional responses. They do not enlarge the inquiry's counterfactual conclusion, disclose the closed evidence or independently prove that every improvement is effective.

This boundary is not a concession to secrecy or institutional convenience. It is how intelligence accountability remains credible. Analysts work with fragmentary information, large caseloads and uncertain meaning. Some judgments will reasonably differ. Accountability should identify where policy, context, timeliness, review or escalation failed, then test the repaired process. It should not pretend that every missed lead was an obvious warning or that acting on one item guarantees prevention.

Closed material limits public replication

Volume 3 is explicitly divided into open and closed components. The closed material contains information whose publication was assessed as damaging to national security. Most evidence supporting the preventability analysis was heard in a closed hearing, and the open report provides a gist of conclusions that could safely be disclosed. Bereaved families and the public therefore cannot inspect the complete intelligence record on which the chair relied.

That creates a legitimate accountability tension. National security may require protection of sources, capabilities, investigative methods and identities. Democratic legitimacy benefits from public evidence that findings are well founded, criticisms are answered and reforms match the failure. The inquiry addressed that tension through restriction orders, closed hearings and public gisting. This article cannot resolve what the public source does not reveal and does not claim access to Volume 3 closed, private intelligence logs or restricted testimony.

The correct boundary is neither to dismiss the public finding because some evidence is closed nor to imply that the open report contains the entire record. The chair saw material unavailable to the public and reached a bounded conclusion. Public analysis can test the logic and language of that conclusion, compare institutional responses and monitor reforms. It cannot independently reconstruct every intelligence decision from the open record.

Closed evidence also changes what “proof of repair” can look like. Publishing sensitive operational detail may itself create risk. Oversight can instead use cleared independent reviewers, audit samples, timeliness metrics, quality-assurance results, escalation testing and public summaries that reveal enough about performance without exposing methods. The public claim should identify who verified the improvement, what period was tested, what standard applied and which limitations remain.

Accountability follows control rights

Responsibility becomes clearer when it is assigned to decisions, interfaces and evidence rather than to one undifferentiated label.

Control domain Primary owner at the relevant stage Evidence the owner needed to produce Accountability issue in the public record
Intelligence assessment Security Service and Counter Terrorism Policing within their statutory and operational roles Timely reports, contextual assessment, lead decisions, review, information-sharing records and quality assurance A report was not made promptly enough, creating a significant missed opportunity; separate information-sharing problems were identified but were not likely causative
Shared-space security Arena operator, property and transport stakeholders, police and contractors within defined scopes One map of public approaches, crowd flows, ownership, threat controls and escalation authority The City Room was a grey space in which formal boundaries did not produce a complete shared security system
Event risk assessment Arena operator and security contractor, coordinated with police advice and deployment Event-specific terrorism risk, controls, owners, timing, residual risk and sign-off Assessments were inadequate, not operationally influential and insufficiently coordinated
CCTV and patrol Arena operator and contractor, with police patrol responsibilities separately confirmed Coverage map, blind-spot register, monitored periods, patrol route, completion log and exception response A significant blind area and inadequate pre-egress patrol reduced the chance of detecting the attacker
Suspicious-behaviour escalation Contractor management, supervisors, control room and police recipients Behaviour-based training, multiple reporting routes, acknowledgement, action owner and closure A public warning and staff observations did not reach effective investigation or crowd-control authority
Policing presence British Transport Police for the complex, coordinated with the operator and other police functions Written deployment plan, experienced supervision, egress patrol and fallback Officers were not in the City Room when a report could have been made to them; organisational planning and vigilance were inadequate
Emergency declaration Each service commander, with GMP owning its Operation Plato communication Timestamped declaration, reason, effects, recipient acknowledgements and review Operation Plato was declared but not communicated to ambulance or fire partners by the declaring officer; GMP's major-incident declaration was late
Joint command Police, fire and ambulance commanders through JESIP Co-located command, shared risk assessment, common operating picture, METHANE updates and decision log No prompt shared forward command post or sufficiently integrated picture emerged
Casualty access and care On-site medical provider and venue before public-service arrival; NWAS, GMFRS and police within response roles Trauma competence, equipment, access route, zoning decision, forward clinical resource, stretchers and evacuation priorities Too few paramedics worked in the City Room, firefighters arrived too late for their greatest contribution and evacuation resources were not used effectively
Family information Police, health services, hospitals and local resilience arrangements within assigned roles Verified casualty data, reconciliation, family liaison, protected communications and correction process The enduring control requirement is a single accurate and humane information chain across scene, hospitals and family support
Recommendation closure Named government departments, emergency services, regulators and other addressees Accepted outcome, implemented control, training, exercise results, audit, performance trend and residual risk Publication and status reporting exist, but a label alone does not prove operational effectiveness

This table does not turn every organisational criticism into personal fault. People worked within contracts, training, supervision and information environments of different quality. The inquiry made some individual criticisms, but the durable repair sits mainly with organisations that controlled requirements, staffing, plans, data, equipment, escalation and assurance.

It also avoids making the Arena operator responsible for intelligence decisions it could not see or making the intelligence agencies responsible for emergency commands they did not control. End-to-end accountability can be comprehensive without being indiscriminate. Each owner should be judged on the evidence and decision rights within its reach, plus the interfaces it was required to maintain.

A verifiable venue-security repair needs ten linked controls

The first control is a shared-space responsibility map. It should cover the licensed venue, publicly accessible approaches, transport interchanges, car parks, queue areas, commercial neighbours, pick-up points and emergency routes. For every zone, it should identify the property controller, operating controller, guarding provider, police jurisdiction, camera owner, patrol owner, medical cover and decision authority. Changes in tenant, construction, transport pattern or event design should trigger review.

The second is an event-specific protective-security assessment. It should begin with current threat advice but avoid pretending that a national threat level predicts a particular venue. It should consider audience and event characteristics, crowd concentrations, arrival and egress timing, hostile reconnaissance indicators, unattended or concealed areas, screening placement, vehicle and pedestrian interfaces, accessible routes, staffing and emergency consequences. The assessment should produce controls with named owners and deadlines, not only a score.

The third is layered observation. Camera coverage should be mapped from the operator's actual monitoring position, not only from installation drawings. Blind spots should be logged and covered by patrol or engineering change. Patrols should have time windows, routes and explicit attention tasks. Completion should be recorded without turning security staff into passive form-fillers. Supervisors should sample performance during live operations.

The fourth is a protected escalation pathway. Every public-facing worker should know how to report suspicious behaviour or an item, and every report should reach a person able to investigate. Radios need priority conventions and backup channels. Reports need acknowledgement and closure. Training must be behaviour-based and avoid discriminatory shortcuts. Good-faith reporting should be reinforced even when investigation finds an innocent explanation.

The fifth is explicit police integration. Operators should not assume deployment from prior events or general relationships. A pre-event record should confirm policing or response arrangements, key contacts, the period of greatest need, authority for crowd intervention and fallback if planned personnel are diverted. Sensitive information can be controlled while still giving operational staff what they need.

The sixth is a joint emergency command design. Plans should identify who declares a major incident, who can declare specialist counter-terrorism operations, what each declaration changes, which services must acknowledge it and where commanders co-locate. A shared log should record the threat assessment, zoning, access, casualty picture, rendezvous points, loading points and command transfers. Plans must work during communications degradation, not only on paper.

The seventh is an access-and-care plan built around time. The venue and its medical provider should define immediate trauma capability, equipment and integration with public ambulance services. Responders should know usable routes into and out of high-consequence spaces. Fire and rescue capability should be matched to casualty movement and scene risks. Ambulance stretchers, casualty clearing and hospital distribution should be treated as one flow rather than separate service tasks.

The eighth is an exercise programme that tests decisions and interfaces. Tabletop discussion is useful for learning roles; live and command-post exercises test whether roles work. Scenarios should include uncertain threat information, a blocked radio channel, an absent commander, conflicting rendezvous points, a need to redirect a crowd, simultaneous incidents, casualty access and family inquiries. Exercise reports should assign corrective actions and retest failures, not merely record participation.

The ninth is a humane information and recovery system. Family liaison, casualty reconciliation, survivor support, psychosocial care, evidence preservation and public updates should begin alongside response. Records should distinguish confirmed, provisional and corrected information. People affected by the incident should have a route to updates on recommendations and reforms, without being required to relive the event to obtain basic institutional answers.

The tenth is independent assurance. Operators and public agencies should retain evidence of risk review, training, patrol, equipment checks, message delivery, exercise performance and recommendation closure. Auditors should sample the system across multiple events and shifts. The strongest metric is not the number of documents completed but whether an ambiguous warning reaches a decision-maker, whether joint command forms within the target time, whether casualty routes are usable and whether a failed test is corrected and passed later.

Emergency interoperability has to be tested as a capability

JESIP doctrine existed before the attack. The inquiry found that its principles had not been sufficiently ingrained in practice. This is a common institutional pattern: a framework is sound, training attendance is recorded and exercises occur, yet behavior under pressure does not follow the framework. The assurance question is not “Do you have JESIP?” but “Can commanders and control rooms demonstrate shared situational awareness when information is incomplete and stakes are high?”

The government's Spring Resolve exercise report described a national counter-terrorism exercise in March 2023 that tested multi-agency command, communication and consequence management, with objectives linked to Volume 2. That is credible evidence of activity and learning attention. An exercise announcement does not disclose every objective result, deficiency, corrective action or retest. It should therefore be treated as a step in assurance, not proof that interoperability was fixed nationwide.

Similarly, the UK Government Resilience Framework implementation update recorded the formal closure of the inquiry in August 2023, a Home Office assurance programme and continuing resilience work. Programme creation establishes ownership and a route for monitoring. The next layer of evidence is whether local and national exercises repeatedly show faster co-location, declaration propagation, shared risk assessment, resource deployment and accurate information transfer.

Metrics should be designed carefully. A short time to declare is useful only if the declaration is appropriate and reaches partners. A short time to establish a forward command post matters only if the right commanders attend and share decisions. More radio messages may reflect confusion rather than coordination. Useful measures combine time, completion and quality: recipient acknowledgement, common threat picture, agreed access route, documented review, resource arrival and closed corrective actions.

Public-sector continuity also requires capacity to train without weakening everyday service. Releasing ambulance, fire and police personnel for joint exercises has operational cost. That is a real constraint, not a reason to leave the capability untested. Funding, backfill, national standards and risk-based exercise frequency should be part of implementation evidence. Otherwise, the services most stretched in routine operations may also be least able to rehearse rare high-consequence events.

Martyn's Law changes the duty structure but does not complete the repair

Volume 1 recommended a statutory Protect Duty. Parliament enacted the Terrorism (Protection of Premises) Act 2025, commonly known as Martyn's Law, on 3 April 2025. The Act creates requirements for persons responsible for qualifying premises and events to take steps to reduce physical harm from terrorism and, for larger qualifying premises and qualifying events, to reduce vulnerability. It gives the Security Industry Authority regulatory, investigative and enforcement functions.

The Home Office overarching factsheet explains the tiered approach. Subject to the Act's other conditions, premises where 200 or more people may reasonably be expected can fall within standard duty; those at 800 or more can fall within enhanced duty; qualifying events use the higher threshold. Standard-duty requirements focus on reasonably practicable public-protection procedures. Enhanced settings and qualifying events must also consider reasonably practicable protection measures.

The reform addresses several accountability gaps: it identifies a responsible person, makes preparedness a legal rather than purely voluntary expectation, requires cooperation in relevant shared-control situations, provides a regulator and creates enforcement tools. It also uses proportionality so that smaller organisations are not automatically expected to install costly physical systems. Procedures such as warning, evacuation, invacuation, lockdown and communication can be low-cost but still material.

As of 17 July 2026, enactment was not the same as substantive commencement. The 2026 statutory guidance states that section 27 had been commenced to permit guidance, while further details would be provided on commencement of the substantive requirements. The SIA reported in June 2026 that its guidance consultation had closed and that the law was expected to come into force from spring 2027. These are time-specific implementation facts, not promises about the eventual date.

Later legislation must not be projected backward as the exact legal duty in May 2017. Volume 1 analysed the law and guidance applicable at the time and recommended change. The 2025 Act is evidence of a later repair to the duty structure. It does not alter the historical standard, decide liability for past conduct or prove that present venues already comply with requirements not yet commenced.

Nor does law eliminate the interface problem automatically. A “responsible person” still needs cooperation from landlords, tenants, event organisers, contractors, transport bodies and public agencies. Inspectors need competence and capacity. Guidance needs to be understood by small organisations as well as major operators. Sensitive security information needs protection. Enforcement needs proportionate escalation. The proof will be in notification, advice, inspections, exercises, corrective action and measurable performance after commencement.

The government's 2024 impact assessment records the policy rationale, affected-premises estimates, expected costs and modeled benefits behind the Bill. Such analysis is useful for proportional design. Its estimates are assumptions for policy appraisal, not observed reductions in attacks or harm. Post-implementation evaluation must compare actual coverage, costs, compliance and outcomes with those assumptions.

Contractor regulation remains a separate repair question

Venue operators often rely on contracted guarding, crowd management, CCTV and medical services. Contracting can bring specialist capability, but it splits control across the purchaser, supplier, individual licence holder, supervisor, training provider and regulator. The purchaser remains responsible for defining the operational outcome and checking delivery. A worker's individual licence does not certify the contractor's command system, event-specific risk assessment or counter-terrorism competence.

Volume 1 made monitored recommendations concerning licensing of companies carrying out security work with a counter-terrorism element and licensing in-house CCTV operators. The Home Office's consultation on monitored recommendations 7 and 8 ran into March 2026 and set out regulatory and non-regulatory options. The existence of a consultation demonstrates policy work. It does not establish that a chosen control has been enacted, implemented or shown effective.

The right assurance unit is the service chain. Did the operator specify terrorism-related duties? Did the contractor assess the event and public approaches? Were staff trained for their actual posts? Were supervisors competent and present? Were radios and alternate routes available? Did control acknowledge reports? Did the operator audit live performance? Did commercial incentives discourage adequate staffing or escalation? Did the regulator inspect the organisation, not only the licence status of individuals?

For small and medium service providers, requirements should be clear and accessible. Complexity can create a market in expensive generic advice without improving safety. Regulators and government should publish outcome-based examples, proportionate templates and direct guidance while warning against anyone claiming that purchase of a product guarantees compliance. A small contractor should be able to show competence through observed drills, records and supervision without imitating the bureaucracy of a national operator.

Recommendation status is not the same as verified effectiveness

The inquiry issued recommendations across venue security, policing, private security regulation, emergency planning, JESIP, control rooms, ambulance and fire capability, trauma care, education, intelligence and inquiry powers. Different bodies own different outcomes. A single statement that “the recommendations were accepted” would conceal whether responsibility, funding, delivery and verification exist for each item.

In September 2023, the Security Minister described the Manchester Arena Inquiry Assurance Programme, intended to oversee continued delivery with emergency-service partners and provide engagement and updates to people affected by the attack. In November 2025 the government created an official Manchester Arena Inquiry recommendations page linking to a dashboard, updated again in June 2026. These steps improve visibility and create a public monitoring route.

The dashboard user guide explains response categories, delivery statuses, historical snapshots and data downloads. It distinguishes accepted in full or in part and in progress or completed. That is valuable governance infrastructure. A “completed” label remains a status assertion unless supported by evidence of the control operating as intended.

Closure evidence should match the recommendation. A training recommendation needs curriculum, target population, completion, competence assessment and refresher evidence. A communications recommendation needs coverage testing, interoperability results, failure handling and exercise records. A command recommendation needs timed formation and decision-quality evidence across exercises and real incidents. A statutory recommendation needs enacted text, commencement, guidance, regulator staffing, inspection and enforcement.

A contractor recommendation needs the final policy decision, legal or other mechanism, implementation and observed compliance.

Independent challenge should be proportionate to risk. Some actions can be verified through documentary review. Others need live observation or unannounced sampling. High-consequence interfaces deserve cross-agency exercises and external assessment. Where evidence is sensitive, a cleared reviewer can publish a bounded assurance statement. People affected by the attack should be able to see what was tested, by whom, when and with what remaining limitation.

Inquiry findings are not civil or criminal judgments

The Manchester Arena Inquiry was established under the Inquiries Act 2005. Cabinet Office national recovery guidance on inquiries explains the legal boundary in direct terms: public inquiries establish facts and support prevention, but do not determine civil or criminal liability, punish people or award compensation. Courts, criminal investigations, inquests, regulators and compensation systems perform different functions under their own law.

This distinction should be stated without weakening the report. The chair was entitled to make factual findings, criticise conduct and recommend reform. The reports identify organisational and individual failures in clear language. Those are authoritative inquiry findings within the terms of reference. They are not, by themselves, convictions, negligence judgments or determinations that a named person owes damages.

Evidence categories should remain distinct as well. A final report contains the chair's adopted findings. A witness statement records a person's evidence. A closing submission argues a entity's position. A policy response records what an organisation says it has done. An exercise announcement confirms activity. A dashboard status records reported delivery. A statute establishes legal requirements according to its commencement and scope. Treating every category as equivalent produces false certainty.

The non-adjudicative boundary is particularly important where the report discusses individuals acting under acute stress or intelligence officers making uncertain judgments. Strong safety criticism can coexist with unresolved legal liability. Conversely, absence of a criminal charge or civil judgment does not erase an inquiry's evidence of a failed control. Accountability journalism should state the institutional finding and its legal limit in the same passage.

What remains unresolved

The open record cannot show exactly what would have happened if the intelligence action identified in Volume 3 had occurred. The action might have generated useful information and enabled disruption; it might not. The inquiry found a realistic possibility and expressly refused a probability conclusion. No later apology or reform claim changes that evidential boundary.

The public record is not the complete intelligence record. Volume 3 closed and its closed recommendations have limited readership. The public cannot independently test every premise, and this article cannot describe material it has not seen. Future declassification or authorised disclosure could change the public evidence, but it would be improper to speculate about what the closed volumes contain.

The precise effect of each pre-attack security intervention also remains counterfactual. Volume 1 found likely harm reduction from a competent intervention, not certain prevention of detonation. Different crowd positions, the attacker's response and the timing of a door hold could have changed consequences. The repair should preserve options and reduce exposure rather than rely on one imagined alternate history.

For fatal outcomes, the inquiry's person-specific conclusions control. John Atkinson's probability conclusion, Saffie-Rose Roussos's remote possibility and the no-possibility conclusions for the other 20 must not be homogenised. The broader injury and trauma record also cannot be assigned to one institutional cause without individual evidence.

The long-term effectiveness of reform remains open. Exercises, assurance programmes, a dashboard, the 2025 Act, statutory guidance and SIA implementation work demonstrate substantial activity. As of the publication date, the Act's substantive duties had not yet been brought into force according to the cited guidance, and the public sources reviewed here did not establish years of inspection, enforcement and performance data under the new regime. Effectiveness will need to be measured after implementation.

Finally, no public system can promise that every terrorist plan will be discovered or every attack prevented. The legitimate standard is not zero uncertainty. It is disciplined use of available intelligence, proportionate protective security, reliable escalation, rapid shared command, effective casualty access, humane information and transparent learning. Institutions should be accountable for controls within their authority and honest about residual risk.

The accountability test

Manchester Arena exposed how safety can fail between competent-looking components. A national threat assessment did not become an adequate event control. A public concourse sat between venue and transport responsibilities. Risk documents did not drive patrol and perimeter choices. A warning did not reach decision authority. A police declaration did not reach partner services. Doctrine did not produce early co-location. Skilled responders and equipment did not all reach casualties when they could contribute most.

The inquiry also showed why accountability needs boundaries. The bomber's deliberate act remains the source of the attack. Individual responders showed courage and saved lives. Not every pre-attack sighting was reasonably suspicious. Not every death was survivable. The intelligence counterfactual did not cross the probability threshold. Closed evidence prevents complete public replication. The inquiry did not conduct a criminal trial or determine civil liability.

Those limits make the repair more credible, not less. They direct attention toward things institutions can prove. A venue can show who owns every shared space. A contractor can demonstrate that an ambiguous report reaches a supervisor. Police can confirm egress deployment and escalation. Three services can show that a declaration is acknowledged, commanders co-locate and access is agreed within target time. Medical providers can demonstrate trauma competence and equipment. Government can connect every recommendation to an owner, implementation record, independent test and residual risk.

The 2025 Act creates a stronger duty structure for qualifying premises and events. The coming test is operational. Does proportional guidance reach small organisations? Can the SIA advise and enforce consistently? Do shared-control sites cooperate? Are protective procedures rehearsed rather than filed? Do larger venues measure vulnerabilities without creating new crowd risks? Are exercises corrected and repeated? Do affected families receive evidence of progress rather than only assurances?

Public safety depends on institutions making uncertainty actionable. The person who notices something should know where to report. The worker who receives the report should have a route that cannot disappear into a busy channel. The commander who makes a declaration should know it reached every partner. The clinician and firefighter should know when and how to move forward. The family should receive verified information. The public should be able to see who tested the repaired system.

That is the Manchester Arena accountability standard: not a claim that harm can always be prevented, but an inspectable chain showing that shared spaces are owned, warnings are escalated, commands are joined, casualties are reached and reforms are demonstrated before the next emergency tests them for real.

Source notes

This article gives controlling weight to the three final Manchester Arena Inquiry volumes for the findings within their respective scopes. Government, MI5, exercise, dashboard, consultation, legislative and guidance sources are used for dated response and reform evidence, not to enlarge the inquiry's historical or counterfactual findings. Volume 3 open is not treated as the complete intelligence record. Later law and guidance are not projected backward as the exact legal standard on 22 May 2017. Access conditions, grades, uses and unresolved boundaries are recorded in the companion source ledger.