HVM Risk Assessment Basics
This guide sets out how a proper HVM risk assessment is actually built, and where street furniture fits into the answer.
What "HVM risk assessment" actually means
HVM risk assessment is a narrower and more specific discipline than general security risk assessment, and it's worth being precise about the difference. A general security review might cover theft, antisocial behaviour, public order and a dozen other concerns across a site. An HVM risk assessment has one job: to work out whether, where, and how badly a vehicle could be used as a weapon against a specific asset or crowd, and what level of protection that finding justifies. It's also not the same exercise as product specification, even though the two get conflated constantly in practice. Specifying a bollard range is the output of a risk assessment, not a substitute for one.
The sequence matters more than any individual step. You start by understanding the threat in general terms and the site in detailed ones, what's there, who uses it, when, and how. From that you assess vulnerability: could a vehicle actually reach this asset, and at what speed. Then consequence: what happens if it does. Only once those three are answered does mitigation enter the conversation.
The threat picture
Vehicles remain an attractive method for hostile actors for straightforward reasons: they require no specialist equipment, no special access, and they're capable of causing mass casualties in seconds against a crowd that has no time to react. Crowded public spaces and events are attractive targets purely on target-selection logic (high footfall, open access, and limited natural barriers between the public realm and a vehicle).
Risk assessors work with the concept of "achieved speed" — the realistic speed a vehicle could reach on the approach to a given point, because that figure is what actually drives the severity of a potential impact. This is deliberately the most clinical section of this guide; the methodology behind real-world attack planning isn't something we'll go into, and a credible risk assessment doesn't need it to be effective.




The standards and guidance landscape
This is the part of HVM that confuses almost everyone outside the specialist world, mostly because the terminology has shifted over time without the older terms disappearing from use.
The National Protective Security Authority (NPSA, the rebranded successor to CPNI) is the UK's national technical authority for protective security and the source of the underlying guidance: how to run a Vehicle Dynamics Assessment, how to define an Operational Requirement, and how the whole risk assessment process should be structured. Sitting underneath that guidance are the impact-testing standards that tell you whether a given barrier, bollard or planter will actually stop or slow a vehicle.
PAS 68 was the original British standard for this and remains the most widely recognised name in the UK market. IWA 14-1 was its international counterpart, used where a globally portable rating mattered. Since 2023, both have technically been superseded by ISO 22343-1, the new international standard, and as of March 2024 NPSA only recognises newly tested products against ISO 22343-1. Crucially, that doesn't make PAS 68 or IWA 14-1 obsolete in practice, as products tested under either standard before that cut-off remain valid and are still specified and installed every week, so anyone working in this space needs to be fluent in all three for some years yet.
Martyn's Law — formally the Terrorism (Protection of Premises) Act 2025 — sits above all of this as the legal layer rather than the technical one. It doesn't mandate specific HVM products. What it does is determine who now has a legal duty to go through a risk-informed process at all: venues and events with a capacity of 200 or more sit in its standard tier, those at 800 or more sit in the enhanced tier with materially heavier obligations, including a compliance document that has to set out how the measures in place reduce vulnerability and risk.
The Act received Royal Assent in April 2025, the Home Office published its statutory guidance in April 2026, and commencement is expected in spring 2027, so it isn't yet enforceable, but the direction of travel is no longer in any doubt.
Standard / guidance |
What it actually is |
Where it sits |
|
NPSA guidance |
National technical authority guidance on running the assessment process itself |
The foundation methodology, not a product test |
|
PAS 68 |
Original British impact-testing standard |
Legacy, but still widely specified and valid where pre-2024 tested |
|
IWA 14-1 |
International impact-testing standard, broadly equivalent to PAS 68 |
Legacy, same status as PAS 68 |
|
ISO 22343-1 |
Current international impact-testing standard, supersedes both above |
Now standard for any new testing |
|
Martyn's Law |
UK legislation creating a legal duty to assess and act |
The legal layer that determines who must engage, and when |
The risk assessment process, step by step
Site and asset characterisation comes first, and it's largely about description rather than judgement at this stage: what exactly is being protected, who passes through the space and when, and whether the context is a permanent installation or a temporary event. A Christmas market and a transport interchange generate very different pictures even if they sit on the same street.
Threat assessment follows, and this is deliberately not done in isolation. It draws on input from police Counter Terrorism Security Advisers and the resources published through NaCTSO and ProtectUK, because the threat picture for a given location is informed by intelligence and context that sits outside any one organisation's own knowledge.
Vulnerability assessment is where the technical work happens, including working out achievable approach speed along realistic routes, stand-off distance between any plausible vehicle approach and the asset, and the hostile vehicle access routes that actually exist once you look at the site rather than the site plan.
Consequence assessment asks the question everyone tends to skip past: if a vehicle did reach the target at the speed established above, what's the realistic harm. This is what turns a vulnerability finding into something that can be prioritised against other risks and against budget.
Risk rating and prioritisation brings the previous four stages together into something actionable, usually ranking multiple vulnerable points across a site rather than treating the whole space as a single uniform risk.
Vehicle dynamics
Three concepts do almost all of the work in this part of the process, and they're worth understanding properly rather than taking on trust.
Achieved speed is not a vehicle's top speed, it's the realistic speed obtainable over a specific approach, given the distance available, the road layout, gradient, bends and any obstacles in the way. A long, straight, unobstructed approach produces a very different figure to a tight, kerbed urban side street, even for the same vehicle.
Approach angle matters because impact-rated products are tested against specific angles, usually a head-on or near head-on hit. A barrier rated to stop a vehicle square-on can behave very differently against a glancing impact, which is why site geometry such as kerb lines, junctions, the curve of a road etc., directly affects which products are even relevant to a given location.
Stand-off and stopping distance tie the other two together. Once you know the achieved speed and the angle, you know roughly how much distance and force is needed to stop or sufficiently slow that vehicle before it reaches the asset. That figure is what determines which rated product is appropriate, rather than reaching for the highest-rated option available by default.




From risk rating to mitigation strategy
Once the risk has been rated, the decisions that follow are largely about matching the type of measure to the context rather than choosing the single "best" product on the market. Permanent sites generally call for permanent, fully rated infrastructure; events and temporary deployments often call for products designed and rated specifically for that use case, which is a different specification exercise entirely.
Active measures, including rising bollards and gates, work best for places that needs to open and close for legitimate traffic, suiting locations where controlled vehicle access is a must. Passive measures, including bollards, planters and rated street furniture, suit locations where the wider public realm still needs to function as a place people want to be. This is also where street furniture earns its place in a serious HVM scheme: a well-designed, properly rated planter or seating run can deliver the same protection as a more overtly defensive barrier without making a public space feel like one.
Common mistakes in HVM risk assessment
A few patterns come up again and again, and they're worth naming plainly. Over-specifying is common. Reaching for the highest available rating without a vulnerability finding that justifies it, usually comes at a real cost in budget and visual impact.
Ignoring pedestrian desire lines is another: people don't walk where a site plan assumes they will, and a scheme that doesn't account for how a space is used can leave the vulnerable point unprotected while hardening somewhere nobody goes.
Treating temporary events and permanent sites identically wastes money in one direction and under-protects in the other, since the appropriate standard differs between the two contexts. And perhaps the most overlooked failure is treating the assessment as a one-off document rather than something that gets revisited as a site's use, footfall or threat picture changes.
Who should carry out a HVM Risk Assessment?
A credible HVM risk assessment is never a single person's call. Police Counter Terrorism Security Advisers and NaCTSO bring the threat context, local authority planners and highways teams understand how a site actually functions and what's feasible within its constraints, and landscape architects and specifiers hold the design intent that determines how a scheme gets adopted gracefully. HVM manufacturers, like Townscape Products, bring the technical detail on what's achievable within a given rating, budget and footprint.
A worked example
One Bishopsgate Plaza in the City of London is a useful real illustration of how this plays out once the theory meets an actual site. The development sits above a Pan Pacific hotel, with a ground-level plaza intended by the specifier to function as genuinely high-quality, usable public space. A risk assessment for a site like this has to hold two things in tension: a prominent, busy City of London frontage that clearly carries vulnerability, and an architectural brief that explicitly didn't want the space to read as fortified.
The resolution was bespoke, impact-rated street furniture: hand-cast precast concrete planters and timber seating, designed to meet both the protective requirement and the specifier's architectural intent, with materials chosen deliberately for how they'd age in a public setting. It's a good example of the principle running through this whole guide: the mitigation is the output of the assessment, shaped to fit the site, not a fixed product dropped onto it.
Where Townscape Products fits
If you're at the stage of trying to understand what a site needs before any product conversation makes sense, our technical guides and brochures are a good starting point, and our team is also available to talk through a specific site directly.

