September 8, 2026

Duty of Care for Business Travel: Employer Legal Obligations & ISO 31030 Checklist

Duty of Care for Business Travel: Employer Legal Obligations & ISO 31030 Checklist

TL;DR — Duty of care in business travel is the employer's legal and moral obligation to protect employees from foreseeable harm while traveling on company business. In the United States it is enforced through the OSHA General Duty Clause (Section 5(a)(1) of the OSH Act of 1970); in the UK through the Corporate Manslaughter and Corporate Homicide Act 2007; in the EU through Framework Directive 89/391/EEC. ISO 31030:2021 is the international framework organizations use to demonstrate compliance.

Why duty of care has become a board-level issue in 2026

Global business travel spend reached $1.48 trillion in 2024 and is projected to surpass $1.64 trillion in 2025, according to the GBTA 2024 Business Travel Index Outlook. As travel volumes have recovered past pre-pandemic levels, the exposure surface for employer liability has expanded in parallel. The U.S. Department of State issued more than 200 Travel Advisory updates in 2024 alone, and the IATA Travel Centre logged sharp increases in entry-requirement changes across 60+ jurisdictions between January and December of that year.

Drawing from 8+ years building AI-powered corporate travel platforms, the patterns that hold up under legal scrutiny are the same regardless of company size: a written policy, a documented risk assessment before every high-risk trip, an auditable pre-trip approval trail, real-time traveler location awareness, and a 24/7 assistance channel with a documented response SLA. Everything else is decoration.

What "duty of care" actually means in law

Duty of care is not a single statute — it is a doctrine that surfaces in occupational safety law, tort law, and corporate criminal law depending on jurisdiction. In the United States, the OSHA General Duty Clause requires employers to "furnish to each of his employees employment and a place of employment which are free from recognized hazards" (29 U.S.C. § 654(a)(1)). OSHA has repeatedly clarified in enforcement letters that the "place of employment" extends to any location an employee is directed to travel to on company business, including hotels, client sites, and transit between them.

Outside the U.S., the picture is stricter. The UK's Corporate Manslaughter and Corporate Homicide Act 2007 permits unlimited fines against organizations whose gross breach of a relevant duty causes an employee's death; convictions have followed events during overseas business travel. Australia's Work Health and Safety Act 2011 imposes analogous "positive duty" obligations on officers. The EU Framework Directive 89/391/EEC obliges employers to assess risks the worker is exposed to, including those "connected with the specific characteristics of the workplace" — case law has extended this to travel destinations.

ISO 31030:2021 — the operating framework

Published by the International Organization for Standardization in August 2021, ISO 31030 Travel risk management — Guidance for organizations is the international reference standard. It is guidance rather than a certifiable management system, but insurers, in-house counsel, and courts have begun to treat alignment with ISO 31030 as evidence that an employer has taken "reasonable steps" to discharge its duty. The standard walks organizations through eight domains: leadership commitment, policy, risk assessment, threat and hazard identification, treatment (mitigation) selection, communication and consultation, monitoring and review, and continuous improvement.

The most-often missed elements in ISO 31030 audits, per practitioner surveys published by the International SOS Foundation in 2023, are: pre-travel medical and mental-health readiness assessments, documented traveler consent for location tracking under GDPR/CCPA, and a written escalation matrix that names roles rather than individuals. Programs that name individuals fail the moment that individual is on annual leave; ISO 31030 §7.4 requires role-based assignment. For deeper technical implementation notes on stitching risk APIs, HR systems, and booking data into a single duty-of-care surface, see our companion piece on duty of care system architecture.

Comparison: Duty of care program maturity levels

CapabilityBasic (compliance-only)Standard (industry norm)ISO 31030-aligned
Written travel risk policyYes — genericYes — role-specificYes — role + destination-tiered
Pre-trip risk assessmentOnly for "high-risk" destinationsAutomated by destination scoreAutomated + medical + mental-health screen
Traveler trackingManual itinerary emailPNR feed to security providerReal-time GPS with documented consent
24/7 assistanceInsurance hotlineDedicated security firm (International SOS, Anvil, etc.)Security firm + documented SLA + tabletop exercises
Incident response drillsNoneAnnualQuarterly, with named role escalation matrix
Board reportingNoneAnnual summaryQuarterly with KPIs (coverage %, response times, near-misses)
Legal defensibilityWeakModerateStrong — passes "reasonable steps" test

The 12-point ISO 31030 checklist (2026)

  1. Board-level policy statement naming an accountable executive (usually CHRO or COO).
  2. Destination risk scoring updated at least monthly against a recognized source (International SOS, Control Risks, or U.S. State Department Travel Advisories).
  3. Pre-trip approval workflow with automated escalation for Level 3/4 destinations.
  4. Traveler medical and mental-health readiness screening for extended or high-risk trips.
  5. Documented traveler consent for location tracking, aligned with GDPR Article 6 and applicable state privacy laws.
  6. Pre-departure briefing pack — country-specific, dated within 30 days of departure.
  7. Real-time location awareness via PNR feed and/or mobile check-in.
  8. 24/7 assistance channel with documented response SLA (typically ≤ 15 minutes for Level 3+).
  9. Written escalation matrix — role-based, not individual-based.
  10. Post-incident review within 30 days, findings fed back into policy.
  11. Quarterly tabletop exercises covering evacuation, medical emergency, and civil unrest.
  12. Annual program audit against ISO 31030 clauses 5–10.

A ready-made policy template that satisfies items 1–3 is included in our library of Fortune 500 travel policy examples.

Where the program fails in practice

The failure modes are boringly consistent. First, traveler data lives in five systems — the TMC, the HRIS, the expense platform, the security provider, and someone's spreadsheet — and no single view exists during an incident. Second, tracking is switched off for VIP travelers who "don't want to be followed," which is exactly the population most likely to trigger a duty-of-care claim. Third, small subsidiaries are excluded from the policy because "they only book one trip a month," which is precisely how liability finds them.

The Travel Code duty of care hub documents how a BYOD (bring-your-own-data) approach solves the first failure mode: the platform ingests booking data from whichever TMC or online booking tool the business already uses, layers risk intelligence and real-time location on top, and exposes a single incident-response surface — without a rip-and-replace of existing systems. Combined with corporate-travel analytics (see our primer on travel spend analytics), the same dataset serves finance, security, and HR.

Frequently Asked Questions

What is duty of care in business travel?

It is the legal obligation for an employer to take reasonable steps to protect employees from foreseeable harm while traveling on company business. In the U.S. it is enforced through the OSHA General Duty Clause and state tort law; in the EU through Framework Directive 89/391/EEC and national transpositions; in the UK through the Corporate Manslaughter and Corporate Homicide Act 2007. The doctrine covers pre-travel information, in-trip assistance, and post-incident response.

Is ISO 31030 mandatory?

No. ISO 31030:2021 is voluntary guidance rather than a certifiable management-system standard. However, insurers, in-house counsel, and — increasingly — courts treat alignment with ISO 31030 as strong evidence that an employer has taken "reasonable steps" to discharge its duty of care. Many multinationals now require ISO 31030 alignment from vendors and joint-venture partners as a matter of contract, so the practical effect is compulsory for enterprise buyers.

What are the legal risks of failing duty of care?

They range from OSHA general-duty citations (up to $16,131 per serious violation in the U.S. as of 2024) to corporate criminal liability under the UK Corporate Manslaughter Act (unlimited fines, publicity orders, remedial orders) to civil negligence claims that have settled for tens of millions of dollars in cross-border business-travel death and injury cases. Personal liability for directors and officers is possible in Australia under the WHS Act 2011 and in several EU member states.

What should a duty of care program include at minimum?

A written policy with a named executive owner, destination risk scoring from a recognized source, a pre-trip approval workflow, real-time traveler location awareness with documented consent, a 24/7 assistance channel with a defined response SLA, and a post-incident review process. ISO 31030 clauses 5 through 10 are the authoritative reference. For a working checklist, see the 12-point list above in this article.

How does duty of care apply to remote or hybrid workers traveling for business?

The obligation is the same. OSHA guidance published in 2023 clarified that "place of employment" is determined by the employer's direction to travel, not by the worker's usual work location. If a remote employee is directed or approved to attend a client meeting, conference, or team offsite, the duty attaches to the entire journey — including the airport, the ride-share to the hotel, and the hotel itself. Employer-approved bleisure extensions do not extinguish the duty during the business-travel portion.

What is the difference between duty of care and business travel accident insurance?

Business Travel Accident (BTA) insurance transfers financial risk to an insurer. Duty of care transfers nothing — it is the underlying legal obligation to actively prevent, prepare for, and respond to harm. Courts have consistently rejected the argument that purchasing BTA insurance discharges the duty. Insurance is one component of a compliant program; alone, it is not a defense against a negligence or general-duty claim.

Sources cited

  • ISO 31030:2021, Travel risk management — Guidance for organizations, International Organization for Standardization, August 2021.
  • 29 U.S.C. § 654(a)(1) — OSHA General Duty Clause, Occupational Safety and Health Act of 1970.
  • Corporate Manslaughter and Corporate Homicide Act 2007 (UK).
  • Council Directive 89/391/EEC on measures to encourage improvements in the safety and health of workers at work (EU Framework Directive).
  • Work Health and Safety Act 2011 (Australia).
  • GBTA 2024 Business Travel Index Outlook, Global Business Travel Association.
  • U.S. Department of State Travel Advisories, travel.state.gov.
  • IATA Travel Centre entry-requirements database, 2024.
  • International SOS Foundation, Duty of Care Benchmarking Report, 2023.

Latest news

Your best journey starts right now!

Travel Code will process your personal data for setting up and managing your account, providing you with the requested travel management services, and as otherwise stated in our Standard Contractual Clauses for Controller/Processor. Travel Code may also process your data as a data controller in accordance with our Data Retention Policy and Cookie Policy.