August 24, 2026

PNR Explained: What Is a Passenger Name Record and How Corporate Travel Programs Use It

PNR Explained: What Is a Passenger Name Record and How Corporate Travel Programs Use It

TL;DR: A Passenger Name Record (PNR) is the electronic reservation file airlines and Global Distribution Systems (GDS) create for every booking. It stores traveler identity, itinerary, ticketing data, contact details, and special-service requests. Per IATA's Reservations Manual, five data elements are mandatory in every PNR. Corporate travel programs rely on PNR data for policy enforcement, duty of care, expense reconciliation, and negotiated-rate tracking.

What is a PNR?

A Passenger Name Record is a data record in an airline's Computer Reservation System (CRS) or a Global Distribution System such as Amadeus, Sabre, or Travelport. IATA formalized the PNR structure in the 1970s to standardize how carriers exchanged reservation data (per IATA Reservations Manual, current edition). Every PNR is identified by a six-character alphanumeric Record Locator — sometimes called a booking reference or airline confirmation code — that both the carrier and the GDS share via the Type A message standard (per IATA PADIS EDIFACT). A single PNR can cover up to nine passengers traveling on the same itinerary; larger groups are handled by linked or split PNRs. When a corporate traveler books through a TMC, the same Record Locator appears in the airline PNR, the GDS PNR, and the mid-office reporting database — this is the anchor that makes corporate reconciliation possible. Understanding the PNR is the entry point for any corporate travel glossary.

The five mandatory PNR elements

Per IATA's Reservations Manual, five data elements are mandatory before an airline will confirm a PNR:

  1. Name (NM): passenger name(s) formatted per airline standards, matching government-issued ID.
  2. Contact (CTC): phone number and/or email address for irregular-operation notifications.
  3. Itinerary: flight segments with class of service, date, origin/destination, and status code.
  4. Ticketing information: either an issued e-ticket number or a Ticketing Time Limit (TTL).
  5. Received-from field (RCVD FROM): identifies the agent, traveler, or system that created or modified the record.

A PNR missing any of these is flagged as "not complete" and is typically auto-cancelled by the airline within 24 to 72 hours, depending on carrier rules and how close the itinerary is to departure.

How PNRs flow through GDS systems

When a corporate travel manager or TMC agent books a flight, three synchronized PNRs are typically created: one in the GDS host (Amadeus, Sabre, or Travelport), one in the operating airline's CRS, and one in the mid-office platform used for reporting and quality control. The GDS pushes segment data to the airline via IATA's PADIS EDIFACT standard or the newer NDC (New Distribution Capability) XML schema (per IATA NDC 21.3 specification). Each system stores its own copy — meaning a change made in one platform must be re-synchronized to the others, a common source of PNR-to-ticket mismatches. Sabre's Command Reference documents SI, SSR, and OSI remarks lines that carriers use to pass corporate discount codes, meal requests, and duty-of-care contact details. Amadeus uses the OSI and SR line structure; Travelport uses similar fields with distinct command syntax. The consequence for corporate travel programs: PNR data quality depends heavily on which GDS and mid-office platform the TMC operates on.

PNR data privacy and government access

Governments have long required advance PNR transmission for security screening. In the United States, TSA's Secure Flight program requires airlines to transmit specific PNR data 72 hours before departure for all flights operating to, from, over, or within US airspace (per 49 CFR Part 1560). The EU's PNR Directive 2016/681, transposed into national law by all 27 member states, requires carriers to share PNR data with each state's Passenger Information Unit for flights entering or leaving the EU; data is retained for five years, with personal identifiers depersonalized after six months. Canada operates under the Passenger Protect Program administered by Public Safety Canada. For corporate travel programs, this creates two compliance obligations: (1) informing travelers in the corporate travel policy that PNR data will be shared with governments, and (2) ensuring GDPR-compliant handling of the same PNR data used internally for reporting. GDPR Article 6 requires a legal basis — most corporate programs rely on legitimate interest supported by explicit traveler notice at the time of booking.

How corporate travel programs use PNR data

Corporate travel managers use PNR feeds for four core workflows. First, policy compliance: mid-office platforms scan PNR remarks and fare codes against written policy, flagging out-of-policy bookings for review (per GBTA's 2025 State of the Industry report, roughly two-thirds of managed programs enforce policy at the mid-office layer). Second, duty of care: PNR itinerary data feeds risk-monitoring platforms so security teams know which employees are in which cities when an incident occurs. Third, expense reconciliation: the Record Locator ties the PNR to the ticket to the credit-card charge to the expense report — the classic four-way match. Fourth, negotiated-rate tracking: airline preferred-vendor codes (Tour Code, CID, or IT Number) stored in the PNR let procurement teams verify that contracted discounts were correctly applied at ticketing (per US GSA City Pair Program contract requirements for federal-government travel). Continuous PNR-data quality is the foundation of every downstream corporate travel workflow.

GDS PNR systems compared

AttributeAmadeusSabreTravelport
Record Locator format6 alphanumeric6 alphanumeric6 alphanumeric
Special Service Request lineSRSSRSSR
Other Service Information lineOSOSIOSI
Corporate discount code fieldTour Code (FT)Tour Code (5-)Tour Code (T-)
NDC platformAmadeus Travel Platform (2020)Sabre NDC (2021)Travelport+ (2022)
Approximate carriers hosted~200~400~500
Primary corporate marketsEMEA, LATAMNorth America, APACGlobal, mid-market

Common corporate PNR fields

Beyond the mandatory five elements, corporate PNRs typically carry SSR (Special Service Request) codes for wheelchair assistance, dietary restrictions, or unaccompanied-minor travel; OSI (Other Service Information) lines carrying corporate account numbers, employee IDs, or cost-center codes; and Tour Codes that trigger negotiated corporate fares at ticketing. The IATA SSR list contains 74 standardized four-letter codes (per IATA Passenger Services Conference Resolutions Manual, PSCRM Resolution 830). Well-structured PNR remarks make automated corporate travel data analytics reliable. Poorly structured ones — with free-text remarks in inconsistent formats — turn every quarterly report into a data-cleaning exercise, and typically inflate leakage estimates by 15 to 25 percent because policy-flagged bookings can't be matched back to the underlying trip.

Where Travel Code fits

Travel Code operates as a BYOD (Bring Your Own Data) overlay: the platform ingests PNR feeds from any TMC, GDS, or corporate booking tool without requiring migration off existing systems. This matters because most enterprise travel programs run on two or three concurrent PNR sources — TMC-issued, self-booked online, and direct-with-supplier — and consolidating them into one policy, duty-of-care, and reporting layer is where corporate teams get stuck. Learn more about the BYOD approach for corporate travel. Drawing from 8+ years building AI-powered corporate travel platforms, the patterns that hold up are the ones that treat PNR data as a live feed — not a monthly export — so policy checks, duty-of-care alerts, and rate re-shopping run continuously against the real state of the itinerary.

Frequently Asked Questions

What are the five mandatory elements of a PNR?

Per IATA's Reservations Manual, every PNR must contain: (1) passenger name, (2) contact details, (3) itinerary segments, (4) ticketing information (either an e-ticket number or a Ticketing Time Limit), and (5) a Received-from field identifying who created or last modified the record. Without all five, the airline will not confirm the booking and will auto-cancel it within 24–72 hours.

How long is PNR data retained?

Retention varies by jurisdiction. The EU PNR Directive 2016/681 requires five-year retention with personal identifiers depersonalized after six months. TSA Secure Flight retains data for seven days for non-matched travelers and up to seven years for records of interest (per DHS Privacy Impact Assessment TSA-PIA-018). Airlines themselves typically retain PNRs for 12–36 months after travel; GDSs archive PNRs for 13 months post-departure by default.

What's the difference between a PNR and a ticket number?

The PNR is the reservation record, identified by a six-character alphanumeric Record Locator. The ticket number is the fulfillment document issued after payment — a 13-digit numeric string starting with the airline's three-digit IATA prefix. One PNR can produce multiple tickets when a traveler upgrades, reissues, or splits an itinerary. The two are linked via the FA (Fare/Ticketing) element in the PNR.

Can PNR data be used for expense reconciliation?

Yes. The Record Locator is the join key across the PNR, the ticket, the corporate credit-card transaction, and the expense report. This "four-way match" is the standard corporate reconciliation workflow — see the end-to-end corporate travel booking process for how the match is assembled from booking through general-ledger posting.

What is a corporate discount code in a PNR?

A corporate discount code — variously called a Tour Code, CID (Corporate Identifier), IT Number, or Contract ID depending on the airline — is stored in a specific PNR field (the Tour Code line in most GDSs) and triggers the negotiated fare at ticketing. For US federal travel, GSA's City Pair Program uses standardized -CA fare codes; commercial contracts use carrier-specific formats defined in the airline's corporate agreement.

Do NDC bookings still create a PNR?

Yes. IATA's NDC standard (New Distribution Capability, current version 21.3) transports offer and order data in XML rather than the legacy EDIFACT format, but the resulting order still generates a PNR-equivalent record in the airline's system. The Order ID replaces the traditional Record Locator in some workflows, though most airlines still issue a six-character Record Locator alongside the Order ID for backward compatibility with legacy mid-office and reporting systems.

Who can access my corporate PNR data?

Access is layered. The booking airline, hosting GDS, and TMC each hold a copy. Government agencies receive extracts under Secure Flight (US), the EU PNR Directive, and equivalent programs in Canada, Australia, and the UK. Internally, corporate travel managers, security teams, and finance receive derived data for policy, duty of care, and reconciliation. GDPR-covered travelers can request their PNR data under Article 15 (right of access).

Sources

  • IATA Reservations Manual (current edition)
  • IATA Passenger Services Conference Resolutions Manual (PSCRM), Resolution 830 — SSR codes
  • IATA New Distribution Capability (NDC) 21.3 specification
  • IATA PADIS EDIFACT Message Implementation Guidelines
  • US 49 CFR Part 1560 — TSA Secure Flight Program
  • EU Directive 2016/681 — Passenger Name Record Directive
  • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR), Articles 6 and 15
  • US GSA City Pair Program contract requirements — federal fiscal year current edition
  • GBTA 2025 State of the Industry / BTI Outlook
  • DHS TSA Privacy Impact Assessment TSA-PIA-018
  • Public Safety Canada — Passenger Protect Program

Latest news

Your best journey starts right now!

Travel Code will process your personal data for setting up and managing your account, providing you with the requested travel management services, and as otherwise stated in our Standard Contractual Clauses for Controller/Processor. Travel Code may also process your data as a data controller in accordance with our Data Retention Policy and Cookie Policy.