Duty of care in corporate travel is the obligation to protect traveling employees. Get the framework, legal foundations, tools, and a program checklist.
Duty of care in corporate travel is a company's legal and moral obligation to take reasonable steps to protect the health, safety, and security of employees while they travel for work. This responsibility applies before the trip begins, throughout the journey, and after the employee returns, and it covers domestic travel as well as international assignments. Failure to fulfill this obligation can expose an organization to negligence claims, regulatory penalties, and reputational harm.
For travel managers, HR leaders, and security teams, duty of care is not a single policy or piece of software. It is a standing organizational commitment touching pre-trip planning, in-transit support, and post-return review. Companies that treat it as a checkbox exercise, rather than a program with clear ownership, get caught unprepared when something goes wrong.
Duty of care carries weight across three distinct areas: legal exposure, employee trust, and business continuity. Each has its own consequences when a program falls short.
In the United States, the OSHA General Duty Clause (Section 5(a)(1)) requires employers to provide a workplace free from recognized hazards likely to cause death or serious harm, and courts have extended this expectation to business travel. Negligence is the legal failure to take reasonable precautions against a foreseeable harm, and foreseeable harm means a risk a reasonable employer should have anticipated, such as sending an employee to a destination with a documented pattern of violent crime without a briefing or response plan.
Employment law exposure compounds when travel crosses jurisdictions, since each country, and sometimes each state, layers on its own standard of care. The financial scale of premises-liability failures can be severe: in 2019, MGM Resorts agreed to pay up to $800 million to settle negligence claims tied to the 2017 mass shooting in Las Vegas, an extreme illustration of how far liability exposure can extend when an organization falls short of a reasonable duty to protect people on its premises.
Duty of care also shapes whether employees are willing to travel at all. Up to 90% of employees may decline a business trip over safety or social concerns, according to SAP Concur, and 82% of workers believe their employer is directly responsible for their safety while traveling, per AlertMedia research. A security manager at a global technology and social media company described a related gap directly: employees who grew up in low-crime environments in Singapore and China often arrive in higher-risk destinations across Latin America or London without the street-level awareness to protect themselves, in some cases carrying $5,000 to $6,000 in cash without realizing the exposure that creates. That gap in awareness is a duty of care problem, not just a training gap, and it directly affects whether talent is willing to accept travel-heavy roles.
An unmanaged travel incident does not stay contained to the traveler. It disrupts deal timelines, client relationships, and project schedules, and it functions as an uninsured operational risk sitting on the business. A security leader at a Fortune 100 global entertainment company described this shift directly, explaining the organization's intent to expand its duty of care program from executive travel alone to cover "executive, talent, and employee travel." That expansion reflects a broader recognition among large employers: business continuity risk from travel incidents is no longer limited to the C-suite.
Duty of care programs typically operate on a tiered coverage model, and defining the boundaries explicitly protects both the company and the traveler.
Tier 1 coverage applies to any employee on company-directed travel, along with embedded contractors whose work exposes them to the same operational risks as full-time staff. If a contractor is functioning as an extension of the company's operations while traveling on its behalf, the practical and often legal expectation is that the company's duty of care program covers them too.
Tier 2 coverage extends to legal dependents accompanying an employee on a company-sponsored relocation or long-term posting. This tier requires its own documented policy, since the scope, support services, and emergency protocols for a spouse or child on an accompanied assignment differ from those for a business traveler on a five-day trip.
Purely personal travel, unrelated to any company assignment, generally falls outside the scope of corporate duty of care, as does travel by extended family members who are not part of a company-sponsored posting. Documenting this boundary clearly protects the company from open-ended liability and gives employees a clear understanding of where their own responsibility begins.
Bleisure travel, which combines a business trip with a personal extension, has become common enough that most duty of care policies need explicit language addressing it. The business leg of the trip is unambiguously covered. The personal extension is more nuanced, but a company's responsibility does not necessarily switch off entirely: it placed the employee in an unfamiliar environment for a business reason in the first place, and emergency support during the extension may still fall within a reasonable duty of care obligation. Policies that leave this scenario undefined create ambiguity for exactly the moment when clarity matters most.
Duty of care and travel risk management are related but distinct concepts, and confusing them leads to gaps in ownership. Duty of care is the obligation. Travel risk management, often abbreviated TRM, is the operational system a company builds to fulfill that obligation, combining risk intelligence, monitoring, communication tools, and emergency response protocols into a working program.
Duty of care is also broader than a standard workplace health and safety policy, which is built around a fixed physical location. Business travel introduces variable, unfamiliar environments that shift with every trip, which is why a static health and safety manual cannot substitute for a travel-specific program. A security professional at a global travel technology company summarized what enterprise buyers actually want from this space: an integrated, "one stop shop" experience that connects travel safety information directly into booking, itinerary, and communication systems, rather than a patchwork of disconnected tools bridging obligation and execution.
Duty of care obligations are not defined by a single global law. They accumulate from a patchwork of national statutes, case law, and international standards, and the requirements shift depending on where employees are traveling from and to.
The OSHA General Duty Clause anchors the U.S. federal standard, requiring employers to address recognized hazards. Beyond OSHA, state-level workers' compensation systems and common-law tort claims for negligence create additional exposure, particularly when an employer knew or should have known about a specific risk and failed to act.
The UK's Health and Safety at Work Act 1974 requires employers to ensure the health, safety, and welfare of employees "so far as is reasonably practicable." Courts have applied this standard extraterritorially to UK-based employers whose staff travel or work abroad, meaning the obligation does not stop at the border.
The EU Health and Safety Framework Directive (89/391/EEC) sets a baseline across member states, but individual countries layer on their own requirements. France's Loi de Vigilance imposes a duty of vigilance on large corporations for risks connected to their operations, and Germany's Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz) extends due diligence obligations across a company's operations and value chain. The Netherlands has developed its own body of corporate duty of care case law in similar territory.
ISO 31030 is an international standard providing structured guidance for managing travel-related risk, covering policy design, risk assessment, monitoring, response, and program review. It functions as a de facto global baseline regardless of which country's laws apply, and gives travel risk programs a shared maturity framework: basic, developing, established, and advanced. Despite that, 31% of travel buyers have never heard of ISO 31030, according to BCD Travel, meaning a meaningful share of programs operate without reference to the one standard designed to unify this field.
A mature duty of care program is built on four operational pillars that map to the lifecycle of a trip.
This pillar covers destination risk scoring, which is a quantified evaluation of the threat level at a specific location, along with pre-trip approval workflows for higher-risk destinations, culturally aware traveler briefings, and confirmation of vaccination requirements, health clearances, and insurance coverage. A Base Operations use case for corporate travel safety assessment walks through this exact workflow: destination mapping, city-wide safety context, hotel comparison using quantified risk scoring, and neighborhood-level analysis that feeds directly into a traveler's pre-trip briefing materials.
Once a trip is underway, this pillar covers traveler tracking, which combines passenger name record (PNR) data, mobile GPS, and card-swipe activity to maintain location awareness, alongside two-way communication and 24/7 assistance access. Event-driven alert platforms such as Dataminr, Everbridge, and AlertMedia handle notifications during this phase. Base Operations plays a complementary role: it provides the underlying threat landscape intelligence, refreshed on a monthly cadence, that these platforms and travel teams use to understand a location's baseline risk before and during a trip. A Fortune 10 company applies this combination to monitor more than 500 locations in one system for continuous threat landscape tracking, and a representative at a Fortune 500 financial services company described using location-level intelligence to assess destinations whenever the operations team sends representatives into the field.
This pillar covers incident escalation protocols, medevac, which is the coordinated transport of an injured or ill employee to an appropriate medical facility, security extraction, and mass notification, which means pushing alerts to affected travelers with confirmation each one received the message. Documented response playbooks matter because ambiguity during an incident costs time. The Security Director at a Fortune 500 global cruise line operator described a common failure pattern: relying on multiple outside vendors for information, then having analysts collate daily bulletins from disconnected sources instead of executing a response.
The final pillar covers incident reporting, traveler debriefs, policy updates driven by lessons learned, legal documentation, and mental health support for any traveler who experienced an incident. Programs that skip this step repeat the same gaps on the next trip.
Use this checklist to audit whether a travel program covers the full lifecycle of a trip.
Pre-Travel Checklist:
During-Travel Checklist:
Post-Travel Checklist:
Program Readiness Diagnostic
These seven questions, adapted from a Direct Travel readiness framework, form a quick audit of program maturity:
Duty of care fails most often not because no one is responsible, but because responsibility is spread across departments without a clear owner for the moments that matter most.
The most common failure mode is ambiguity over who owns the "last mile," meaning the actual moment an incident occurs and someone needs to act. A global consultancy with 280,000 employees found its security team was consumed by manual, low-value tasks and unable to operate as a strategic partner until it freed up capacity through more efficient tooling. A recurring theme across enterprise customers: shifting from reactive response to proactive risk management requires an explicit, named owner, not a responsibility assumed to be someone else's job.
The framework only matters if it holds up against the specific risks travelers actually face.
Programs need destination-specific intelligence and clearly defined evacuation triggers. A Fortune 500 travel company uses street-level intelligence to shape destination-specific response plans rather than relying on broad country-level alerts.
A seasonal risk review ahead of the trip, paired with mass notification capability, allows a program to react quickly when weather disrupts travel plans.
Confirmed insurance coverage, medevac service-level agreements, and a vetted network of in-country medical providers close the gap between an incident and appropriate care.
VPN requirements, device security policies, and clear guidance on public Wi-Fi use protect both the traveler and company data while on the road.
Generic country-level crime statistics obscure risk that varies block by block. A quantified example: within a quarter-mile radius of one hotel evaluated for executive travel, location-level data identified 189 simple assaults, 58 aggravated assaults, 45 robberies, and 9 homicides in a single quarter, a level of granularity a country-level rating would never surface. A senior manager at a Fortune 100 enterprise technology company put it directly: what matters is location-specific risk, such as the likelihood of being targeted as a foreigner in a particular region, not a national crime average. Cultural awareness gaps compound this further, since travelers unfamiliar with a destination are less likely to recognize warning signs.
Alternative routing options, 24/7 rebooking support, and pre-arranged emergency accommodation protocols reduce the time a traveler spends stranded.
No single tool covers every duty of care obligation. Most mature programs combine several categories of technology, each addressing a different gap.
These platforms provide threat landscape intelligence, location risk scoring, and trend analysis, though specifics vary by vendor. When evaluating one, look at data source quality, update frequency, whether findings are analyst-verified or automated only, and whether the platform delivers street-level or only city-level granularity. It is worth distinguishing between persistent threat intelligence platforms like Base Operations, which aggregate 25,000+ global data sources and refresh on a monthly cadence at sub-mile resolution, and event-driven alert platforms such as Dataminr and Everbridge. These are complementary layers, not competing ones: one gives a program its baseline understanding of a location's threat landscape, and the other pushes notifications when a specific event unfolds. Named platforms in the broader travel risk intelligence category include International SOS and Crisis24. A Fortune 500 travel company described its own shift from country-level geopolitical analysis to sub-mile precision, now assessing more than 300 locations annually with that level of granularity.
These tools combine PNR data, GPS, and card-swipe activity to maintain a continuously updated picture of where travelers are. Evaluation criteria include privacy compliance, the ability to ingest data across multiple platforms, and location accuracy in remote or lower-connectivity regions. Named tools in this category include SAP Concur Locate and Safeture.
These systems push alerts to travelers and confirm receipt, escalating automatically when someone does not respond. Look for multi-channel delivery across SMS, app, and voice, confirmed delivery tracking, and integration with existing traveler profile data. Everbridge is a named platform in this category.
These services provide global hotlines, medevac coordination, and security extraction capability. When evaluating a provider, distinguish between an owned clinical network and a brokered one, and ask for average response time service-level agreements. Healix is a named provider in this space.
Choosing the right technology starts with identifying the specific gap a program has:
Enterprise buyers increasingly want these categories to work together rather than as isolated point solutions. A security professional at a global travel technology company described the ideal as a "one stop shop" connecting supply, booking, and travel safety information into a single system, and a security manager at a global technology and social media company noted that a platform's versatility across travel risk, event security, and real estate site selection is itself a factor in the buying decision. AI-enhanced analysis is also changing what these platforms deliver: one enterprise customer measured a 25% increase in threat-related insights after adding it to their assessment workflow.
Building or auditing a duty of care policy follows a sequence, whether starting from scratch or updating an existing program.
Start with the seven diagnostic questions from the checklist section above. The Security Director at a Fortune 500 global cruise line operator described the outcome of this kind of audit candidly: a team that assumed it was doing intelligence work discovered its analysts were spending most of their time aggregating data rather than analyzing it.
Apply the tiered coverage model from the earlier section on scope, explicitly documenting which employees, contractors, and dependents fall under which tier.
Define what risk level triggers a pre-trip approval requirement and what triggers an outright travel prohibition. Quantified destination risk scoring makes it possible to set these thresholds against a consistent number rather than a subjective judgment call.
Cross-reference the buyer decision framework from the technology section to match specific tools to specific gaps rather than buying a bundle that duplicates existing capability. A global 3PL that selected the right combination of platforms achieved a 4x increase in the scale of its route security analysis alongside a 75% reduction in assessment costs.
A duty of care policy buried on a rarely visited intranet page is not effective. It needs to be accessible, with clear, named escalation contacts a traveler can find in under a minute during an emergency.
Cultural awareness training is essential for a globally distributed workforce traveling into unfamiliar risk environments, and emergency response protocols should be tested regularly rather than assumed to work.
A quarterly review cadence is a reasonable minimum, and every incident should trigger a policy review regardless of the regular schedule. A Fortune 500 travel company treats this as a continuous, platform-driven improvement cycle rather than an annual exercise.
Duty of care in corporate travel is a company's legal and ethical obligation to take reasonable steps to protect employees' health, safety, and security before, during, and after work travel. It applies to domestic and international trips alike, and failing to meet it can expose an organization to negligence claims and regulatory penalties.
In general corporate governance, duty of care refers to a director's fiduciary obligation to act with the care a reasonably prudent person would exercise in managing the company's affairs. In the travel context specifically, that broader governance obligation narrows to a concrete responsibility: protecting employees while they are traveling for company business.
A job description listing "30% travel" means the role requires travel roughly three out of every ten working days. Frequent travelers in this range carry proportionally higher exposure to travel-related risk, and duty of care protections apply to them at the same standard as employees who travel occasionally.
The 4 C's are Cost, Compliance, Convenience, and Care. Care is the duty of care dimension: the obligation to protect traveler health, safety, and security, which sits alongside cost control, policy compliance, and traveler convenience as a core pillar of corporate travel management.
Consider an employee traveling to a city where civil unrest breaks out during the trip. With a program in place: a pre-trip risk assessment had already flagged elevated political risk, the traveler received a briefing, an alert went out when protests escalated, the security team confirmed the traveler's location within about 15 minutes, and alternative accommodation and a rebooked return flight followed. Without a program: the company has no record of the employee's exact location, no communication channel, the employee is stranded for 48 hours, and the company faces legal exposure afterward.
At minimum: a completed destination risk assessment, a pre-trip approval workflow for high-risk locations, a current traveler profile with emergency contacts, confirmed travel insurance, and a delivered safety briefing. The full checklist above adds during-travel and post-travel items to cover the entire trip lifecycle.
Duty of loyalty is a director's fiduciary responsibility to act in the corporation's best interests rather than a personal or conflicting one. It is distinct from duty of care, which concerns the standard of diligence and prudence applied to decisions; loyalty is about whose interests a decision serves, while care is about how carefully that decision was made.
The business judgment rule is a legal protection that shields corporate directors from liability for decisions made in good faith, with reasonable diligence, and without a conflict of interest, even if the decision later turns out badly. Companies that document their travel risk decisions, including what data they reviewed and what risk threshold they applied, are in a stronger position to claim this protection.
A breach of duty occurs when a company fails to take reasonable precautions and that failure directly causes foreseeable harm to a traveling employee. Two examples: sending an employee to a destination with a documented pattern of violent crime without a briefing or emergency plan, or failing to act on a known security threat that later results in an incident.
Base Operations supports corporate travel duty of care programs with street-level threat intelligence rather than country-level or city-level averages. Analysis at sub-mile precision means a security team can compare specific hotels, airports, meeting venues, and restaurants instead of relying on a single risk rating for an entire city. One Fortune 500 travel company put it directly: "Prior to Base Operations, our reporting was limited to country or city-level geopolitical analysis and annual travel ratings. Now granular reporting means we can make informed decisions on where to stay, where to eat, where to entertain."
That granularity feeds directly into pre-trip assessments: destination risk scoring, hotel comparison, and route safety analysis drawing on quantified, neighborhood-level crime data rather than broad estimates. For security teams managing large travel footprints, that intelligence scales without adding headcount. A Fortune 10 company now monitors more than 500 locations in one system, a global consultancy realized a 35% efficiency gain in site assessments, and an AI provider cut executive protection assessment time by 75% while surfacing 25% more threat-related insights.
The larger shift these organizations describe is a change in how the security function is perceived. One Fortune 500 travel company's security team described the change directly: they are no longer relied on just for the latest news reporting, but treated as a concierge for travel recommendations, a shift from reactive reporting to proactive advisory that duty of care programs depend on to stay ahead of risk.
See how Base Operations supports corporate travel duty of care programs.
The strongest programs contact an affected traveler within 12 to 30 minutes of an incident, though the actual figure depends on alert automation, the accuracy of traveler tracking data, and how clearly escalation protocols are defined in advance. Programs that rely on manual, multi-vendor data correlation typically respond slower than those with automated, pre-integrated systems. One AI-enabled security program achieved a 3x improvement in report generation speed after modernizing its intelligence workflow, illustrating how much automation affects response time.
ISO 31030 provides structured guidance across five areas: policy, risk assessment, monitoring, response, and program review. It defines four maturity levels: basic, developing, established, and advanced. A program is compliant to the extent it has documented practices across all five guidance areas and can demonstrate which maturity level it operates at. Despite its relevance, 31% of travel buyers have never heard of the standard, according to BCD Travel, so simply reviewing it against existing policy is often the fastest way to identify gaps.
In most jurisdictions, yes, if the contractor is embedded in company operations and traveling on the company's behalf. Courts generally look at the practical relationship, not just the contract classification, when determining where responsibility falls. The safest approach is to document contractor coverage explicitly in the written duty of care policy rather than leaving it as an assumption.
Travel insurance covers financial risk, such as medical costs or trip cancellation expenses, after something has already gone wrong. Duty of care is the broader obligation to take reasonable steps to prevent harm in the first place, spanning pre-trip risk assessment, in-transit support, and emergency response. Insurance is one component of a duty of care program, not a substitute for the rest of it.
Yes, in most cases responsibility does not fully switch off during personal time attached to a business trip. The company placed the employee in an unfamiliar environment for a business purpose, and emergency support may still be a reasonable expectation during a personal extension of that same trip. Policies should state explicitly what support applies during bleisure travel so there is no ambiguity if an incident occurs.
Costs generally fall into three tiers based on scope of service: technology-only platforms typically run $20 to $35 per traveler per year, technology paired with a 24/7 assistance hotline runs $45 to $70 per traveler per year, and a full package that adds insured medical evacuation runs $90 to $140 per traveler per year. These figures reflect broad industry benchmarks for third-party travel risk services and vary by vendor, traveler volume, and destination risk profile. Organizations that consolidate multiple point solutions into one platform have reported measurable savings; one Fortune 500 travel company achieved $25,000 in annual savings while expanding its program's scope.
Track five indicators: average time to locate a traveler during a crisis, incident response time from alert to resolution, the percentage of travelers who can correctly identify the emergency contact number, policy compliance rate, and post-incident satisfaction scores from affected travelers. A program with strong metrics across all five is demonstrating real operational readiness, not just documented policy.
A company that ignores its duty of care and an employee is harmed faces potential negligence liability, regulatory fines, lawsuits, workers' compensation claims, and reputational damage. The scale can be significant: the 2019 MGM Resorts settlement of up to $800 million following the 2017 Las Vegas mass shooting illustrates how large premises-liability exposure can grow. Companies that document their risk decisions, including the data reviewed and the threshold applied, are generally in a stronger legal position under the business judgment rule than those that made the same call without a paper trail.
Talk to Base Operations about building a data-driven duty of care program.

Join 1100+ security leaders getting new ideas on how to better protect their people and assets.