Duty of Care Checklist for Business Travel: A Complete Employer Guide

A phase-by-phase duty of care checklist for business travel: pre-trip through post-trip, aligned with ISO 31030 and OSHA requirements.

Duty of Care Checklist for Business Travel: A Complete Employer Guide

Duty of care in business travel is the legal and ethical obligation an employer holds to protect employees from foreseeable harm during work-related travel. That obligation runs across the full travel lifecycle: from pre-trip planning and approval, through the trip itself, to the employee's return home. It applies whether the trip is a same-day flight to a regional office or a six-week assignment in a high-risk market.

This article provides a phase-by-phase checklist aligned with ISO 31030:2021, the international guidance standard for travel risk management, so travel managers, HR directors, and security leaders can audit an existing program or build one from scratch. A Fortune 500 travel company's security team found that manual research processes consuming hours per destination could not scale to support a 15,000-employee travel program and an executive team expecting immediate answers. The checklist below is built to close that exact gap.

What Is Duty of Care in Business Travel?

Duty of care in business travel is an employer's legal and ethical obligation to take reasonable steps to protect employees from foreseeable harm while traveling for work, covering physical safety, health, and security risks. It applies to every employee traveling for business, domestically or internationally, and extends across the full trip lifecycle: pre-trip planning, in-transit travel, time at the destination, and the return home.

Duty of care is not limited to war zones or high-crime cities. A traveler injured in a car accident on a routine domestic trip, or one who falls ill without access to adequate medical care, falls within the same legal framework as an employee dispatched to a politically unstable region. The obligation is proportional to risk: higher-risk trips demand more rigorous planning, but the underlying duty applies to every trip an employer authorizes.

Duty of Care vs. Travel Risk Management: What Is the Difference?

Duty of care and travel risk management are related but distinct concepts, and conflating them is a common source of program gaps.

Travel risk management (TRM) is the structured program, policies, and tools an organization uses to fulfill its duty of care obligation: risk assessment, traveler tracking, briefing protocols, and emergency response, put into practice.

Dimension Duty of Care Travel Risk Management
Definition Legal and ethical obligation to protect employees Structured program and framework to fulfill that obligation
Legal basis OSHA General Duty Clause, UK Health and Safety at Work Act 1974, common law ISO 31030:2021 (guidance standard)
Ownership The organization (employer liability) Security, HR, and travel management (cross-functional)
Measurement Legal compliance, incident outcomes KPIs: time-to-locate, response time, coverage percentage
Relationship The "why" The "how"

Duty of care is the obligation. Travel risk management is the operating system that satisfies it.

Why Duty of Care Matters for Business Travelers in 2026

Three forces are pushing duty of care from a compliance afterthought to a board-level priority.

Legal exposure is rising. In the United States, OSHA's General Duty Clause obligates employers to provide a workplace free from recognized hazards, and courts have extended that obligation to travel undertaken at an employer's direction. In the UK, the Health and Safety at Work Act 1974 sets a "so far as is reasonably practicable" standard, and the Corporate Manslaughter and Corporate Homicide Act 2007 adds criminal exposure for senior-management failures that contribute to a travel-related death. Internationally, ISO 31030:2021 has become the reference standard courts and auditors use to judge whether an organization took reasonable steps.

Employee trust and retention are on the line. Duty of care has become a talent differentiator, not just a legal safeguard. One global entertainment and media company's security team described plans to expand travel protection beyond executives to include talent and general employee travel, reflecting a broader market shift toward protecting all business travelers, not just senior leaders. According to a 2026 survey of business travelers commissioned by World Travel Protection, 22% say they have not been told who to contact in an emergency abroad, a gap that erodes trust before a crisis happens.

Operational continuity depends on it. Unprotected travelers create project disruption and traveler reluctance: employees decline assignments, delay travel, or work around policy when they do not trust the program meant to protect them.

Legal Requirements by Jurisdiction

OSHA General Duty Clause: Section 5(a)(1) of the Occupational Safety and Health Act of 1970 requires employers to provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." OSHA has not issued travel-specific rules, so the General Duty Clause is the primary federal instrument used to evaluate employer conduct on business travel. Separately, many states apply the "special errand" doctrine in workers' compensation law, which treats injuries sustained while traveling at an employer's direction as arising out of employment.

  • United States: OSHA General Duty Clause (Section 5(a)(1)); state-level workers' compensation doctrines for travel-related injury.
  • United Kingdom: Health and Safety at Work Act 1974 (reasonably practicable standard); Corporate Manslaughter and Corporate Homicide Act 2007 (criminal liability for management failures).
  • International: ISO 31030:2021 as the cross-border benchmark; specific requirements vary by jurisdiction, so legal counsel should review policy for each country of operation.

Legal requirements vary by jurisdiction. Organizations operating across multiple countries should treat this as a baseline, not a complete compliance map, and consult legal counsel for jurisdiction-specific obligations.

The Consequences of Failing Duty of Care

Failing to meet duty of care obligations carries costs across three categories:

  1. Financial: Litigation, regulatory fines, and higher insurance premiums. In Dusek v. StormHarbour Securities LLP [2015] EWHC 37 (QB), the UK High Court found a securities firm liable after an employee died in a helicopter crash while traveling to a remote project site in Peru, ruling that the firm had done nothing to investigate the flight's safety. The duty of care owed to a traveler scales with trip risk: a scheduled flight between major cities requires less scrutiny than a chartered flight into a remote, higher-risk area.
  2. Reputational: Brand damage and reduced ability to attract and retain talent, particularly among employees who travel frequently.
  3. Operational: Traveler reluctance and project disruption. A Fortune 500 travel company's security team found that when assessments consistently lagged behind business decisions, security could not demonstrate strategic value beyond crisis response, weakening its influence over travel policy at the moment it mattered most.

The Duty of Care Checklist for Business Travel (Phase-by-Phase)

A duty of care program breaks into five phases spanning the traveler's full journey: pre-trip assessment, booking and policy compliance, pre-departure briefing, in-trip monitoring, and post-trip debrief. Use this checklist to audit an existing program or build a new one.

Phase 1: Pre-Trip Risk Assessment

Traveler visibility is the ability to see, in one place, who is traveling, where, when, and what risk level that destination carries at the time of travel. Without traveler visibility, none of the later phases can function: security cannot brief, monitor, or respond to a trip it does not know is happening.

  • Conduct a destination risk assessment covering political, health, crime, cyber, and natural disaster factors
  • Profile individual traveler risk, including health conditions, gender-specific risk, and LGBTQ+ considerations
  • Verify travel documents: passport expiry, visa requirements, and required vaccinations
  • Confirm insurance coverage for medical evacuation, repatriation, and political evacuation
  • Assign a destination risk tier (low, moderate, high) using an internal framework
  • Complete an ISO 31030-aligned risk assessment template
  • Review recent incident data at the neighborhood or street level, not just the country or city level
  • Obtain required approvals for high-risk destinations
  • Verify traveler emergency contact information is current

Base Operations' nine-step travel security assessment workflow maps directly to this phase: defining the destination, establishing city-wide safety context, comparing hotel risk scores, running neighborhood-level analysis, and reviewing walking safety before a single approval is issued. This addresses a common gap: generic crime data does not answer whether a threat pattern affects business travelers specifically, or just local residents, and that distinction determines whether a risk assessment is useful.

Phase 2: Booking and Policy Compliance

  • Route all bookings through approved, centralized channels
  • Vet accommodations against security standards, including risk score and neighborhood analysis
  • Arrange vetted ground transportation
  • Confirm the pre-trip approval workflow is complete for high-risk destinations
  • Verify travel insurance is attached to the booking
  • Flag any off-platform bookings as visibility blind spots
  • Document booking decisions with the risk rationale behind them

Off-platform bookings are one of the most common gaps in a duty of care program: a traveler who books outside the approved channel is invisible to security until something goes wrong. A Fortune 500 travel company's security team found that inconsistent data quality across regions, driven largely by scattered booking channels, was eliminated only after bookings and risk data moved onto a single centralized platform.

Phase 3: Pre-Departure Traveler Briefing

  • Distribute emergency contact numbers: embassy, company security desk, and assistance hotline
  • Verify the traveler profile is current: emergency contacts, medical conditions, dietary and allergy information
  • Confirm the traveler tracking app or tool is installed and functioning
  • Provide an offline emergency contact card
  • Communicate the check-in protocol appropriate to the destination's risk level
  • Brief the traveler on destination-specific risks and areas to avoid
  • Provide cultural and legal awareness briefing, especially for first-time destinations
  • Document that the briefing occurred, for liability protection
  • Provide time-based safety protocols, such as rideshare requirements after dark

Documentation matters as much as the briefing itself. A program that cannot produce a record showing a traveler was briefed on destination-specific risks cannot demonstrate the "reasonable steps" standard that both OSHA and UK law require.

Phase 4: In-Trip Monitoring and Emergency Response

  • Activate traveler location tracking through GPS or itinerary feeds
  • Configure alerts for destination risk changes: political unrest, natural disaster, health outbreak
  • Confirm two-way mass communication capability is operational
  • Verify 24/7 assistance line access
  • Confirm emergency fund access, including corporate card limits and emergency cash protocols
  • Establish an early extraction protocol for use if risk escalates
  • Define welfare check procedures triggered by proximity to an incident
  • Maintain dashboard visibility for the security operations team

This phase is where duty of care programs typically split responsibility across tool categories: mass notification platforms such as AlertMedia and Everbridge handle event-driven alerts, assistance providers such as International SOS and Crisis24 handle medical and security response, and a persistent threat intelligence layer supplies the destination risk context both depend on. A global travel and hospitality company managing more than 400,000 people worldwide summarized the distinction directly: an event alert tool collects incidents that already happened, while a threat intelligence platform is a preventative layer built for planning ahead. A Fortune 10 company applied that combination across a 500-location global footprint, replacing fragmented regional tools with unified monitoring and using the resulting data to identify safer commute routes during a return-to-office transition.

Phase 5: Post-Trip Debrief and Program Improvement

  • File incident reports within 48 hours of return
  • Conduct a traveler health and mental health check-in, especially after high-risk travel
  • Collect traveler feedback on the safety experience and any program gaps
  • Feed trip-level risk data back into the pre-trip assessment model
  • Update destination risk ratings based on new trip intelligence
  • Review quarterly KPIs: time-to-locate, message delivery rate, incident closure time
  • Document lessons learned and distribute them to the travel security team

A top-5 US healthcare provider applied this improvement cycle to its 400,000-employee, 1,100-zip-code in-home clinician program, standardizing its threat assessment framework and onboarding roughly 30 new coverage areas each quarter. Coverage rose to 85% of monitored zip codes, a threefold increase, without adding headcount to the security team.

Ready to close the gaps in your travel risk program? Download this checklist as a shareable reference for your security, HR, and travel management teams, and use it to audit where your current program falls short.

What Are the 4 C's of Corporate Travel Management?

The 4 C's framework describes the pillars of a mature corporate travel program: Cost, Compliance, Care, and Carbon (sustainability).

  • Cost: Managing travel spend through negotiated rates, preferred vendors, and expense policy enforcement.
  • Compliance: Ensuring bookings and traveler behavior align with internal policy and external regulation.
  • Care: Protecting traveler health, safety, and security across the trip lifecycle, the focus of this article.
  • Carbon: Measuring and reducing the environmental footprint of business travel, from flight selection to trip necessity review.

Care is the connecting thread for duty of care programs. Cost and compliance controls exist partly to fund and enforce the care obligation: a booking policy that routes travelers through approved, centralized channels serves cost management and duty of care at the same time, because it keeps every traveler visible to the team responsible for their safety. Organizations that treat the four C's as separate workstreams tend to build travel policies with gaps; the ones that succeed treat care as the anchor the other three support.

Do Businesses Have a Duty of Care to Customers?

Yes, but in a different legal context. Businesses owe a duty of care to customers under product liability and premises liability law: a retailer must maintain safe store conditions, and a manufacturer must design products that do not create unreasonable risk of harm. These obligations exist alongside, not instead of, the duty of care owed to employees.

For business travel specifically, the duty of care obligation runs to traveling employees, not to customers or the general public. A security or travel risk management program built around this article's checklist protects the organization's own workforce: the employee flying to a client meeting, attending a trade show, or opening a new market. If a business-travel-related incident also affects a customer, for example a security incident at a company-hosted event, premises liability and duty of care to employees can both apply, but they are separate legal obligations evaluated under different standards.

ISO 31030 and the International Standard for Travel Risk Management

ISO 31030:2021 is a guidance standard published by the International Organization for Standardization (ISO) in January 2021, titled "Travel risk management: Guidance for organizations." Built on the ISO 31000 risk management framework, it provides a structured approach for organizations to identify, assess, and manage the risks associated with business travel.

ISO 31030 organizes travel risk management into five requirement areas: leadership commitment and governance, risk assessment, pre-trip authorization, traveler tracking and monitoring, and incident response. It is guidance, not law: no regulator requires certification against it. In practice, it carries significant legal weight anyway, because courts and auditors increasingly treat it as the benchmark for what "reasonably practicable" duty of care looks like. An organization that can point to an ISO 31030-aligned program has a materially stronger defense than one that cannot.

ISO 31030 Requirement Checklist Action Phase
Leadership commitment Assign cross-functional ownership across security, HR, travel, and legal Implementation
Risk assessment Complete destination and individual traveler risk profiling Phase 1
Pre-trip authorization Apply a tiered approval workflow for high-risk destinations Phase 2
Traveler tracking and monitoring Maintain traveler location visibility and destination risk alerts Phase 4
Incident response Provide 24/7 assistance access and an extraction protocol Phase 4

Two enterprise programs illustrate what ISO-aligned standardization looks like at scale. A leading AI company with rapidly growing executive travel volume standardized its executive protection assessments against a consistent template, and a top-5 US healthcare provider standardized its threat assessment framework across more than 1,100 zip codes covering an in-home clinician workforce. In both cases, standardization was the mechanism that turned an ad hoc process into an auditable one. That is the practical value of ISO 31030: a documented structure to point to when a regulator, auditor, or plaintiff's counsel asks how a travel decision was made.

Duty of Care for Vulnerable Traveler Groups

Generic travel briefings are built for the average traveler, and the average traveler is not the one facing the highest risk. A duty of care program that treats every employee identically leaves its most exposed travelers under-protected.

Women Travelers

According to a 2026 global survey of business travelers commissioned by World Travel Protection, 71% of women say they feel less safe traveling for work than men do. That gap shows up in behavior, not just perception: nearly a third of women surveyed said they avoid traveling or going out alone at night, roughly double the rate reported by men. A standard briefing script built around a male traveler default, covering ground transportation, accommodation location, and after-dark movement, is not sufficient. Gender-specific risk factors, including solo travel safety and accommodation neighborhood, belong in the pre-departure briefing (Phase 3), not treated as an afterthought.

LGBTQ+ Travelers

At least 60 countries criminalize consensual same-sex relationships; ILGA World counted 65 UN member states with criminalizing laws in its most recent count. Yet the same World Travel Protection survey found that only 13% of employers provide LGBTQ+-specific pre-travel guidance. Destination-specific risk assessment for this population needs to account for legal exposure and social hostility that a generic crime-data feed will not surface. A senior manager at a global enterprise software company described the exact gap this creates, requesting risk filters for kidnapping exposure and for the elevated risk travelers face when perceived as foreign nationals in certain regions, a request standard country-level crime data cannot answer.

Travelers With Pre-Existing Medical Conditions

  • Pre-travel health screening to identify conditions relevant to the destination
  • Telemedicine access confirmed before departure
  • Medical evacuation coverage verified, not assumed
  • Medication legality confirmed in the destination country; some common prescriptions are controlled substances abroad

Each of these vulnerable-traveler categories needs the same underlying capability: destination and traveler-specific risk context, not a one-size-fits-all crime score. Feeding that context into Phase 1 risk profiling and Phase 3 briefing content is what separates a compliant-on-paper program from one that actually protects the traveler most likely to need it.

How to Implement a Duty of Care Policy for Business Travel (Step-by-Step)

  1. Audit the current state against ISO 31030 requirements to identify gaps in policy, tooling, and ownership.
  2. Define risk appetite and create tiered destination risk ratings (low, moderate, high) that drive approval and briefing requirements.
  3. Centralize all travel data in a single system to eliminate off-platform booking blind spots.
  4. Assign clear cross-functional ownership across security, HR, travel management, and legal.
  5. Deploy traveler communication and tracking tools, combining an intelligence platform, a notification system, and an assistance provider.
  6. Train travelers and managers on briefing protocols, app adoption, and escalation paths.
  7. Establish a quarterly review cadence to reassess KPIs, update policy, and recalibrate risk ratings.
Function Duty of Care Role
Security/Risk Threat intelligence, destination risk ratings, emergency response
HR Policy ownership, traveler welfare, post-trip health check-ins
Travel Management Booking compliance, itinerary visibility, vendor management
Legal Regulatory compliance, liability review, policy sign-off
Finance Insurance coverage, emergency fund access, budget allocation

Ownership fragmentation is the most common implementation failure. A Fortune 100 health insurance company's security lead described the practical cost: intelligence data lacking standardized location fields is difficult to hand off to the HR, legal, and travel management teams that need it, slowing the decisions those teams own. Centralizing data in a single system (step 3) is what makes step 4's cross-functional ownership possible, not just an org chart.

Programs that follow this sequence see the return in efficiency, not just risk reduction. A global consultancy centralized its travel and site risk intelligence and measured a 35% efficiency improvement in its security operations, moving its GSOC from a reactive posture to a proactive one.

Technology and Tools That Support Duty of Care Compliance

Four categories of tools support a duty of care program, and no single category covers the full lifecycle on its own.

Travel risk intelligence platforms provide destination monitoring, risk scoring, and pattern analysis. Base Operations sits in this category, providing street-level threat intelligence that enables comparative accommodation risk scoring, neighborhood-specific traveler briefings, and destination monitoring through monthly risk score updates. This category fills the Phase 1 risk assessment and Phase 4 monitoring gaps: it is the layer that tells a security team where risk is concentrated, down to the street or neighborhood, not just the country.

Traveler tracking and location visibility tools, such as SAP Concur Locate (PNR-based tracking) and card-spend-based feeds, fill the Phase 4 monitoring and welfare-check gap by showing where travelers actually are.

Mass notification and two-way communication tools, such as AlertMedia and Everbridge, fill the Phase 4 emergency response gap: they push event-driven alerts and manage two-way check-ins during an active incident.

Medical and security assistance services, such as International SOS and Crisis24, fill the Phase 4 emergency response and Phase 1 evacuation-coverage gap, providing 24/7 hotlines and evacuation networks.

These categories are complementary, not interchangeable. A leading AI company that automated its risk assessment workflow using a travel risk intelligence platform cut assessment time by 75% and tripled its threat coverage, but that platform did not replace its mass notification tool or assistance provider; it made both more effective by supplying the destination risk context they depend on. A global travel technology company made a similar point about its own enterprise customers: value is highest when travel safety information is integrated into the same system used for booking, not checked separately as a standalone tool.

See what street-level threat intelligence looks like for your travel footprint. Request a demo to see how Base Operations supports your Phase 1 risk assessment and Phase 4 monitoring workflows.


Frequently Asked Questions About Duty of Care for Business Travel

What is the legal requirement for duty of care in business travel?  

In the United States, the OSHA General Duty Clause (Section 5(a)(1) of the Occupational Safety and Health Act) requires employers to provide a workplace free from recognized hazards, and this obligation extends to travel undertaken at the employer's direction. In the United Kingdom, the Health and Safety at Work Act 1974 sets a "reasonably practicable" standard, backed by the Corporate Manslaughter and Corporate Homicide Act 2007. Requirements vary by jurisdiction, so a global travel program needs country-specific legal review. Internationally, ISO 31030:2021 has become the benchmark courts and auditors use to evaluate whether an organization took reasonable steps to protect a traveling employee.

What is the difference between duty of care and travel insurance?

Duty of care is an employer's obligation to prevent, monitor, and respond to risks a traveling employee faces. Travel insurance is a financial risk-transfer product that reimburses costs after an incident, such as medical treatment or trip cancellation. Insurance is one component of a duty of care program, particularly medical evacuation and repatriation coverage, but carrying a policy does not by itself satisfy the broader obligation to assess, brief, monitor, and respond to traveler risk.

Does duty of care apply to domestic business travel?

Yes. Duty of care applies to domestic business travel with the same legal force as international travel, though the risk profile differs. Domestic risk factors include road safety, severe weather, regional healthcare access, and crime variation between neighborhoods in the same metro area. The same five-phase checklist (pre-trip assessment, booking, briefing, in-trip monitoring, post-trip debrief) applies; typically only the assigned risk tier and level of scrutiny change for domestic destinations.

What is ISO 31030 and does my organization need to comply with it?

ISO 31030:2021 is a guidance standard, not a legal requirement, so no organization is compelled to comply with it by law. In practice, courts and auditors increasingly treat it as the benchmark for what "reasonably practicable" duty of care looks like, which gives ISO 31030 alignment significant weight in litigation and compliance review even though certification is not mandatory. Any organization that sends employees to travel internationally, particularly those in regulated industries or with enterprise customers who evaluate vendor risk programs, should align its travel risk management program with the standard's five requirement areas: leadership commitment, risk assessment, pre-trip authorization, traveler tracking, and incident response.

How do I handle duty of care for LGBTQ+ or other vulnerable travelers?

Standard travel briefings are insufficient for LGBTQ+ travelers and other vulnerable groups because they assume a uniform risk profile that does not exist. At least 60 countries criminalize consensual same-sex relationships (65 UN member states, according to ILGA World's most recent count), yet only 13% of employers provide LGBTQ+-specific pre-travel guidance. A minimum program includes a country-specific legal briefing covering local laws and social attitudes, emergency contacts for identity-specific assistance resources, and accommodation selection that accounts for neighborhood-level hostility risk, not just general crime data. The same standard applies to travelers with pre-existing medical conditions: destination-specific medication legality and medical evacuation coverage need individual verification, not a blanket policy.

Build a duty of care program you can defend. Every checklist item above depends on knowing your risk before you need to react to it. Request a demo to see how Base Operations gives your travel security team street-level visibility across your global footprint.

Takeaways

Subscribe to newsletter

Join 1100+ security leaders getting new ideas on how to better protect their people and assets.