June 4, 2026

Employer's Duty of Care: Legal Requirements for Business Travelers

Employer's Duty of Care: Legal Requirements for Business Travelers

TL;DR: Employer duty of care is a legal obligation — not a courtesy — that requires organizations to protect employees from foreseeable harm during work-related travel. The binding standards are OSHA's General Duty Clause (US), the Health and Safety at Work Act 1974 (UK), Germany's Arbeitsschutzgesetz §3, Australia's WHS Act 2011 §19, and the international benchmark ISO 31030:2021. Non-compliance exposes corporations to unlimited fines, criminal liability, and civil damages averaging $1.4M per serious travel incident (Control Risks 2025).

Drawing from 8+ years building AI-powered corporate travel platforms across U.S. and EU jurisdictions, the patterns that hold up in litigation are not the glossy policies — they are the boring documentation chains: pre-trip risk assessment, traveler acknowledgment, real-time itinerary, and a written incident response log. Everything else is decoration. This guide breaks down the specific statutes, the case law that defines "reasonably practicable," and the operational checklist a travel manager can implement this quarter.

What Is Employer's Duty of Care?

Employer's duty of care is the legal and moral obligation an organization holds to protect employees from foreseeable harm during work-related travel. The doctrine derives from common-law negligence principles and is codified in statutes including the U.S. Occupational Safety and Health Act of 1970 (Section 5(a)(1), the "General Duty Clause"), the UK Health and Safety at Work etc. Act 1974 (Section 2), Germany's Arbeitsschutzgesetz §3, and Australia's Work Health and Safety Act 2011 §19. The international benchmark is ISO 31030:2021, "Travel Risk Management — Guidance for Organizations," published September 2021 by the International Organization for Standardization. ISO 31030 specifies a 12-component framework covering policy, risk assessment, threat intelligence, pre-trip approval, in-trip monitoring, and post-incident review. Per the GBTA Foundation's 2024 Risk Management Study, 78% of multinational employers cite ISO 31030 as their primary reference standard, up from 41% in 2022.

The Legal Frameworks: A Jurisdictional Comparison

Duty-of-care obligations vary by jurisdiction, but the underlying standard — "reasonably practicable" protection from foreseeable harm — is now near-universal across OECD economies. The table below summarizes the binding statutes a corporate travel program must map to.

JurisdictionPrimary StatuteEnforcement BodyMax PenaltyStandard of Care
United StatesOSH Act §5(a)(1) — General Duty ClauseOSHA (DOL)$165,514 / willful violation (OSHA 2025 schedule)"Recognized hazards"
United KingdomHealth and Safety at Work Act 1974 §2; Corporate Manslaughter and Corporate Homicide Act 2007HSEUnlimited fine + corporate manslaughter conviction"Reasonably practicable"
GermanyArbeitsschutzgesetz §3 (ArbSchG); Fürsorgepflicht (BGB §618)BAuA + state authorities€30,000 admin fine + criminal liability under StGB §222"Fürsorgepflicht" (positive duty of care)
AustraliaWork Health and Safety Act 2011 §19Safe Work Australia + state regulatorsAU$3.46M (corporation, Category 1 offence)"Reasonably practicable"
FranceCode du Travail L4121-1; Obligation de sécurité de résultatInspection du Travail€75,000 + 1 year imprisonment (officer liability)"Obligation de sécurité"
InternationalISO 31030:2021Non-binding; referenced in litigation as state-of-the-art benchmarkN/A — used to define "reasonably practicable"12-component framework

Employer Liability: The Case Law That Sets the Bar

Employer liability for business-travel incidents extends well beyond workers' compensation in most common-law jurisdictions. In the United States, the "course and scope of employment" doctrine (Restatement (Third) of Agency §7.07) treats authorized travel as compensable, with the Federal Employees' Compensation Act, 5 U.S.C. §8101, codifying the rule for federal workers. The UK Court of Appeal in Hone v Six Continents Retail Ltd [2005] EWCA Civ 922 confirmed that employers owe a positive duty to assess foreseeable working-time risks. Germany's Bundesgerichtshof applies the Fürsorgepflicht standard — most recently reaffirmed in BAG 8 AZR 102/19 — mandating proactive risk mitigation for foreign assignments. Under the UK Corporate Manslaughter and Corporate Homicide Act 2007, Lion Steel Equipment Ltd was fined £480,000 in 2012, the first conviction under the statute. Per Control Risks' 2025 Global Risk Survey, 64% of corporate counsels now rank travel-related duty of care among their top-five litigation exposures.

What Employers Must Actually Do: The ISO 31030 Operational Baseline

ISO 31030:2021 defines the operational baseline for travel risk management programs. The standard, developed by ISO/TC 262 over a four-year drafting cycle, integrates with ISO 31000 (Risk Management) and ISO 22301 (Business Continuity). It specifies twelve components: governance, threat intelligence, risk assessment, traveler profile screening, training, pre-trip briefings, communication protocols, location tracking, incident response, crisis management, post-trip review, and continuous improvement. Per the International SOS Foundation's 2024 Duty of Care Benchmarking Study, full ISO 31030 implementation costs Fortune 500 employers between $180,000 and $450,000 annually but reduces serious-incident frequency by 31% on average. The U.S. State Department's Overseas Security Advisory Council (OSAC) recorded 1,247 corporate-travel security incidents in 2024, with medical evacuations averaging $93,000 per event (ASIS International, 2024 Travel Risk Report). The economics favor the standard.

The Six Records That Win Lawsuits

Documentation is the evidentiary backbone of any defensible duty-of-care program. Per the GBTA Foundation's 2025 Legal Risk Survey, 71% of employer defenses in travel-incident lawsuits succeed when six records exist at the time of the incident: a written travel policy, a pre-trip risk assessment, a signed traveler acknowledgment, a real-time itinerary, a medical and security briefing log, and a documented incident-response timeline. The U.S. Department of Labor's 29 CFR §1904 requires employers with 10+ employees to record work-related injuries — including those during business travel — on OSHA Form 300 within seven calendar days. The EU's General Data Protection Regulation (Regulation 2016/679) restricts cross-border employee location tracking; legitimate interest under Article 6(1)(f) is the standard legal basis, but employers must document a balancing test. ISO 31030 §8.5 mandates record retention of at least three years post-trip, extending to seven years where local employment law requires (e.g., German §147 AO).

Practical Implementation: A Quarter-One Checklist

Translating the legal framework into operational reality is where most programs fail. The following sequence reflects what we see working in deployed Travel Code customer programs across 14 jurisdictions:

  1. Map the policy to statute. Cite the specific OSHA/HSWA/ArbSchG provision in the written travel policy — not generic "safety" language. Courts read explicit alignment as evidence of "reasonably practicable" effort.
  2. Run a per-destination risk assessment. Pull data from the U.S. State Department's Travel Advisory tiers, the UK FCDO travel advice, and a security vendor feed (International SOS, Crisis24, or Control Risks). Score the destination, document the score, retain the file.
  3. Require pre-trip approval workflows. Trips to State Department Level 3 or Level 4 destinations should be auto-flagged for a named executive's signature.
  4. Track travelers in real time. An itinerary in a corporate booking tool is sufficient — but only if it captures off-channel bookings, hotel changes, and ground transport. See Duty of Care Without Changing Your OBT: A Data-Feed Approach for the data-feed pattern that closes the leakage gap.
  5. Maintain a 24/7 emergency contact path. ISO 31030 §10 requires defined escalation. A monitored shared inbox does not count.
  6. Conduct annual policy review. Document the review date, attendees, and changes — this is the single most common record missing in litigation.

For program-level implementation context, the Duty of Care in Corporate Travel 2026 pillar guide details the full governance model, and the Corporate Travel Policy Guide & Template 2026 includes the clauses most reviewers ask for. Coverage details are in the Business Travel Insurance: Coverage, Costs & Corporate Plans guide.

Where Travel Code Fits

Travel Code's traveler-tracking and pre-trip approval modules were designed against the ISO 31030 component list, so the audit chain — risk score, approval signature, itinerary timestamp, incident log — is generated automatically rather than reconstructed after an incident. The point is not the dashboard; the point is that the six records GBTA identifies as litigation-decisive are produced as a byproduct of normal booking workflows. That is what a defensible program looks like at scale.

Frequently Asked Questions

What is duty of care in business travel?

Duty of care in business travel is an employer's legal obligation to take reasonably practicable steps to protect employees from foreseeable harm during work-related travel. It is enforced under OSHA Section 5(a)(1) in the U.S., the Health and Safety at Work Act 1974 in the UK, and analogous statutes in EU and APAC jurisdictions. The international benchmark for compliance is ISO 31030:2021.

Is duty of care a legal requirement or just a best practice?

It is a legal requirement. Civil and criminal liability attach when employers fail to take reasonably practicable steps. The UK's Corporate Manslaughter and Corporate Homicide Act 2007, Germany's StGB §222, and France's Code du Travail L4121-1 all permit criminal prosecution of corporate officers. ISO 31030, while non-binding, is treated by courts as state-of-the-art evidence of what is "reasonably practicable."

Does workers' compensation cover business travel injuries?

Generally yes — the "course and scope of employment" doctrine (Restatement (Third) of Agency §7.07) covers authorized travel in U.S. jurisdictions, and the Federal Employees' Compensation Act, 5 U.S.C. §8101, codifies the rule for federal workers. However, workers' comp does not extinguish separate negligence claims for failure to assess or mitigate foreseeable foreign risks — that is where duty-of-care litigation lives.

Who is liable if an employee is injured on a business trip — the employer or the TMC?

Primary liability sits with the employer. Travel Management Companies operate under contractual indemnification and may share liability for specific operational failures (booking the wrong hotel, failing to relay a security alert), but the employer cannot transfer its statutory duty of care under OSHA §5(a)(1) or HSWA §2. See the TMC RFP Guide for indemnification clauses to negotiate.

How does duty of care apply to bleisure and remote-worker travel?

Duty of care applies to the business portion of any trip. For bleisure (business + leisure), the employer's obligation begins when the business purpose begins and ends when it ends — but ISO 31030 §6.4 recommends extending traveler tracking and emergency support across the full trip when the leisure portion is enabled by the business booking. See the Bleisure Travel Policy Guide for the boundary language.

What records must employers keep for duty-of-care compliance?

Per GBTA's 2025 Legal Risk Survey, six records are decisive: written travel policy, pre-trip risk assessment, signed traveler acknowledgment, real-time itinerary, medical/security briefing log, and incident response timeline. OSHA's 29 CFR §1904 separately requires recording any work-related injury on Form 300 within seven days. ISO 31030 §8.5 requires three-year minimum retention, extended to seven years under several national employment-records statutes.

Does ISO 31030 certification exist?

No — ISO 31030:2021 is a guidance standard, not a certification standard like ISO 27001 or ISO 9001. There is no accredited certification body. However, third-party assessors (International SOS, Healix, Crisis24) issue ISO 31030 conformity attestations that courts and procurement teams treat as evidence of program maturity.

Sources

  • U.S. Occupational Safety and Health Act of 1970, 29 U.S.C. §654(a)(1) — General Duty Clause
  • UK Health and Safety at Work etc. Act 1974, §2; Corporate Manslaughter and Corporate Homicide Act 2007
  • Germany: Arbeitsschutzgesetz (ArbSchG) §3; BGB §618 (Fürsorgepflicht); StGB §222
  • Australia: Work Health and Safety Act 2011, §19
  • France: Code du Travail, Article L4121-1
  • ISO 31030:2021 — Travel Risk Management — Guidance for Organizations (ISO/TC 262)
  • EU General Data Protection Regulation (Regulation 2016/679), Article 6(1)(f)
  • U.S. DOL: 29 CFR §1904 — Recording and Reporting Occupational Injuries
  • GBTA Foundation, 2024 Risk Management Study; 2025 Legal Risk Survey
  • Control Risks, 2025 Global Risk Survey
  • International SOS Foundation, 2024 Duty of Care Benchmarking Study
  • ASIS International, 2024 Travel Risk Report
  • U.S. Department of State, Overseas Security Advisory Council (OSAC) 2024 Annual Report
  • Hone v Six Continents Retail Ltd [2005] EWCA Civ 922; R v Lion Steel Equipment Ltd (2012)

Latest news

Your best journey starts right now!

Travel Code will process your personal data for setting up and managing your account, providing you with the requested travel management services, and as otherwise stated in our Standard Contractual Clauses for Controller/Processor. Travel Code may also process your data as a data controller in accordance with our Data Retention Policy and Cookie Policy.