A locked door is a security feature until the moment the fire alarm sounds and it is standing between people and their escape route. Under the Regulatory Reform (Fire Safety) Order 2005, Articles 13 and 14 make the Responsible Person accountable for fire detection and for emergency routes and exits. In a building with electronic access control, those two duties meet at one specific piece of engineering: the interface that releases the doors when the alarm operates.
In our survey work across commercial estates, that interface is one of the most common, and most serious, failures we find. Not because anyone decided to cut a corner, but because access control and fire detection are usually bought, installed and maintained as separate systems, by separate contractors, on separate service contracts. Each system passes its own service visit. Nobody owns the join.
What the standard actually requires
BS 7273-4 is the code of practice for the actuation of release mechanisms for doors: the document that governs how electronically locked doors on escape routes behave when the fire alarm operates. It does not treat every door the same. It defines three categories of actuation, and the category decides how much has to go wrong before the door still opens.
- Critical actuation (Category A). Release is driven directly by the fire alarm system and fails safe under the widest range of faults, including total loss of the fire alarm panel’s normal and standby power. Annex B calls for this wherever the public are present (shops, hotels, pubs, venues, transport terminals), in residential care, hospitals and schools.
- Standard actuation (Category B). The door releases on a fire signal, on any open or short circuit in the wiring that carries the release signal, and on loss of power to the lock. Faults elsewhere in the fire alarm system do not have to release it.
- Indirect actuation (Category C). The fire alarm signals the access control equipment, and the access control equipment releases the door. Permitted in ordinary workplaces such as offices, factories and warehouses where staff are trained, but only with safeguards: the link between the fire panel and the access control equipment must itself fail safe, and unless the doors release when the access control power fails, that supply needs at least four hours of standby.
Whichever category applies, four principles hold for electronically secured doors on a means of escape:
- The lock must need power to stay locked. On total loss of power the door unlocks. A standby battery may keep it secured for security reasons, but only if the manual release control cuts the standby supply as well as the mains.
- Every secured door needs a manual release control beside it. A green break-glass marked “EMERGENCY DOOR RELEASE”, within about two metres of the door, wired directly in series with the lock’s power so that it works whatever state the fire alarm or the access control system is in, and releasing the door within three seconds.
- Once released, the door stays released until the fire alarm is reset. Silencing the sounders must not re-lock it, and secured doors must never rely on an acoustic signal from the sounders to release at all.
- The release wiring is expected to fail safe, not to survive the fire. This is the point most often got wrong. Because an open or short circuit on the release circuit causes the door to unlock, the standard says that wiring does not need to be fire-resisting; what it needs is mechanical protection, so that damage does not release doors unnecessarily. Fire-resisting cable to BS 5839-1 is only required where, exceptionally, a release circuit cannot be made to fail safe.
Five questions for your own building
If your estate has access control, these five questions establish whether you have a compliance position or a liability.
- Which category of actuation was installed, and where is it written down? The commissioning certificate should state it. If nobody can produce a category, nobody designed the interface against the standard.
- Does every access-controlled door on an escape route release when its wiring fails, and unlock when its power fails? Those two conditions are the minimum in every category. A door that stays locked on a cut cable or a dead supply is non-compliant whatever else is true.
- Is there a green emergency door release at every secured door, and does it cut the standby battery too? A release control that only tells the access control software to open the door does not count.
- Is there any mechanical lock that can be left engaged? A key-operated deadlock or a bolt fitted alongside a maglock stays locked no matter what the electronics do. It is outside the electrical fail-safe entirely and needs its own remediation. A thumb-turn that occupants can operate from inside is a different matter, and can reduce what the standard asks of the electronic release.
- When was release last proved door by door? The standard expects a weekly fire alarm test that actuates every release mechanism and confirms each door unlocks, inspection and servicing of the release arrangements at intervals not exceeding six months, and an annual operation of every manual release control. Not the alarm test alone: the doors.
Why service records miss it
The uncomfortable pattern: a building can hold years of clean fire alarm service certificates while its escape-route doors would not have released on any of those days. The alarm services test the alarm. The access control services test the access control. Unless someone tests the release itself, and knows what BS 7273-4 requires of it, the gap sits invisibly between two healthy-looking maintenance files. We have seen service paperwork that recorded doors failing to release on activation, on the same visit the system was signed off as fault-free.
What good remediation looks like
The fix is rarely exotic: a door-by-door survey against the access control asset register, with the category of actuation the building needs taken from Annex B; interface units that fail safe, with release wiring mechanically protected and fire-resisting only where a circuit genuinely cannot fail safe; locks that unlock on power loss, with any security standby wired through the manual release; a green release control at every door that lacks one; the mechanical locking issues separated into their own workstream; and a witnessed, whole-site cause-and-effect test at the end, every door physically proven and documented for the Responsible Person’s file, with the category stated on the certificate.
The result is release that works when the software does not. If you cannot answer the five questions above for your building, a survey will answer them quickly, and give you the evidence either way. Start with our access control and fire systems teams, or talk to us about a door-release survey across your estate.