Destinations

getty
Three years ago, “duty of care” belonged on the last slide of a corporate travel RFP—a comfort item, alongside 24/7 support and an emergency hotline. In 2026, the same phrase appears in the board minutes. It’s not that travel got more dangerous. Rather, regulators, insurers, courts and employees have all quietly moved travel risk from a nice-to-have to a stated obligation. Most travel programs have not caught up.
I run a B2B platform used by companies to manage corporate travel, so I have a stake in how this narrative plays out. But the shift I am describing is happening independent of any vendor. It is happening because of the underlying standards—ISO 31030 and the national employer-safety statutes.
ISO 31030, published in 2021, gave courts and regulators an internationally recognized benchmark for assessing what a “reasonable employer” looks like when a traveler is harmed on a work trip. It covers risk assessment, traveler tracking, response protocols and performance monitoring. In jurisdictions that already had general employer-safety statutes—OSHA’s General Duty Clause in the U.S., the Health and Safety at Work Act 1974 in the U.K., the Work and Health Safety Act 2011 in Australia, §3 Arbeitsschutzgesetz in Germany—ISO 31030 has become the implicit standard by which those statutes are measured.
In the absence of a formal policy, courts now ask whether the employer met the standard “a reasonable employer with an ISO 31030-aligned framework” would have met. That kind of civil exposure is no longer an insurance-desk number. It is a board-level number.
At the same time, the frequency has shifted. The Zurich “Business Travel Outlook 2026” reported that 80% of business travelers experienced at least one disruption in 2025, and 53% said they encountered an actual incident or emergency during travel. If eight in 10 trips involve disruption, travel risk is not a rare event category. It is a recurring operational variable. And a recurring operational variable that carries $1.4 million in average civil exposure is exactly the kind of thing CFOs and general counsels have opinions about.
If your program was designed under the “duty of care is a perk” mental model, you are almost certainly behind on at least three of the following five signals.
1. You cannot locate every traveler within two hours. Two hours is now the informal 2026 baseline for traveler location—the point at which a program is defensible against an ISO 31030-aligned expectation. If your answer to “Where is our team in Frankfurt right now?” is “Let me check with the TMC on Monday,” you are exposed. The requirement is real-time visibility, not next-day reporting.
2. Your crisis communication does not fire in under 30 minutes. From incident to first structured contact with the affected employee, 30 minutes is the modern baseline. Some programs still operate on a business-hours email chain. That gap between “incident happened” and “we reached the person” is the gap plaintiffs’ counsel will spend a deposition on.
3. Your travel policy contains the words “duty of care” but not a written risk assessment. This is the most common failure I see. A policy referencing “duty of care” as a value, without a documented pre-trip risk assessment tied to each destination and each traveler, is not defensible in litigation. Courts look for the artifacts. A named value is not an artifact. A signed acknowledgment plus a documented assessment is.
4. Your booking channel and your traveler-location system are separate. If your travelers can book through the corporate tool, on an airline’s direct site or on a public OTA—and your locator only sees one of those channels—you have systematic blind spots. Any trip booked outside the managed channel is invisible to your response protocol. Today, off-channel bookings often account for a significant share of corporate travel. That share is also your legal exposure surface. At Travel Code, we found that the customers asking the sharpest questions are not asking about savings per trip. They are asking about what percentage of their travelers are actually visible to the locator on any given weekday.
5. Duty of care lives with the travel manager, not with risk, legal and HR. In the old model, “duty of care” was a travel operations concern. In the current one, it is a governance concern, shared across risk management, legal and human resources. Programs where the travel manager is the sole owner of the topic tend to underinvest in exactly the areas—risk assessments, incident documentation, board reporting—that courts and regulators care most about.
The practical move for a leader who sees themselves in more than one of those five is not to buy a new tool. First, it is to close the visibility loop: Confirm that every trip, regardless of booking channel, is visible to a single locator in real time. Then confirm that the incident response protocol is written, timed and tested, not just documented. Finally, treat the ISO 31030 framework as an internal audit checklist, not an aspiration.
The programs that will survive the next regulatory cycle in corporate travel are not the ones with the most premium travel-risk vendor. They are the ones that stopped treating “duty of care” as a slide and started treating it as an operational baseline. The shift is not coming—it already happened. What remains is whether your program acknowledges it before or after an incident forces the acknowledgment for you.
Forbes Business Council is the foremost growth and networking organization for business owners and leaders. Do I qualify?
Discover more from PMN S.P.O.R.T.S - A PRIME MEDIA NETWORK BRAND
Subscribe to get the latest posts sent to your email.

