A phase-by-phase duty of care checklist for business travel: pre-trip through post-trip, aligned with ISO 31030 and OSHA requirements.
Duty of care in business travel is the legal and ethical obligation an employer holds to protect employees from foreseeable harm during work-related travel. That obligation runs across the full travel lifecycle: from pre-trip planning and approval, through the trip itself, to the employee's return home. It applies whether the trip is a same-day flight to a regional office or a six-week assignment in a high-risk market.
This article provides a phase-by-phase checklist aligned with ISO 31030:2021, the international guidance standard for travel risk management, so travel managers, HR directors, and security leaders can audit an existing program or build one from scratch. A Fortune 500 travel company's security team found that manual research processes consuming hours per destination could not scale to support a 15,000-employee travel program and an executive team expecting immediate answers. The checklist below is built to close that exact gap.
Duty of care in business travel is an employer's legal and ethical obligation to take reasonable steps to protect employees from foreseeable harm while traveling for work, covering physical safety, health, and security risks. It applies to every employee traveling for business, domestically or internationally, and extends across the full trip lifecycle: pre-trip planning, in-transit travel, time at the destination, and the return home.
Duty of care is not limited to war zones or high-crime cities. A traveler injured in a car accident on a routine domestic trip, or one who falls ill without access to adequate medical care, falls within the same legal framework as an employee dispatched to a politically unstable region. The obligation is proportional to risk: higher-risk trips demand more rigorous planning, but the underlying duty applies to every trip an employer authorizes.
Duty of care and travel risk management are related but distinct concepts, and conflating them is a common source of program gaps.
Travel risk management (TRM) is the structured program, policies, and tools an organization uses to fulfill its duty of care obligation: risk assessment, traveler tracking, briefing protocols, and emergency response, put into practice.
Duty of care is the obligation. Travel risk management is the operating system that satisfies it.
Three forces are pushing duty of care from a compliance afterthought to a board-level priority.
Legal exposure is rising. In the United States, OSHA's General Duty Clause obligates employers to provide a workplace free from recognized hazards, and courts have extended that obligation to travel undertaken at an employer's direction. In the UK, the Health and Safety at Work Act 1974 sets a "so far as is reasonably practicable" standard, and the Corporate Manslaughter and Corporate Homicide Act 2007 adds criminal exposure for senior-management failures that contribute to a travel-related death. Internationally, ISO 31030:2021 has become the reference standard courts and auditors use to judge whether an organization took reasonable steps.
Employee trust and retention are on the line. Duty of care has become a talent differentiator, not just a legal safeguard. One global entertainment and media company's security team described plans to expand travel protection beyond executives to include talent and general employee travel, reflecting a broader market shift toward protecting all business travelers, not just senior leaders. According to a 2026 survey of business travelers commissioned by World Travel Protection, 22% say they have not been told who to contact in an emergency abroad, a gap that erodes trust before a crisis happens.
Operational continuity depends on it. Unprotected travelers create project disruption and traveler reluctance: employees decline assignments, delay travel, or work around policy when they do not trust the program meant to protect them.
OSHA General Duty Clause: Section 5(a)(1) of the Occupational Safety and Health Act of 1970 requires employers to provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." OSHA has not issued travel-specific rules, so the General Duty Clause is the primary federal instrument used to evaluate employer conduct on business travel. Separately, many states apply the "special errand" doctrine in workers' compensation law, which treats injuries sustained while traveling at an employer's direction as arising out of employment.
Legal requirements vary by jurisdiction. Organizations operating across multiple countries should treat this as a baseline, not a complete compliance map, and consult legal counsel for jurisdiction-specific obligations.
Failing to meet duty of care obligations carries costs across three categories:
A duty of care program breaks into five phases spanning the traveler's full journey: pre-trip assessment, booking and policy compliance, pre-departure briefing, in-trip monitoring, and post-trip debrief. Use this checklist to audit an existing program or build a new one.
Traveler visibility is the ability to see, in one place, who is traveling, where, when, and what risk level that destination carries at the time of travel. Without traveler visibility, none of the later phases can function: security cannot brief, monitor, or respond to a trip it does not know is happening.
Base Operations' nine-step travel security assessment workflow maps directly to this phase: defining the destination, establishing city-wide safety context, comparing hotel risk scores, running neighborhood-level analysis, and reviewing walking safety before a single approval is issued. This addresses a common gap: generic crime data does not answer whether a threat pattern affects business travelers specifically, or just local residents, and that distinction determines whether a risk assessment is useful.
Off-platform bookings are one of the most common gaps in a duty of care program: a traveler who books outside the approved channel is invisible to security until something goes wrong. A Fortune 500 travel company's security team found that inconsistent data quality across regions, driven largely by scattered booking channels, was eliminated only after bookings and risk data moved onto a single centralized platform.
Documentation matters as much as the briefing itself. A program that cannot produce a record showing a traveler was briefed on destination-specific risks cannot demonstrate the "reasonable steps" standard that both OSHA and UK law require.
This phase is where duty of care programs typically split responsibility across tool categories: mass notification platforms such as AlertMedia and Everbridge handle event-driven alerts, assistance providers such as International SOS and Crisis24 handle medical and security response, and a persistent threat intelligence layer supplies the destination risk context both depend on. A global travel and hospitality company managing more than 400,000 people worldwide summarized the distinction directly: an event alert tool collects incidents that already happened, while a threat intelligence platform is a preventative layer built for planning ahead. A Fortune 10 company applied that combination across a 500-location global footprint, replacing fragmented regional tools with unified monitoring and using the resulting data to identify safer commute routes during a return-to-office transition.
A top-5 US healthcare provider applied this improvement cycle to its 400,000-employee, 1,100-zip-code in-home clinician program, standardizing its threat assessment framework and onboarding roughly 30 new coverage areas each quarter. Coverage rose to 85% of monitored zip codes, a threefold increase, without adding headcount to the security team.
Ready to close the gaps in your travel risk program? Download this checklist as a shareable reference for your security, HR, and travel management teams, and use it to audit where your current program falls short.
The 4 C's framework describes the pillars of a mature corporate travel program: Cost, Compliance, Care, and Carbon (sustainability).
Care is the connecting thread for duty of care programs. Cost and compliance controls exist partly to fund and enforce the care obligation: a booking policy that routes travelers through approved, centralized channels serves cost management and duty of care at the same time, because it keeps every traveler visible to the team responsible for their safety. Organizations that treat the four C's as separate workstreams tend to build travel policies with gaps; the ones that succeed treat care as the anchor the other three support.
Yes, but in a different legal context. Businesses owe a duty of care to customers under product liability and premises liability law: a retailer must maintain safe store conditions, and a manufacturer must design products that do not create unreasonable risk of harm. These obligations exist alongside, not instead of, the duty of care owed to employees.
For business travel specifically, the duty of care obligation runs to traveling employees, not to customers or the general public. A security or travel risk management program built around this article's checklist protects the organization's own workforce: the employee flying to a client meeting, attending a trade show, or opening a new market. If a business-travel-related incident also affects a customer, for example a security incident at a company-hosted event, premises liability and duty of care to employees can both apply, but they are separate legal obligations evaluated under different standards.
ISO 31030:2021 is a guidance standard published by the International Organization for Standardization (ISO) in January 2021, titled "Travel risk management: Guidance for organizations." Built on the ISO 31000 risk management framework, it provides a structured approach for organizations to identify, assess, and manage the risks associated with business travel.
ISO 31030 organizes travel risk management into five requirement areas: leadership commitment and governance, risk assessment, pre-trip authorization, traveler tracking and monitoring, and incident response. It is guidance, not law: no regulator requires certification against it. In practice, it carries significant legal weight anyway, because courts and auditors increasingly treat it as the benchmark for what "reasonably practicable" duty of care looks like. An organization that can point to an ISO 31030-aligned program has a materially stronger defense than one that cannot.
Two enterprise programs illustrate what ISO-aligned standardization looks like at scale. A leading AI company with rapidly growing executive travel volume standardized its executive protection assessments against a consistent template, and a top-5 US healthcare provider standardized its threat assessment framework across more than 1,100 zip codes covering an in-home clinician workforce. In both cases, standardization was the mechanism that turned an ad hoc process into an auditable one. That is the practical value of ISO 31030: a documented structure to point to when a regulator, auditor, or plaintiff's counsel asks how a travel decision was made.
Generic travel briefings are built for the average traveler, and the average traveler is not the one facing the highest risk. A duty of care program that treats every employee identically leaves its most exposed travelers under-protected.
According to a 2026 global survey of business travelers commissioned by World Travel Protection, 71% of women say they feel less safe traveling for work than men do. That gap shows up in behavior, not just perception: nearly a third of women surveyed said they avoid traveling or going out alone at night, roughly double the rate reported by men. A standard briefing script built around a male traveler default, covering ground transportation, accommodation location, and after-dark movement, is not sufficient. Gender-specific risk factors, including solo travel safety and accommodation neighborhood, belong in the pre-departure briefing (Phase 3), not treated as an afterthought.
At least 60 countries criminalize consensual same-sex relationships; ILGA World counted 65 UN member states with criminalizing laws in its most recent count. Yet the same World Travel Protection survey found that only 13% of employers provide LGBTQ+-specific pre-travel guidance. Destination-specific risk assessment for this population needs to account for legal exposure and social hostility that a generic crime-data feed will not surface. A senior manager at a global enterprise software company described the exact gap this creates, requesting risk filters for kidnapping exposure and for the elevated risk travelers face when perceived as foreign nationals in certain regions, a request standard country-level crime data cannot answer.
Each of these vulnerable-traveler categories needs the same underlying capability: destination and traveler-specific risk context, not a one-size-fits-all crime score. Feeding that context into Phase 1 risk profiling and Phase 3 briefing content is what separates a compliant-on-paper program from one that actually protects the traveler most likely to need it.
Ownership fragmentation is the most common implementation failure. A Fortune 100 health insurance company's security lead described the practical cost: intelligence data lacking standardized location fields is difficult to hand off to the HR, legal, and travel management teams that need it, slowing the decisions those teams own. Centralizing data in a single system (step 3) is what makes step 4's cross-functional ownership possible, not just an org chart.
Programs that follow this sequence see the return in efficiency, not just risk reduction. A global consultancy centralized its travel and site risk intelligence and measured a 35% efficiency improvement in its security operations, moving its GSOC from a reactive posture to a proactive one.
Four categories of tools support a duty of care program, and no single category covers the full lifecycle on its own.
Travel risk intelligence platforms provide destination monitoring, risk scoring, and pattern analysis. Base Operations sits in this category, providing street-level threat intelligence that enables comparative accommodation risk scoring, neighborhood-specific traveler briefings, and destination monitoring through monthly risk score updates. This category fills the Phase 1 risk assessment and Phase 4 monitoring gaps: it is the layer that tells a security team where risk is concentrated, down to the street or neighborhood, not just the country.
Traveler tracking and location visibility tools, such as SAP Concur Locate (PNR-based tracking) and card-spend-based feeds, fill the Phase 4 monitoring and welfare-check gap by showing where travelers actually are.
Mass notification and two-way communication tools, such as AlertMedia and Everbridge, fill the Phase 4 emergency response gap: they push event-driven alerts and manage two-way check-ins during an active incident.
Medical and security assistance services, such as International SOS and Crisis24, fill the Phase 4 emergency response and Phase 1 evacuation-coverage gap, providing 24/7 hotlines and evacuation networks.
These categories are complementary, not interchangeable. A leading AI company that automated its risk assessment workflow using a travel risk intelligence platform cut assessment time by 75% and tripled its threat coverage, but that platform did not replace its mass notification tool or assistance provider; it made both more effective by supplying the destination risk context they depend on. A global travel technology company made a similar point about its own enterprise customers: value is highest when travel safety information is integrated into the same system used for booking, not checked separately as a standalone tool.
See what street-level threat intelligence looks like for your travel footprint. Request a demo to see how Base Operations supports your Phase 1 risk assessment and Phase 4 monitoring workflows.
In the United States, the OSHA General Duty Clause (Section 5(a)(1) of the Occupational Safety and Health Act) requires employers to provide a workplace free from recognized hazards, and this obligation extends to travel undertaken at the employer's direction. In the United Kingdom, the Health and Safety at Work Act 1974 sets a "reasonably practicable" standard, backed by the Corporate Manslaughter and Corporate Homicide Act 2007. Requirements vary by jurisdiction, so a global travel program needs country-specific legal review. Internationally, ISO 31030:2021 has become the benchmark courts and auditors use to evaluate whether an organization took reasonable steps to protect a traveling employee.
Duty of care is an employer's obligation to prevent, monitor, and respond to risks a traveling employee faces. Travel insurance is a financial risk-transfer product that reimburses costs after an incident, such as medical treatment or trip cancellation. Insurance is one component of a duty of care program, particularly medical evacuation and repatriation coverage, but carrying a policy does not by itself satisfy the broader obligation to assess, brief, monitor, and respond to traveler risk.
Yes. Duty of care applies to domestic business travel with the same legal force as international travel, though the risk profile differs. Domestic risk factors include road safety, severe weather, regional healthcare access, and crime variation between neighborhoods in the same metro area. The same five-phase checklist (pre-trip assessment, booking, briefing, in-trip monitoring, post-trip debrief) applies; typically only the assigned risk tier and level of scrutiny change for domestic destinations.
ISO 31030:2021 is a guidance standard, not a legal requirement, so no organization is compelled to comply with it by law. In practice, courts and auditors increasingly treat it as the benchmark for what "reasonably practicable" duty of care looks like, which gives ISO 31030 alignment significant weight in litigation and compliance review even though certification is not mandatory. Any organization that sends employees to travel internationally, particularly those in regulated industries or with enterprise customers who evaluate vendor risk programs, should align its travel risk management program with the standard's five requirement areas: leadership commitment, risk assessment, pre-trip authorization, traveler tracking, and incident response.
Standard travel briefings are insufficient for LGBTQ+ travelers and other vulnerable groups because they assume a uniform risk profile that does not exist. At least 60 countries criminalize consensual same-sex relationships (65 UN member states, according to ILGA World's most recent count), yet only 13% of employers provide LGBTQ+-specific pre-travel guidance. A minimum program includes a country-specific legal briefing covering local laws and social attitudes, emergency contacts for identity-specific assistance resources, and accommodation selection that accounts for neighborhood-level hostility risk, not just general crime data. The same standard applies to travelers with pre-existing medical conditions: destination-specific medication legality and medical evacuation coverage need individual verification, not a blanket policy.
Build a duty of care program you can defend. Every checklist item above depends on knowing your risk before you need to react to it. Request a demo to see how Base Operations gives your travel security team street-level visibility across your global footprint.

Join 1100+ security leaders getting new ideas on how to better protect their people and assets.