Travel Manager's Duty of Care Checklist: Responsibilities & Action Plan
TL;DR: A travel manager's duty of care covers identifying risks before a trip, tracking travelers during it, and responding to incidents fast. The operating standard is ISO 31030:2021 (Travel Risk Management), reinforced by the OSHA General Duty Clause in the U.S. and Directive 89/391/EEC in the EU. Programs that can locate every traveler within two hours and trigger crisis comms inside 30 minutes meet today's baseline; the rest carry legal and reputational exposure.Drawing from eight-plus years building AI-powered corporate travel infrastructure, the duty-of-care patterns that hold up under real incidents — pandemics, regional conflict, weather events, medical emergencies — are not the ones that look best on a policy document. They are the ones that survive the gap between booking channels: travelers who self-booked on a consumer site, contractors not in HRIS, last-minute extensions that never made it back to the system of record. This checklist focuses on those gaps.
What Duty of Care Means for a Travel Manager
Duty of care is the legal and ethical obligation an employer holds to protect employees from foreseeable harm while traveling on company business. For the travel manager, this translates into a defined set of operational responsibilities: pre-trip risk assessment, traveler authentication and tracking, communication, medical and security assistance, evacuation, and post-incident documentation. The benchmark framework is ISO 31030:2021 — Travel Risk Management: Guidance for Organizations, published by the International Organization for Standardization in September 2021. It is the first global standard that codifies what a defensible program looks like.
The Legal Framework Behind the Obligation
Travel managers operate under overlapping statutory and common-law duty-of-care obligations. In the United States, the OSHA General Duty Clause (29 U.S.C. § 654(a)(1)) requires employers to furnish a workplace "free from recognized hazards" — a clause federal courts have repeatedly extended to business travel contexts. In the European Union, Council Directive 89/391/EEC obligates employers to ensure worker safety "in every aspect related to the work," with no geographic carve-out. The United Kingdom's Corporate Manslaughter and Corporate Homicide Act 2007 created direct organizational criminal liability where senior management failure causes a death. Per the GBTA Foundation's 2024 risk management survey, only about 38% of corporate travel programs had a formally documented travel risk management policy aligned to ISO 31030 — meaning the majority of programs would struggle to demonstrate "reasonable steps" in court.
Core Responsibilities Checklist
The travel manager's duty-of-care scope, mapped to ISO 31030 clauses, breaks into seven categories:
- Policy & governance — written travel risk policy, board-level sponsor, annual review
- Pre-trip risk assessment — destination rating, traveler profile screening, trip approval workflow
- Traveler preparation — country briefing, vaccinations, visa, ICE contacts, insurance verification
- In-trip tracking & communication — PNR ingestion across all booking channels, two-way messaging, check-in cadence
- Incident response — 24/7 assistance line, escalation tree, evacuation provider, family liaison
- Insurance & assistance — corporate travel medical, security extraction, kidnap & ransom where applicable
- Post-incident review — documented after-action report, policy update, regulator notification if required
Pre-Trip: The Highest-Leverage Phase
Per ISO 31030, a defensible pre-trip risk assessment combines three inputs: destination risk (security, health, political, environmental), traveler profile (medical conditions, gender-specific risks, nationality, language), and trip purpose (site visit, conference, high-risk fieldwork). The U.S. State Department issues four-level travel advisories (Level 1 — Normal Precautions through Level 4 — Do Not Travel) updated continuously through travel.state.gov; the CDC Travelers' Health portal publishes destination-specific health advisories and the Yellow Book reference. The U.K. FCDO and Germany's Auswärtiges Amt provide parallel guidance. GBTA's 2024 benchmarking found only 42% of programs perform pre-trip risk briefings on a consistent basis, with the largest gap in trips to Level 2 destinations — exactly where most "ordinary" business travel happens and where overconfidence creates exposure. Approval workflows should auto-flag any Level 3+ destination for manager review and any traveler with a high-risk profile for medical sign-off.
For policy-side detail, our corporate travel policy compliance guide covers approval-tier design.
In-Trip: Tracking Across Every Booking Channel
This is where most programs fail in practice. Traveler tracking only works if the system ingests PNRs from every channel — managed TMC bookings, direct airline bookings, OTA reservations, last-minute rail and ride-share, and any extensions the traveler arranges on the road. IATA reported 4.7 billion passenger journeys in 2024, and a meaningful share of corporate travel — particularly for SMB and mid-market programs — leaks outside the managed channel. GBTA research consistently finds that fewer than 60% of programs can locate every active traveler within two hours of a major incident. The remediation is multi-source PNR ingestion (GDS feeds, direct API connections, email parsing, mobile check-in), combined with a two-way comms layer that lets the travel manager push a check-in request and receive a confirmed-safe response within minutes — not the next business day.
A practical pattern that avoids ripping out an existing OBT is documented in our BYOD duty-of-care without changing your OBT write-up.
Crisis Response: The 30-Minute Standard
The industry working benchmark for crisis activation — first communication to affected travelers — is 30 minutes from event confirmation. Achieving that requires three pre-built artifacts: (1) a crisis communication tree with named primary and backup owners, (2) pre-approved message templates for the top five incident categories (natural disaster, civil unrest, medical, criminal, transportation disruption), and (3) a contracted assistance provider with global coverage. Major providers — International SOS, Crisis24 (GardaWorld), Anvil Group, Healix — typically guarantee response SLAs in their corporate contracts. The U.S. Department of State's Smart Traveler Enrollment Program (STEP) remains a free supplemental layer for U.S. nationals abroad. Document every activation: time of first notification, time first traveler reached, time last traveler accounted for. Those three timestamps are the metrics insurance carriers, regulators, and (in worst cases) plaintiff attorneys will examine. They are also the metrics that distinguish a defensible program from a paper one.
Technology Stack: Build, Buy, or Overlay
Duty-of-care technology choices generally fall into four buckets. The table below compares them on the capabilities that matter when an incident actually happens.
| Capability | In-house spreadsheet | TMC-bundled tool | BYOD overlay platform | Dedicated risk platform |
|---|---|---|---|---|
| Real-time traveler tracking | No | Partial (managed bookings only) | Yes — multi-channel PNR | Yes |
| Coverage of self-booked / direct trips | Manual | No | Yes | Partial |
| Two-way crisis communication | Email only | SMS + email | Push + SMS + email | Multi-channel |
| Integrates without swapping OBT | N/A | Locks to TMC | Yes | Sometimes |
| Typical pricing model | Internal labor | Bundled in TMC fee | RateGuard 25% of validated savings (Travel Code) | $5–$15 per traveler / month |
| Time-to-deploy | Days | 3–6 months (RFP) | 2–4 weeks | 2–4 months |
The right choice depends on program size and channel mix. Programs with high self-booking leakage typically gain the most from an overlay model, because the duty-of-care problem is fundamentally a data-coverage problem before it is a tooling problem.
Documentation and Audit Trail
Every duty-of-care decision needs a record. ISO 31030 Annex A specifies the documentation set: policy, risk register, traveler authorization records, incident log, and post-incident review. Retention periods should align to local employment-law statutes of limitation — typically 3 to 7 years. Insurance carriers will request this documentation at renewal, and it forms the core of any defense if a traveler injury becomes a legal matter.
Frequently Asked Questions
What is duty of care in business travel?
Duty of care is the legal and ethical obligation of an employer to take reasonable steps to protect employees from foreseeable harm during work-related travel. Per ISO 31030:2021, that includes pre-trip risk assessment, in-trip tracking, communication, assistance, and post-incident review. It applies to all employees on company business — including contractors and bleisure extensions where the travel was company-funded.
Is duty of care legally required in the United States?
Yes, indirectly. The OSHA General Duty Clause (29 U.S.C. § 654(a)(1)) requires employers to provide a workplace free from recognized hazards, and federal courts have applied this to business travel. State tort law adds negligence exposure. There is no single federal "travel duty of care" statute, which is why programs anchor to ISO 31030 as the de facto standard of reasonable care.
What should a pre-trip risk assessment include?
Per ISO 31030, three input sets: destination risk (security, health, political, environmental — sourced from State Department, CDC, FCDO, WHO), traveler profile (medical, gender-specific, nationality, language), and trip purpose. Output should be an approval decision, a documented briefing, and any required mitigations (vaccinations, security training, alternative routing).
How quickly should a travel manager be able to locate every active traveler?
The working industry benchmark is within two hours of a major incident, with first crisis communication out within 30 minutes. Per GBTA Foundation research, fewer than 60% of programs currently meet the two-hour standard, primarily because of booking-channel leakage outside the managed TMC.
Does ISO 31030 require formal certification?
No. ISO 31030:2021 is a guidance standard, not a certifiable management system standard like ISO 27001 or ISO 9001. Organizations can self-attest alignment, and several risk consultancies offer third-party assessments against the framework, but there is no formal accredited certification body as of mid-2026.
How does duty of care apply to bleisure or remote work travel?
If the travel was authorized or funded by the employer in any segment, duty of care typically extends across the whole trip — including personal extensions. Policy should explicitly define when the employer obligation ends. See our bleisure travel policy guide for the boundary language most programs use.
What insurance should a corporate travel program carry?
Standard coverage stack: corporate travel medical (including evacuation and repatriation), business travel accident, and — for high-risk destinations — kidnap, ransom & extortion. Coverage limits should be benchmarked to the highest-risk destination on the itinerary, not the average. Our business travel insurance guide covers carrier comparisons.
Sources
- International Organization for Standardization. ISO 31030:2021 — Travel Risk Management: Guidance for Organizations. September 2021.
- U.S. Occupational Safety and Health Administration. General Duty Clause — 29 U.S.C. § 654(a)(1).
- European Council. Directive 89/391/EEC on the introduction of measures to encourage improvements in the safety and health of workers at work.
- U.K. Ministry of Justice. Corporate Manslaughter and Corporate Homicide Act 2007.
- Global Business Travel Association (GBTA) Foundation. Risk Management Benchmarking Survey, 2024.
- International Air Transport Association (IATA). Annual Review 2024.
- U.S. Department of State. Travel Advisories & Smart Traveler Enrollment Program (STEP).
- U.S. Centers for Disease Control and Prevention. CDC Yellow Book: Health Information for International Travel.