Duty of Care Legal Requirements for Employers: The Complete Compliance Guide

Comprehensive guide to employer duty of care legal requirements: OSHA, UK HSWA, ISO 31030, breach consequences, travel and remote worker obligations, and a step-by-step compliance framework.

Duty of Care Legal Requirements for Employers: The Complete Compliance Guide

Duty of Care Legal Requirements for Employers: The Complete Compliance Guide

What Is the Legal Duty of Care for Employers?

The legal duty of care for employers is the obligation to take reasonable steps to protect the health, safety, and wellbeing of employees while they work. It is enforceable through occupational health and safety statutes, common law negligence, and contract law. An employer who fails to meet this standard and causes harm can face regulatory penalties, criminal liability, and civil damages claims.

This duty is not optional and it is not limited to the physical workplace. It follows employees into the field, onto business trips, and into home offices. It covers physical hazards, psychological harm, and security risks across every location where people perform work on the employer's behalf.

The Legal Definition of Duty of Care

In tort law, duty of care describes a legal relationship in which one party must avoid causing foreseeable harm to another. The concept traces to Donoghue v Stevenson [1932], the case that established the modern "neighbour principle": you owe a duty to those who would be closely and directly affected by your acts. For employers, that neighbour is the employee.

Establishing a breach requires four elements to line up in sequence:

  1. A duty of care existed between the parties.
  2. The duty was breached.
  3. The breach caused harm.
  4. The harm is measurable.

When all four are present, liability follows. The Cornell Law definition frames duty of care as the degree of attentiveness and caution a reasonable person would exercise in a given situation. For employers, the law translates "reasonable person" into "reasonable employer," judged against what a competent organization in the same sector would have done.

Duty of Care as a Legal vs. Moral Obligation

A legal duty of care is statutory and enforceable. Regulators issue citations, courts award damages, and prosecutors can pursue criminal charges when breaches are severe. A moral duty of care is the ethical expectation that an organization will protect its people because it is the right thing to do, with reputational consequences when it fails.

Both carry practical business cost. The legal obligation sets the floor that keeps the organization out of court. The moral obligation shapes whether employees, customers, and investors trust the company. Treating duty of care as only a compliance checkbox misses how directly it now affects talent retention, brand value, and the cost of capital.

What Are the Four Main Principles of Employer Duty of Care?

The four main principles of employer duty of care are the four legal elements a claimant must prove to establish negligence: a duty existed, the standard of care was breached, the breach caused harm, and measurable damage resulted. Each principle has a specific employer-context meaning.

PrincipleEmployer-Context Explanation
Duty of care existedA legal relationship between employer and worker created an obligation to protect health, safety, and wellbeing. This relationship is presumed in employment and extends to contractors and travelers under the employer's direction.
Standard of care was breachedThe employer failed the "reasonable employer" test by not taking precautions a competent organization in the same sector would have taken, such as conducting a risk assessment or providing training.
Causation was establishedThe breach directly caused the harm. The claimant must show the injury would not have happened, or would have been less severe, if the employer had met the standard.
Measurable damage resultedA real, quantifiable loss occurred: physical injury, psychiatric harm, financial loss, or death. Without measurable damage, a negligence claim does not succeed.

These four principles apply identically whether the harm happened on a factory floor, in a hotel abroad, or at a home workstation. The location changes the facts. It does not change the test.

The Legal Framework: Key Laws Governing Employer Duty of Care

Employer duty of care is codified differently across jurisdictions, but the underlying standard is consistent: take reasonable, practicable steps to prevent foreseeable harm. Organizations with operations in more than one country must comply with each jurisdiction's specific statutes, not a single global rule. The sections below cover the major frameworks corporate security and compliance teams encounter.

United States: OSHA and the General Duty Clause

In the United States, the Occupational Safety and Health Act of 1970 anchors employer duty of care. Section 5(a)(1), known as the General Duty Clause, requires every employer to provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." This clause covers hazards that have no specific OSHA standard, which makes it a broad and frequently cited basis for enforcement.

Penalties scale with severity. In 2024, a willful or repeat violation carries a maximum penalty of $161,323 per violation, while serious and other-than-serious violations top out at $16,131 each. Twenty-two states operate their own OSHA-approved plans that meet or exceed federal requirements, so the applicable standard depends on where the workplace sits.

Two companion statutes extend the obligation. The Americans with Disabilities Act (ADA) requires reasonable accommodation for employees with disabilities, including mental health conditions. The Family and Medical Leave Act (FMLA) protects job security during qualifying medical and family leave. Together with OSHA, they define a large part of the U.S. employer's legal duty.

United Kingdom: Health and Safety at Work Act 1974

The Health and Safety at Work etc. Act 1974 (HSWA) is the cornerstone of UK duty of care. It requires employers to ensure, "so far as is reasonably practicable," the health, safety, and welfare of employees. The Management of Health and Safety at Work Regulations 1999 make risk assessment an explicit legal requirement.

The "reasonably practicable" standard asks employers to weigh the risk against the cost, time, and effort of removing it. A serious risk demands action even when the remedy is expensive. The Corporate Manslaughter and Corporate Homicide Act 2007 raises the stakes further: an organization whose gross failure in management causes a death can face an unlimited fine and a publicity order. The Health and Safety Executive (HSE) enforces these duties, with unlimited fines for serious breaches and the possibility of imprisonment for individuals.

Australia: Work Health and Safety Act 2011

Australia's Work Health and Safety Act 2011 places a "primary duty of care" on a "person conducting a business or undertaking" (PCBU). The PCBU must ensure, so far as is reasonably practicable, the health and safety of workers and others affected by the work.

A significant change took effect in April 2023, when model WHS regulations made the management of psychosocial hazards an explicit requirement within mandatory risk assessments. Employers must now identify and control hazards such as excessive workload, bullying, and exposure to traumatic content with the same rigor applied to physical hazards. Safe Work Australia sets national policy, while state and territory regulators handle enforcement.

Canada: Provincial OH&S Acts and Bill C-45

Canada distributes occupational health and safety authority across federal and provincial levels. The Canada Labour Code Part II governs federally regulated workplaces, while each province and territory maintains its own occupational health and safety act for everyone else.

Bill C-45, often called the Westray Law after the 1992 mining disaster that prompted it, amended the Criminal Code in 2004 to impose criminal liability on organizations and individuals for gross negligence that causes injury or death. It established a legal duty for anyone directing work to take reasonable steps to prevent bodily harm, and it made corporations prosecutable for criminal negligence. The law signaled that severe duty of care failures in Canada can be treated as crimes, not just regulatory matters.

International Standards: ISO 45001 and ISO 31030

Beyond national law, two international standards shape how organizations operationalize duty of care. ISO 45001:2018 is the global benchmark for occupational health and safety management systems. It is not itself a law, but it is increasingly written into contracts, procurement requirements, and insurance terms, which gives it practical force. Certification signals that an organization has a structured, auditable approach to identifying and controlling workplace risk.

ISO 31030 is the travel risk management standard, and it is the one most directly relevant to organizations with mobile workforces. Published as guidance, it sets out how to manage risk to traveling employees across the full trip lifecycle. Its operational requirements include pre-trip risk assessment, ongoing review of the threat landscape, a 24/7 assistance capability, and a post-trip review. The standard's reference to ongoing threat review means maintaining current visibility into the risk environment at travel destinations. Persistent threat landscape intelligence, refreshed on a regular cadence, is what supports that requirement, distinct from event-driven alerting which the standard treats as a separate response capability. Fewer than three competing resources cover ISO 31030 at any depth, which leaves a gap for organizations that want practical guidance on aligning a travel risk program with the standard.

Five Core Responsibilities Employers Have Under Duty of Care

Duty of care converts into five core responsibilities that recur across every major jurisdiction. Meeting them is how an employer demonstrates the "reasonable steps" the law requires.

1. Conducting Regular Risk Assessments

The first responsibility is to identify hazards before they cause harm. A complete risk assessment covers physical, chemical, ergonomic, psychosocial, security, and travel or destination-specific risks. In the UK, risk assessment is legally mandatory for any employer with five or more employees, and the same expectation runs through OSHA, the Australian WHS Act, and Canadian provincial law.

Scale makes this hard. One Fortune 10 company needed to assess employee safety across more than 500 offices in 35 countries under return-to-office time pressure, and its existing tools took weeks per location, which created liability exposure while assessments sat incomplete. A Fortune 100 e-commerce and technology company faced the same problem across 441 global locations, where a security manager described the manual approach as unsustainable: leadership wanted more regular updates, and the work was consuming bandwidth the team needed elsewhere. Continuous, location-specific risk scoring addresses this gap. BaseScore™ provides a standardized 0-100 risk score for each location, refreshed monthly, so teams can compare sites and prioritize the highest-risk ones with data rather than guesswork.

2. Implementing Preventive and Protective Measures

Identifying a hazard creates an obligation to control it. The hierarchy of controls runs from engineering solutions and safe systems of work through to personal protective equipment, which OSHA requires employers to provide at no cost to the worker. For mobile and lone workers, controls include lone-worker protocols and documented travel security plans.

Documentation matters as much as the measure itself. A control the employer cannot prove it implemented offers little legal defense after an incident. Location-specific security recommendations, tied to the actual risk profile of each site, give organizations a defensible record of what they did and why. The same intelligence that drives a Fortune 500 travel company's executive protection program lets security teams match protective measures to the specific threats at each location rather than applying a single generic policy everywhere.

3. Providing Safety Training and Ensuring Competency

Employers must ensure workers are competent to do their jobs safely. Training has to be role-specific, repeated on a regular schedule, and documented. OSHA requires training records to be maintained and accessible. For travelers, this responsibility includes pre-trip briefings on destination-specific risks so employees understand the environment they are entering.

Traveler briefing materials grounded in current destination intelligence turn this from a box-ticking exercise into genuine preparation. One leading technology provider standardized its executive protection memos so every briefing followed the same structure and drew on the same quality of data, which made training consistent across the program and easier to audit.

4. Establishing Worker Consultation and Reporting Channels

Workers must be able to raise safety concerns without fear of retaliation. This means formal mechanisms, not just an open-door promise. In the United States, Section 11(c) of the OSH Act protects employees who report hazards from retaliation. In the United Kingdom, the Public Interest Disclosure Act 1998 provides equivalent whistleblower protection.

Effective consultation also surfaces hazards the employer might otherwise miss. The people doing the work often see emerging risks first, and a reporting channel that workers trust turns that frontline knowledge into early warning.

5. Emergency Preparedness and Crisis Response

The final responsibility is to plan for the situations risk assessment cannot fully prevent. Documented emergency plans must cover fire, medical emergencies, natural disasters, and, for traveling employees, travel crises such as political unrest, terrorism, and disease outbreaks. In the United States, OSHA standard 29 CFR 1910.38 sets specific requirements for written emergency action plans. ISO 31030 calls for a 24/7 assistance capability for travelers.

Strong preparation reduces how often crisis response is needed at all. A Fortune 500 travel company shifted its security function from reactive incident reporting toward concierge-level travel security, using better intelligence to inform decisions before trips rather than scrambling after something went wrong. Proactive risk visibility does not replace emergency response, but it shrinks the number of emergencies that reach it.

Duty of Care for Traveling and Remote Employees

Duty of care follows the employee wherever work takes them. A business trip and a home office are not exceptions to the obligation. They are extensions of it, and courts treat them that way.

The Legal Basis for Duty of Care During Business Travel

The same reasonable-care standard that applies in the office applies on the road. In Palfrey v. Ark Offshore Ltd., an employer was found liable after an employee died of malaria contracted on an overseas assignment, because the employer had failed to provide adequate health protection and advice. The case is a clear precedent: sending someone to a higher-risk destination without proper assessment and preparation is a breach.

More than 50 countries now have duty of care laws that cover business travelers, so the obligation is not confined to the employer's home jurisdiction. Employees feel the gap when it is not met. In a SAP Concur survey, 58% of business travelers said they had changed travel arrangements because of safety concerns, and 52% named travel safety as the most valuable form of training their employer could provide. Duty of care for travelers is both a legal requirement and a factor in whether employees are willing to travel at all.

What Duty of Care Looks Like in Practice for Business Travel

In practice, travel duty of care follows the lifecycle that ISO 31030 lays out. Each phase carries its own obligations:

PhaseWhat the Employer Must Do
1. Pre-trip risk assessmentAssess the destination using current crime, unrest, and environmental data at the neighborhood level, not just a country-level advisory.
2. Pre-travel briefing and trainingBrief the traveler on specific risks, local context, and protocols before departure, and document it.
3. Threat landscape visibility during travelMaintain current awareness of the destination's risk profile and a means to reach the traveler if conditions change.
4. 24/7 emergency response capabilityProvide a way for travelers to reach assistance at any hour, through internal resources or an assistance provider.
5. Post-trip debrief and program reviewCapture lessons, update the risk picture, and improve the program for the next trip.

A complete travel security assessment walks through these phases in detail, from defining the destination through hotel risk scoring, neighborhood analysis, and traveler briefing materials. A threat intelligence platform delivers phases 1 through 3 directly by supplying the destination intelligence and risk scoring those phases depend on, and it provides the data infrastructure that makes phases 4 and 5 work. A Fortune 500 travel company assessed more than 300 locations in a single year this way, evolving its travel briefs from high-level city summaries into location-specific security recommendations.

Duty of Care for Remote Workers

Duty of care applies to home-based workers. The obligation does not switch off because the work happens outside a company building. Employers are expected to provide ergonomic guidance, mental health support, emergency preparedness information, and cybersecurity training for remote staff. The standard is "reasonable steps" applied to what the employer can actually control: the employer cannot inspect every home, but it can provide guidance, equipment stipends, and support.

For distributed workforces that operate in the field rather than at home, the duty extends to the locations employees travel through and work in. A healthcare leader managing in-home clinicians built a standardized security framework that scored risk down to the ZIP-code level across all service territories, replacing inconsistent regional efforts with one data-driven approach. The same logic covers the commute. A commute safety assessment evaluates route-specific crime patterns and transit-stop safety, which is exactly the kind of foreseeable risk an employer is expected to consider when it asks people to come into an office.

Tailoring Duty of Care to Destination Risk

A one-size-fits-all policy is legally insufficient. The reasonable-employer standard expects precautions to match the actual risk, which means calibrating duty of care to the destination, the employee, and the assignment. Destination factors include political stability, healthcare quality, crime levels, and exposure to natural disasters. Employee factors include health conditions, and assignment factors include duration and activity. A CEO attending meetings in Switzerland and an engineer deploying to a conflict zone do not require the same plan, and treating them identically exposes the employer on both ends.

Failure to account for destination-specific risk is itself a basis for negligence claims, because it shows the employer did not take the reasonable step of assessing what the employee actually faced. Granular intelligence supports this calibration. The same approach used for executive protection risk assessment, working from city-wide context down through hotel comparison, neighborhood analysis, and crime-type filtering, lets an organization justify why one trip warranted enhanced measures and another did not. A reinsurance executive captured the discipline behind this when reviewing the company's risk exposure: there was no value in investing attention in a region where the organization had no people and no underwriting exposure. Matching risk intelligence to actual exposure is what separates a defensible program from a generic one.

Duty of Care for Employee Mental Health

Employee mental health is now part of the legal duty of care, not a discretionary wellness perk. Courts and regulators increasingly treat psychological harm the same way they treat physical injury, and the trend is expanding.

The Legal Basis for Mental Health Duty of Care

The precedent runs back to Walker v Northumberland County Council [1995], in which an employer was held liable for the psychiatric harm a social worker suffered after a foreseeable second breakdown caused by excessive workload. The case established that employers can be liable for psychiatric injury when the harm is foreseeable and they fail to act.

Statutory obligations reinforce the case law. The UK Equality Act 2010 and the U.S. ADA both require reasonable adjustments or accommodations for employees with mental health disabilities. Australia's April 2023 WHS changes went further by mandating explicit psychosocial hazard risk assessments. The scale of the problem explains the legal momentum: roughly 1 in 4 people in England experience a mental health problem each year, and poor mental health costs U.S. businesses an estimated $108 billion annually through lost productivity and absence.

What Constitutes a Psychosocial Hazard Under the Law

A psychosocial hazard is any aspect of work design or management that can cause psychological harm. Regulators have moved these from the category of soft HR issues into the category of assessable workplace hazards. The recognized hazards include:

  • Excessive workload and unrelenting time pressure
  • Low job control or autonomy
  • Poor role clarity
  • Bullying, harassment, and workplace violence
  • Exposure to traumatic content or events
  • Poorly managed organizational change

Framed correctly, these are employer obligations to identify and control, not suggestions to consider. An organization that knows a role exposes workers to traumatic content, for example, and does nothing to manage that exposure, is failing a duty in the same way it would by ignoring a faulty machine.

Employee Assistance Programs and the Duty of Care

Employee assistance programs (EAPs) are not universally mandated, but failing to provide access to support can constitute a breach when the psychological risk is foreseeable. If an employer knows a role carries significant mental health risk and offers no support pathway, that absence becomes evidence of an unreasonable response.

The business case reinforces the legal one. Access to mental health support reduces absenteeism, lowers stress-related turnover, and improves retention. Anchoring EAPs in legal risk reduction, rather than treating them as a benefits-brochure line item, reframes them as part of the organization's defense against foreseeable psychological harm.

What Constitutes a Breach of Duty of Care?

A breach of duty of care occurs when an employer fails to meet the standard a reasonable employer would have met, and that failure causes measurable harm. Establishing a breach is a structured legal test, not a judgment call.

The Legal Test for Establishing Negligence

Negligence requires four elements, applied in order:

  • Duty: The employer owed the worker a duty of care. In employment this is presumed.
  • Breach: The employer failed the objective "reasonable employer" standard, judged against what a competent organization in the same sector would have done, not against the employer's own intentions.
  • Causation: The breach directly caused the harm. The claimant must show the injury would not have occurred, or would have been less severe, but for the breach.
  • Damage: Measurable harm resulted, whether physical, psychiatric, or financial.

The standard is objective. An employer who genuinely believed it was doing enough still breaches the duty if a reasonable organization would have done more.

Common Examples of Duty of Care Breaches

Breaches appear across every work context. The table below maps common categories to concrete failures.

CategoryExample of Breach
WorkplaceFailing to maintain equipment, leaving a known mechanical hazard unaddressed.
TravelSending an employee to a high-risk destination without a risk assessment, the failure at the center of the Palfrey precedent.
Mental HealthIgnoring a reported hazard or failing to act on known bullying after it was raised.
Remote WorkProviding no ergonomic support or guidance to home-based staff.

The common thread is foreseeability. In each case the risk was knowable in advance, and the breach was the failure to take a reasonable step that would have addressed it. Scattered, slow assessment tools contribute directly to this exposure, because they leave hazards unassessed for longer and make it harder to prove the employer acted with reasonable diligence.

5 Examples of Unsafe Conditions in the Workplace

Five conditions recur in unsafe-workplace claims:

  1. Unguarded or poorly maintained machinery.
  2. Slip, trip, and fall hazards from spills, clutter, or poor maintenance.
  3. Hazardous substance exposure without proper controls or ventilation.
  4. Excessive noise above safe exposure limits.
  5. Inadequate fire safety measures, including blocked exits and missing equipment.

Each represents a recognized hazard under OSHA's General Duty Clause and its UK and Australian equivalents. An employer aware of any of these and slow to act is exposed to both regulatory citation and a negligence claim.

The Consequences of Breaching Employer Duty of Care

The consequences of breaching duty of care fall into two categories: direct legal and financial penalties, and the slower but often larger reputational and operational damage. Together they make the business case for compliance unambiguous.

Legal and Financial Penalties

Regulatory penalties are substantial and rising. In the United States, 2024 OSHA penalties reach $161,323 per willful or repeat violation. In the United Kingdom, the HSE reports an average cost of around $8,800 for a non-fatal injury, while the most serious cases have drawn fines near $10 million, and the agency maintains a conviction rate above 90% in the cases it prosecutes.

Regulatory fines are only the first layer. Civil negligence claims sit on top of them, brought directly by injured employees or their families, and these can far exceed the regulatory penalty. An organization that breaches its duty can therefore face a citation, a civil judgment, and, in severe cases under laws like the UK Corporate Manslaughter Act or Canada's Bill C-45, criminal prosecution.

Reputational and Operational Consequences

The reputational cost reaches further than the courtroom. Surveys show that 97% of employees consider safety a key factor in deciding where to work, which ties duty of care directly to recruitment and retention. On the customer side, research from Qualtrics found that 1 in 4 consumers stopped buying from brands they judged to have insufficient safety practices. Poor safety records also feed into ESG ratings and weigh on investor confidence.

There is an upside to handling this well. The same Fortune 500 travel company that strengthened its travel security program elevated security from a cost center into a strategic advisor that leadership consulted on major decisions. Meeting duty of care obligations rigorously is not just risk avoidance. Done with good data, it becomes a source of organizational credibility.

What Managers Are Not Allowed to Do Under Duty of Care

Duty of care imposes specific prohibitions on managers. Under the obligation, a manager cannot:

  • Direct untrained employees into tasks they are not competent to perform safely.
  • Ignore hazards that workers have formally reported.
  • Retaliate against employees who raise safety concerns.
  • Send employees to high-risk locations without a documented risk assessment.
  • Require working hours that induce dangerous fatigue.
  • Discriminate against employees because of a mental health condition.

Each prohibition maps to a recognized legal duty, and crossing any of them can convert routine management into a breach.

How to Build a Compliant Duty of Care Program: Step-by-Step

Building a compliant duty of care program is a six-step process that moves from understanding legal obligations to operating a continuously improving system. The steps below give security and compliance teams a practical sequence.

Step 1: Gap Analysis and Legal Register

Start by auditing current programs against statutory requirements. Build a legal register that lists every obligation the organization faces, jurisdiction by jurisdiction, because each country requires separate analysis. For a multinational, this can mean tracking obligations across 190 or more jurisdictions, which is a common enterprise challenge. The Fortune 100 e-commerce company managing 441 locations found that doing this manually became unsustainable as its program matured and leadership demanded more frequent updates. A gap analysis exposes where current practice falls short of legal requirement, which is where the program work begins.

Step 2: Risk Assessment Across All Work Contexts

Assess risk in every context where work happens: the office, the home, business travel destinations, long-term overseas postings, and contractor sites. A single workplace assessment is no longer enough when the workforce is distributed. The framework below structures the assessment by context.

Work ContextPrimary Risk Focus
Office sitesPhysical hazards, fire safety, security of premises
Remote and homeErgonomics, mental health, cybersecurity, lone working
Business travelDestination crime and unrest, health risks, transport safety
Long-term overseasPolitical stability, healthcare access, sustained environmental risk
Contractor and field sitesSite-specific hazards, route safety, third-party coordination

The scale challenge is real. One Fortune 10 company assessed more than 500 offices across 35 countries, a healthcare leader scored risk across 300 ZIP codes for its distributed workforce, and commute-route analysis added another layer for return-to-office planning. Standardized, location-specific scoring is what makes assessment at this scale manageable.

Step 3: Policy Development and Documentation

Translate the assessment into a written duty of care policy. The policy must define its scope clearly, covering employees, contractors, and interns, and it must address risk categories, training requirements, incident reporting, emergency response, travel risk management, and mental health support. A documented policy is both a management tool and a legal artifact: it demonstrates the organization identified its obligations and set out how it would meet them.

Step 4: Training, Communication, and Worker Consultation

A policy that workers do not understand provides little protection. Employers have an obligation to communicate so that workers know their rights and responsibilities, and all training must be documented. Where the law requires them, safety committees give workers a formal consultation channel. Traveler briefing materials, drawn from current destination intelligence, are a concrete example of training that meets a specific legal duty rather than a generic safety module.

Step 5: Technology, Monitoring, and Response

Modern duty of care requires a technology layer that earlier steps depend on. A complete program needs traveler tracking, threat intelligence that combines a persistent view of the threat landscape with event-driven alerting, alerts from the appropriate platforms, and a 24/7 emergency response capability. The key is to map each technology requirement back to the legal obligations established in the earlier sections, so the stack exists to satisfy duties, not for its own sake.

This is where the distinction between two kinds of intelligence matters. Base Operations provides persistent street-level threat intelligence: 25,000+ data sources aggregated into more than 150 million mapped incidents, refreshed monthly with sub-mile granularity and trend analysis, so teams can understand and forecast the risk environment at every location in their footprint. Event-driven, time-sensitive alerts about unfolding incidents come from complementary platforms such as Dataminr, Everbridge, and AlertMedia. A mature program runs both: the persistent intelligence layer to assess and prioritize risk, and the alerting layer to respond to events as they happen. The payoff from getting the intelligence layer right is concrete. One leading AI provider cut executive protection assessment time by 75% while increasing the insights each assessment produced and tripling the speed of standardized recommendations. A Fortune 10 company replaced scattered tools with a unified intelligence platform across hundreds of sites, and a Fortune 500 travel company assessed more than 300 locations in a year on the same foundation.

See how Base Operations operationalizes duty of care compliance for traveling employees. Request a demo.

Step 6: Continuous Improvement and Audit

Duty of care is not a one-time project. Risk assessments need updating at least annually and after any incident, with post-incident investigation feeding corrective actions that the organization tracks to completion. Auditing the program against ISO 45001 or an equivalent framework provides external structure and evidence of diligence. A global consultancy that standardized its assessment process achieved a 35% efficiency lift within three months, a measurable transformation that also created the consistent records an audit requires. A healthcare leader used predictive risk modeling to anticipate seasonal fluctuations, which moved the program from reacting to last year's incidents toward preparing for next quarter's.

Duty of Care Compliance vs. Proactive Risk Management: What's the Difference?

Duty of care compliance is the legal minimum: doing enough to avoid liability. Proactive risk management goes beyond the floor to actively reduce risk before it materializes. Courts and regulators increasingly look for the second, because reactive compliance is becoming harder to defend as a "reasonable" standard. The table below maps the difference across five dimensions.

DimensionMinimum Legal ComplianceProactive Risk Management
Risk AssessmentPeriodic, scheduled reviewsContinuous, data-driven scoring with monthly updates and trend analysis
Threat IntelligenceStatic destination advisoriesPersistent threat landscape intelligence combined with event-driven alerts
Employee CommunicationGeneric pre-trip briefingBriefings informed by current threat data, plus event-driven alerts from alerting platforms
Emergency Response24-hour callbackRapid response capability through 24/7 assistance providers
DocumentationAnnual reviewAudit trail captured per incident

The direction of travel is clear. Regulators and courts now look for evidence that an employer was actively identifying hazards, not merely responding after harm occurred. AlertMedia's framework describes three types of employer along this spectrum: the Uninformed, the Bare Minimum, and the Employee-First organization. Only the last is consistently defensible. A logistics security leader put the contrast plainly when describing the shift his team wanted: proactively assessing risk instead of staying on defense and waiting for the next bad thing to happen. The same move repeats across organizations that have made it, like the global consultancy that went from cost center to strategic partner once its risk process became data-driven.

Persistent threat landscape intelligence, with monthly updates, sub-mile granularity, and 25,000+ data sources, is what enables the shift from reactive to proactive, complemented by event-driven alert platforms for in-trip response.

Move from reactive compliance to proactive risk management. Explore Base Operations for corporate security.

OSHA Requirements for Employers: Key Standards Explained

For U.S. employers, OSHA defines the core of workplace duty of care. The General Duty Clause and supporting standards set obligations that every covered employer must meet. The primary requirements include:

  • Provide a workplace free from recognized serious hazards, as required by the General Duty Clause, Section 5(a)(1).
  • Comply with all applicable OSHA standards for the industry and hazards present.
  • Examine workplace conditions to confirm they conform to OSHA standards.
  • Provide and pay for required personal protective equipment.
  • Train workers on hazards in a language and vocabulary they understand, and keep training records.
  • Maintain accurate records of work-related injuries and illnesses.
  • Display the official OSHA poster informing workers of their rights.
  • Provide a way for workers to report hazards without fear of retaliation, protected under Section 11(c).

These obligations apply alongside any stricter standards in the 22 states that run their own OSHA-approved plans.

Frequently Asked Questions

What is the legal definition of duty of care?

Duty of care is the legal obligation to take reasonable steps to avoid causing foreseeable harm to another party. The concept comes from tort law and the 1932 case Donoghue v Stevenson. For employers, it means taking reasonable, practicable measures to protect the health, safety, and wellbeing of employees while they work. A breach requires four elements: a duty existed, it was breached, the breach caused harm, and the harm is measurable.

What are the four main principles of duty of care?

The four main principles are the legal elements needed to prove negligence. First, a duty of care existed between the parties. Second, that duty was breached against the standard of a reasonable employer. Third, the breach directly caused harm. Fourth, measurable damage resulted, whether physical, psychiatric, or financial. All four must be present for liability to follow, and the same test applies in the office, on business travel, and in a home office.

What are five responsibilities of employers under duty of care?

Employers have five core responsibilities: conducting regular risk assessments across all hazard types, implementing preventive and protective measures, providing role-specific safety training and ensuring competency, establishing worker consultation and reporting channels free from retaliation, and maintaining emergency preparedness and crisis response plans. These responsibilities recur across U.S., UK, Australian, and Canadian law and apply to office, remote, and traveling employees.

Does duty of care apply to remote and traveling employees?

Yes. Duty of care follows the employee wherever work takes them. For travelers, the Palfrey v. Ark Offshore Ltd. case confirmed employer liability when an employee died after a high-risk assignment, and more than 50 countries have laws covering business travelers. For remote workers, employers must provide ergonomic guidance, mental health support, emergency preparedness, and cybersecurity training, applying the "reasonable steps" standard to what the employer can control.

What happens if an employer breaches their duty of care?

An employer that breaches duty of care can face regulatory penalties, civil negligence claims, and, in severe cases, criminal prosecution. In 2024, OSHA willful violations carry penalties up to $161,323 each, and UK serious cases have drawn fines near $10 million. Injured employees can also bring civil claims that exceed regulatory fines. Reputational consequences follow too, affecting recruitment, customer trust, and investor confidence.

Is a duty of care policy legally required?

A standalone written "duty of care policy" is not always mandated by a single statute, but the underlying obligations it documents are legally required. UK law mandates risk assessments for employers with five or more employees, OSHA requires written emergency action plans, and Australia mandates psychosocial hazard assessments. A documented policy is the practical way to demonstrate the organization identified and addressed these legal duties, and it serves as evidence of diligence.

What is the difference between duty of care and negligence?

Duty of care is the obligation itself: the responsibility to take reasonable steps to protect others from foreseeable harm. Negligence is the legal failure to meet that obligation when the failure causes measurable damage. Put simply, duty of care is the standard, and negligence is the breach of that standard. An employer cannot be negligent without first owing a duty of care, and proving negligence requires showing the duty existed, was breached, caused harm, and produced loss.

How does ISO 31030 relate to duty of care for business travelers?

ISO 31030 is the international travel risk management standard, and it gives employers a structured way to meet duty of care obligations for traveling employees. It covers the full trip lifecycle: pre-trip risk assessment, ongoing review of the destination threat landscape, a 24/7 assistance capability, and a post-trip review. Following ISO 31030 helps an organization demonstrate it took the reasonable, documented steps the law expects when sending employees to assess and manage travel risk.

What is an employer not allowed to do under duty of care?

Under duty of care, an employer or manager cannot direct untrained employees into unsafe tasks, ignore formally reported hazards, retaliate against workers who raise safety concerns, send employees to high-risk locations without a documented risk assessment, require fatigue-inducing working hours, or discriminate against employees with mental health conditions. Each prohibition maps to a recognized legal duty, and crossing any of them can constitute a breach that supports a negligence claim.

How does duty of care differ across countries?

The core standard is consistent across countries, but the statutes differ. The U.S. relies on OSHA's General Duty Clause; the UK uses the Health and Safety at Work Act 1974 with a "reasonably practicable" test; Australia's WHS Act 2011 imposes a "primary duty of care" and now mandates psychosocial hazard assessment; and Canada combines provincial OH&S acts with criminal liability under Bill C-45. Multinationals must comply with each jurisdiction separately, which is why a per-country legal register is the foundation of a compliant program.

Takeaways

Subscribe to newsletter

Join 1100+ security leaders getting new ideas on how to better protect their people and assets.