Duty of Care Compliance: Legal Requirements for Business Travel Programs
TL;DR: Duty of care compliance obligates employers to take reasonable, documented steps to protect business travelers from foreseeable harm. In the US it is anchored in OSHA's General Duty Clause (29 U.S.C. §654(a)(1)); internationally, ISO 31030:2021 sets the auditable travel-risk-management baseline. A defensible program ties pre-trip risk assessment, locate-and-communicate capability, and incident response to written policy — not policy alone.
The Legal Foundations of Duty of Care for Business Travel
Employer duty of care is not a single statute. In the United States, it flows from OSHA's General Duty Clause (29 U.S.C. §654(a)(1)), which requires each employer to furnish "employment and a place of employment which are free from recognized hazards." Federal case law (Jones v. Halliburton Co., 583 F.3d 228, 5th Cir. 2009) has extended that reasoning to foreign deployments where the employer controls the itinerary. In the EU, Framework Directive 89/391/EEC obliges employers to assess all occupational risks, including those from business travel, and the UK's Corporate Manslaughter and Corporate Homicide Act 2007 creates criminal liability for gross management failures. ISO 31030:2021 ("Travel risk management — Guidance for organizations"), published September 2021, is the first international consensus standard that courts and auditors now reference as the duty-of-care benchmark.
What Regulators and Courts Actually Expect
Drawing from 8+ years building AI-powered corporate travel platforms, the compliance patterns that hold up under audit share one trait: documented, auditable processes rather than policies that live only on paper. The GBTA 2024 Risk Management Study found that 83% of travel programs have a written duty-of-care policy, yet only 29% can produce an auditable record of pre-trip risk briefings for every traveler sent to an elevated-risk destination. US courts applying the "reasonable foreseeability" test (see Hoyt v. Gutterz Bowl & Lounge, 2015 WL 5157728) consistently separate programs that react to incidents from programs that demonstrate prior assessment. The practical implication: a traveler-tracking tool with no evidence of pre-trip approval review carries most of the liability of having no program at all. Program maturity, not program existence, is what moves a case.
Comparison: Duty of Care Program Maturity Levels
| Capability | Basic (policy only) | Intermediate | Mature (ISO 31030-aligned) |
|---|---|---|---|
| Pre-trip risk assessment | None or ad hoc | Country-level advisory check | Itinerary-level scoring, documented approval |
| Traveler location data | PNR only | TMC itinerary feed | Real-time GPS + lodging + ground segments |
| Communication | Mass SMS | Two-way confirm-safe, 24/7 | |
| Incident response | HR hotline | Third-party assistance line | Documented SLA, after-action review |
| Audit trail | Policy document | Approval emails | Immutable log tied to each trip |
| Typical annual cost (1,000 travelers) | <$10,000 | $40,000–$90,000 | $120,000–$250,000 |
Building a Defensible Compliance Program
A defensible program maps to five ISO 31030 clauses: context (5.2), risk assessment (6.2), risk treatment (6.3), communication (7), and monitoring and review (8). Operationally, that translates into a documented traveler-approval workflow, a locate-and-communicate layer that captures every segment (not just the TMC-booked flight), and a post-trip review that feeds back into the risk register. The GSA's Federal Travel Regulation (41 CFR Chapters 300-304) imposes parallel obligations on federal contractors and sets a usable template: pre-trip authorization, itemized itinerary, duty-station documentation, and incident reporting through SF-91. For multinational programs, GDPR Article 6(1)(f) legitimate-interest balancing must support any traveler-location processing — a written DPIA is now expected by EU data protection authorities. Technology choice follows the policy; the Travel Code duty of care hub covers the operational playbook in depth.
Jurisdictional Variations: US, EU, and APAC
Compliance obligations fragment at the border. In the US, OSHA enforcement is complaint-driven and civil, but state workers' compensation statutes (particularly California Labor Code §3600.5 and New York WCL §17) extend coverage to employees on business travel without a required nexus to the state of hire. The EU operates on a prescriptive model: employers must document a risk assessment for every category of foreseeable hazard, and failure to do so is itself a sanctionable offense regardless of outcome. The UK adds criminal exposure through the 2007 Corporate Manslaughter Act. In APAC, Australia's model Work Health and Safety Act 2011 §19 imposes a non-delegable "primary duty of care" that explicitly covers travel; Japan's Industrial Safety and Health Act applies the anzen hairyo gimu (safety consideration obligation) through civil case law (Dentsu case, Supreme Court 2000). A single global policy that ignores these differences fails on first contact with a local regulator.
How Technology Supports Duty of Care Compliance
Audit-grade compliance requires evidence that spans TMC itineraries, direct bookings, hotel folios, and ground transport — the segments that typically fall outside a traditional managed program. BYOD overlay platforms address this by sitting across booking channels and capturing a unified trip record without forcing travelers off their preferred booking tools. Travel Code's overlay, for example, continuously re-shops rates (RateGuard, priced at 25% of validated savings) while feeding the same itinerary data into a real-time duty-of-care layer, so pre-trip approval, traveler location, and after-the-fact audit evidence all draw from one source of truth. Comparable approaches are discussed in the business travel safety risk categories guide. The buying lesson from the GBTA 2024 study is that integration beats breadth: three well-integrated signals beat seven stand-alone dashboards.
Frequently Asked Questions
What is duty of care in business travel?
Duty of care is the employer's legal and ethical obligation to take reasonable steps to protect employees from foreseeable harm while traveling for work. In the US it is enforced under OSHA's General Duty Clause and state workers' compensation statutes; internationally, ISO 31030:2021 provides the auditable framework.
Is ISO 31030 certification required by law?
No. ISO 31030 is a guidance standard, not a mandatory certification. However, since its publication in September 2021, courts, insurers, and procurement teams increasingly treat alignment with ISO 31030 as the benchmark for "reasonable" duty of care — meaning programs that deviate must justify the gap in writing.
Who is legally responsible when a business traveler is harmed abroad?
Primary liability rests with the employer under the "reasonable foreseeability" standard. US case law (Jones v. Halliburton, 2009) confirms that employer responsibility travels with the itinerary. Third-party vendors — TMCs, assistance providers, booking platforms — may share liability if their contracted scope included the failed function. See the Travel Code duty of care hub for contract-language templates.
How does GDPR affect duty-of-care tracking of EU employees?
GDPR Article 6(1)(f) permits traveler-location processing on legitimate-interest grounds, but employers must complete a Data Protection Impact Assessment (DPIA), define a retention period (CNIL guidance recommends ≤30 days post-trip for granular GPS), and offer travelers transparent opt-out from non-safety-critical use. Covert tracking is not compliant.
What documentation does a compliant duty-of-care program maintain?
Six artifacts: (1) a written policy approved by the board or executive sponsor, (2) a documented risk assessment per destination tier, (3) pre-trip approval records tied to each itinerary, (4) traveler communication logs, (5) incident reports and after-action reviews, and (6) an annual program audit. Reference policy templates are available in the business travel policy examples library.
Do small and mid-market companies have the same duty of care obligations?
Yes. OSHA's General Duty Clause and ISO 31030 do not scale by headcount. The standard for "reasonable" steps scales with program complexity and traveler exposure, but a 50-person company sending consultants to elevated-risk destinations carries essentially the same core obligations as a Fortune 500. Lightweight overlays and shared-service assistance providers are how smaller programs close the gap without a six-figure budget.
How often should a duty-of-care program be reviewed?
ISO 31030 clause 8.2 requires monitoring that reflects material change in travel patterns or threat environment. GBTA's 2024 guidance recommends a full policy review annually, risk-register refresh quarterly, and an after-action review within 30 days of any serious incident. Programs that review only after an incident consistently fail the "reasonable foreseeability" test.
Sources
- OSHA General Duty Clause, 29 U.S.C. §654(a)(1)
- ISO 31030:2021, Travel risk management — Guidance for organizations
- GBTA 2024 Risk Management Study
- EU Framework Directive 89/391/EEC on health and safety at work
- UK Corporate Manslaughter and Corporate Homicide Act 2007
- Jones v. Halliburton Co., 583 F.3d 228 (5th Cir. 2009)
- GSA Federal Travel Regulation, 41 CFR Chapters 300-304
- CNIL guidance on employee geolocation (France, 2022 update)
- Australia Work Health and Safety Act 2011, §19
- Supreme Court of Japan, Dentsu case (2000) on anzen hairyo gimu