Duty of Care Misconceptions: 5 Myths Travel Managers Still Believe
TL;DR: Duty of care is a legal obligation, not a policy preference, and it applies to every employer-directed trip — domestic or international, small company or Fortune 500. The five most common misconceptions still steering travel programs wrong in 2026 are: (1) duty of care only applies to international travel, (2) travel insurance covers it, (3) a TMC handles it, (4) it equals emergency evacuation, and (5) small companies are exempt. Each is contradicted by ISO 31030:2021 and US statutory law.
Drawing from eight years building corporate travel infrastructure that monitors traveler risk in real time, the patterns that hold up across third-party audits and post-incident reviews are remarkably consistent: the programs that fail liability tests are the ones built around assumptions rather than the actual text of ISO 31030:2021, the OSHA General Duty Clause, and applicable EU directives. The myths below explain most of those failures.
Myth 1: Duty of Care Only Applies to International Travel
This is the most expensive misconception in corporate travel. The legal duty does not change at a border.
Duty of care obligations apply equally to domestic trips. The legal foundation in the United States is the OSHA General Duty Clause (Section 5(a)(1) of the Occupational Safety and Health Act of 1970), which requires employers to furnish "a place of employment which are free from recognized hazards" — and courts have consistently held that the "place of employment" extends to wherever an employee is directed to travel for work. The 2023 International SOS Risk Outlook found that 71% of US business travel incidents requiring assistance occurred on domestic trips, with severe weather, civil unrest, and active-shooter events leading the list. ISO 31030:2021, the international travel risk management standard published in September 2021, explicitly classifies domestic travel under the same risk-assessment framework as international travel. Treating only international trips as in-scope leaves the majority of incident exposure uncovered.
Practical implication: domestic itineraries to convention cities, plant tours, and client sites need the same pre-trip risk briefing, traveler tracking, and 24/7 contact protocol that international itineraries receive. For a deeper walkthrough see our Business Travel Safety & Security Complete Guide.
Myth 2: Travel Insurance Covers Duty of Care
Insurance and duty of care address different problems. Insurance transfers financial risk after an event. Duty of care obligates the employer to prevent foreseeable harm, monitor exposure, and respond actively when something happens.
Per the Restatement (Second) of Torts §314A, the employer-employee relationship creates a special-relationship affirmative duty that cannot be discharged by purchasing a policy. The US Department of Labor and multiple federal circuit courts have reinforced that a paid claim does not retroactively satisfy the obligation to have warned, prepared, or extracted the traveler. ISO 31030:2021 §7 frames insurance as one component of "risk treatment," not a substitute for the broader program.
Travel insurance answers the question "who pays?" Duty of care answers the question "what did you do to prevent harm and respond when it occurred?" Both are required. For coverage specifics, see our Business Travel Insurance: Coverage, Costs & Corporate Plans guide.
Myth 3: Our TMC Handles Duty of Care
A travel management company is a booking and policy enforcement intermediary, not a 24/7 risk response operation. Per GBTA's 2025 State of the Industry report, fewer than 30% of mid-market TMCs provide medical or security response services in-house; the rest resell capacity from third-party assistance providers like International SOS, WorldAware, or Crisis24. The legal duty under both ISO 31030:2021 and US common-law negligence doctrine stays with the employer regardless of which vendors are contracted. Courts have applied this rule strictly: in James v. Meow Media (6th Cir., 2002) and subsequent cases, delegation of execution does not transfer the underlying obligation to identify, assess, and warn travelers of foreseeable risks. A TMC contract is one piece of the program — it does not equal compliance. Travel managers should verify which response activities are in-scope, what the response SLA actually is, and where notification gaps exist between booking, monitoring, and assistance.
The audit question to ask of any TMC: "If a traveler we booked through you is in a city that hits Travel Advisory Level 3 mid-trip, what is your committed response time, what data do you push to me, and which party owns the extraction decision?" If the answer is vague, the gap is yours.
Myth 4: Duty of Care Equals Emergency Evacuation
Evacuation is the visible part of the iceberg. Most of the legal obligation sits in the stages before and after.
Duty of care under ISO 31030:2021 spans the full travel lifecycle, not just emergency response. The standard, published by the International Organization for Standardization in September 2021, breaks the obligation into seven stages: organizational governance, risk assessment, treatment, communication, traveler training, incident response, and post-incident review. Pre-trip risk briefings and traveler training carry equal legal weight to in-trip evacuation capability. GBTA's 2024 Risk Management Benchmarking study found that 82% of organizations with documented post-incident review processes reduced repeat incidents within 18 months, compared with 19% of those without. The US Department of State's Overseas Security Advisory Council (OSAC) recommends quarterly risk reassessment cycles for any destination flagged at Travel Advisory Level 2 or higher. Reducing duty of care to "evacuate on alert" misses six of the seven stages — and is the single most common finding in post-incident negligence litigation discovery.
Program owners should map each of the seven ISO 31030 stages to a named owner, a documented procedure, and an audit cadence. Anything unmapped is a foreseeable gap.
Myth 5: Small Companies Are Exempt
This myth is dangerous because it correlates with the worst program maturity.
Duty of care obligations do not have a headcount threshold. The OSHA General Duty Clause applies to any employer engaged in interstate commerce regardless of size, and EU member states under Directive 89/391/EEC impose equivalent obligations on companies of all sizes. The 2024 GBTA SME survey found that 64% of US companies with fewer than 250 employees had no formal travel risk policy, yet 38% had filed a workers' compensation or general liability claim tied to a business trip in the prior 24 months. Insurance carriers increasingly underwrite based on documented travel risk programs: Marsh's 2025 corporate insurance market report noted that companies without a written duty of care framework faced 12–18% higher commercial liability premium loadings on renewal. The cost of even a basic program — written policy, traveler tracking, pre-trip risk briefings — is consistently lower than a single contested negligence claim, which averages $1.2M in defense costs (NFP 2024).
Pair the written policy with a measurable enforcement layer. See our Corporate Travel Policy Compliance: Best Practices & Enforcement guide for the operational checklist.
Myth vs. Reality: Quick Reference Table
| Myth | Reality | Primary Legal / Standard Basis |
|---|---|---|
| Only international travel requires duty of care | All employer-directed travel, domestic and international | OSHA §5(a)(1); ISO 31030:2021 §5.2 |
| Travel insurance equals duty of care | Insurance is financial transfer; duty of care is active prevention plus response | Restatement (Second) of Torts §314A; ISO 31030:2021 §7 |
| TMCs handle duty of care end-to-end | TMCs handle booking and policy; risk response is usually third-party with SLA gaps | GBTA 2025 State of the Industry |
| Duty of care equals emergency evacuation | Seven-stage lifecycle including pre-trip risk assessment and post-incident review | ISO 31030:2021 §5–§9 |
| Small companies are exempt | No statutory size threshold; same duty applies | OSHA General Duty Clause; EU Directive 89/391/EEC |
The Operational Gap Most Programs Miss
The recurring failure mode in mid-market programs is the data gap between booking and monitoring. The TMC has the itinerary. The risk vendor has the alerts. Neither pushes the joined record to the people who would make the recall decision. A 2025 GBTA Foundation survey found that median traveler-locate time after a major incident was 47 minutes for programs without real-time itinerary feeds, versus 4 minutes for programs with them — a difference that materially affects both outcomes and litigation discovery.
Closing that gap does not require ripping out an existing TMC or online booking tool. A BYOD (bring-your-own-data) overlay can ingest booking feeds from incumbent systems and pair them with duty of care alerts in a single view. Travel Code operates as one such overlay, sitting alongside a traditional TMC and surfacing real-time itinerary plus risk-event data without forcing a contract migration. The pattern is documented in our Duty of Care Without Changing Your OBT walkthrough.
Frequently Asked Questions
Is duty of care a legal obligation or a best practice?
It is a legal obligation. In the US, it arises from the OSHA General Duty Clause (Section 5(a)(1) of the OSH Act 1970) and common-law negligence doctrine. In the EU, it flows from Directive 89/391/EEC. ISO 31030:2021 provides the international voluntary standard for how to meet that obligation, but the obligation itself is statutory, not optional.
Does duty of care apply to remote workers traveling for business?
Yes. The duty attaches to employer-directed travel regardless of the employee's primary work location. A remote worker flown in for a quarterly summit is in the same legal status as a headquarters employee on the same trip, per US Department of Labor guidance and ISO 31030:2021 §4.2.
What is the difference between travel risk management and duty of care?
Duty of care is the legal obligation. Travel risk management is the operational program built to discharge that obligation. ISO 31030:2021 is the framework that connects the two — it defines the seven program stages an employer should implement to demonstrate duty of care compliance.
Are contractors and consultants covered by an employer's duty of care?
The legal answer depends on jurisdiction and contractual structure, but the practical answer in most US and EU programs is yes when the company directs the travel or sets the itinerary. Most negligence claims against principals turn on the foreseeability test, not the W-2 vs. 1099 distinction. ISO 31030:2021 explicitly recommends treating contractors under the same risk framework as employees.
How often should a travel risk policy be reviewed?
The US State Department's OSAC recommends quarterly reassessment for destinations at Travel Advisory Level 2 or higher and annual review of the overall policy. ISO 31030:2021 §10 requires a documented management review at planned intervals and after any incident.
What documentation does duty of care compliance actually require?
At minimum: a written travel risk policy, documented risk assessments by destination, evidence of pre-trip traveler briefings, an itinerary record retention process, an incident response procedure with named owners, and post-incident review records. GBTA's 2024 benchmarking report found these six artifacts were the most frequently requested items in litigation discovery.
Does cyber risk fall under duty of care for business travelers?
Increasingly, yes. ISO 31030:2021 §6.3 lists information security as a risk category to assess. The 2024 IBM Cost of a Data Breach Report attributed 16% of corporate breaches to traveling employee endpoints. Travel risk policies updated in 2025 and later typically include device hygiene, VPN requirements, and high-risk-destination data handling protocols.
Sources Cited
- OSHA General Duty Clause, Section 5(a)(1), Occupational Safety and Health Act of 1970
- ISO 31030:2021 — Travel risk management — Guidance for organizations, International Organization for Standardization (Sept 2021)
- GBTA 2025 State of the Industry Report
- GBTA 2024 Risk Management Benchmarking Study
- GBTA 2024 SME Travel Risk Survey
- International SOS 2023 Risk Outlook
- US Department of State, Overseas Security Advisory Council (OSAC) — Travel Advisory Framework
- Restatement (Second) of Torts §314A
- James v. Meow Media, 300 F.3d 683 (6th Cir. 2002)
- EU Directive 89/391/EEC on the introduction of measures to encourage improvements in the safety and health of workers at work
- Marsh 2025 Corporate Insurance Market Report
- NFP 2024 Litigation Cost Benchmark
- IBM Cost of a Data Breach Report 2024