In April 2026, the UK government confirmed it would convene an industry-wide roundtable on hotel guest safety. The catalyst was a single conviction: in January 2026, Kyran Smith was jailed for seven years and seven months for trespass with intent to commit a relevant sexual offence and for sexual assault, after Travelodge reception staff handed him a keycard to a woman’s room at the Maidenhead branch in December 2022. He had given only her name and claimed to be her boyfriend.

The scandal that followed was not really about Travelodge. It was about how thin the line is, in much of UK hospitality, between a paying guest and an unauthorised intruder when the only thing standing in between is a brief conversation at a front desk. Over 100 MPs and peers wrote to Travelodge’s chief executive, Jo Boydell, after reports that the victim had initially been offered a £30 refund. The chain has since overhauled its key-issuing policy, but the wider question, the one the government is now expected to put to industry, is whether voluntary changes are enough.

What Travelodge Has Changed

Travelodge’s revised policy now requires staff to verify the identity of anyone asking for a room key. According to reporting by the BBC and ITV News, that verification must come either through the original booking reference or by contacting the person already inside the room. Replacement keys can no longer be issued on the basis of a name alone.

That is a reasonable baseline. It is also not a particularly demanding one. In a separate incident reported by ITV News in May 2026, a woman alleged that a stranger had been issued a keycard and accessed her room at a Travelodge in York in June 2025, which suggests the gap between written policy and frontline practice can still be wide. Where regulators land on this is now a matter of active consultation.

Why Hotel Access Control Is Different

Most corporate buildings operate on a closed-loop model: only known staff and verified visitors get badges, and every badge is tied to an audit trail. A hotel does the opposite. It pushes hundreds of strangers through reception every day, hands each of them a credential to a private room, and expects junior staff, often working alone on night shift, to make consequential identity decisions in seconds.

That tension is the heart of the problem. Access control in a hotel is not just a piece of hardware. It is a chain of human and technical steps, each of which has to hold up under pressure. When the chain breaks, it tends to break at the human end.

Hotel Access Control 101

For operators reviewing their own protocols, our team would expect a credible baseline to cover the following:

  • Identity verification at every key issue. A photo ID check at first issue, and a booking reference or in-room confirmation for any replacement or additional key. No exceptions for confident-sounding visitors who claim a relationship to the guest.
  • Audit trails on every keycard. Modern electronic locks log who opened which door and when. That data should be reviewed after any incident, and ideally sampled proactively for anomalies, such as a single card being used at unusual hours or out of sequence.
  • Clear escalation rules for front-desk staff. Reception staff need a written, rehearsed protocol for what to do when a guest is distressed, when a visitor’s story does not add up, or when CCTV shows a person loitering near guest floors. They also need permission to call the duty manager and the police without waiting for sign-off.
  • Restricted access to non-guest floors. Service corridors, plant rooms, and back-of-house should require staff credentials. Lift access to guest floors should ideally be tied to an active key.
  • CCTV coverage of corridors and key issuing points. Cameras at reception, at lift lobbies, and along guest-floor corridors are now industry standard. Footage retention should be long enough to support a police investigation that may only open weeks later.
  • Vetted, SIA-licensed security staff overnight. Many incidents at hotels happen after midnight, when one receptionist may be the only person on shift. A licensed security officer on the premises overnight materially shifts the risk profile.

What This Means for Hotel Operators

The Travelodge case has done two things at once. It has put hotel guest safety on the legislative agenda for the first time in years, alongside the parallel rollout of Martyn’s Law for venues that meet the relevant occupancy thresholds. And it has made every UK hotel chain a stakeholder in the outcome, not just the brand involved.

Operators reviewing their own posture before the government roundtable concludes should be doing three things now. First, audit how replacement keys are issued at every property and document the result. Second, brief reception and night-shift staff on the specific scenarios the Travelodge case highlights, including the unverified-partner scenario, so the response is not improvised. Third, where overnight cover is a single member of staff at reception, consider whether a dedicated, SIA-licensed security presence would close the gap.

Voluntary change is moving in the right direction. Whether it moves fast enough to satisfy the Home Office is the open question.

Need a Security Review?

Our team supports hotels, serviced apartments, and other hospitality operators across London and the wider UK with overnight manned guarding, access control reviews, and CCTV assessments. If you are reviewing your access control protocols ahead of the government’s roundtable, or simply want a second opinion on how your front-of-house holds up at 3am, we can help.

Call us on 020 3700 0967, email info@secureonsitesecurity.co.uk, or use our contact form. You can also read more about our corporate security services and manned guarding options.

Loading...
Share This