Duty of Care for Business Travelers: Choosing the Right Standard
Two ISO standards frame how organizations set a duty of care policy for travel. This page explains the choice, and how risk intelligence supports it before, during, and after every trip.
Security and risk leaders can use this guide to choose the standard behind their duty of care policy and show that foreseeable risks were managed.
Duty of care is a decision to make, not a document to file
Duty of care for business travelers means taking reasonable steps to identify foreseeable threats and reduce the risk of harm connected with work travel. It is not a guarantee that no traveler will be harmed. It is an obligation to act reasonably and consistently on the information available at the time. The precise legal standard varies by jurisdiction and employment relationship, so qualified legal counsel should shape the policy itself.
What this page offers is the frame around that policy. Two international standards, ISO 31030:2021 and ISO 31000:2018, describe how an organization should structure the work, and most security teams build their travel duty of care policy on one of them. The sections below explain what each standard asks for, how to choose between them, and how Seerist’s risk intelligence supports the choice before, during, and after a trip.
ISO 31030: the standard written for travel
ISO 31030:2021 is the only international guidance dedicated to organizational travel risk management. It expects an organization to assess each journey against current conditions, set proportionate controls, and support the traveler from departure through to review.
Its strength is specificity. It speaks the language of itineraries, briefings, and traveler communications, so a security team can map its existing controls directly onto the standard. Choose it when travel risk is managed as a distinct program and the team needs a benchmark it can audit against on its own terms.
ISO 31000: the standard written for the whole enterprise
ISO 31000:2018 is the broader risk management framework. It says little about travel specifically and a great deal about governance: how risk appetite is set, how decisions are owned, and how risk information reaches the people accountable for it.
Choose it when travel is one exposure among many inside a mature enterprise risk program. Travel decisions then inherit the organization’s existing thresholds and reporting lines, which makes them easier to defend to a board that already thinks in ISO 31000 terms. The cost is that the travel-specific detail has to be written in by the team.
How to choose, and why the follow-through matters more
The choice usually follows the shape of the organization. A standalone travel security function is best served by ISO 31030. A team that reports into enterprise risk should anchor on ISO 31000 and adopt ISO 31030 as the travel layer beneath it. The two are designed to work together, so neither choice locks the other out, and either should connect to the organization’s wider travel risk management program.
Whichever standard frames the policy, both make the same demand in practice. The organization has to show that it assessed foreseeable risk before travel, kept the decision live while the traveler was exposed, and can reconstruct what it knew and did afterwards. That is why the rest of this page follows the trip itself: before, during, and after. Neither standard replaces local legal advice or creates a universal safe harbor.
Intelligence is not evidence
A generic country report without a decision or communication trail is intelligence, not evidence of a complete control. Under either standard, what counts is the assessment it informed, the decision it produced, and the record that shows both.
Pre-trip
Before the trip: assess the journey as it stands today
Preparation starts with an assessment of the destination as it is now, not as an annual country rating describes it. City-level conditions, recent patterns of unrest or violence, and planned events around the dates of travel can change the answer for a routine trip. Traveler-specific exposure matters just as much. An executive visit, a trip carrying sensitive devices, or a traveler whose identity raises legal risk each calls for different controls.
Seerist supports this stage with destination intelligence and Control Risks analyst context across 195 countries. Recent verified incidents show what has actually happened, analyst outlooks show where conditions are heading, and the two together let the security team set a threshold in advance rather than discover it mid-trip. The output of the assessment should be a decision: proceed, proceed with added controls, or defer.
Before the trip: brief the traveler and record the approval
A pre-trip brief is the point where intelligence becomes a control. It should tell the traveler what conditions to expect, what to do if they change, and how to reach help. Seerist analysis lets the brief lead with what is current and relevant to this journey, so the traveler reads a short, specific document rather than a generic country report.
Approval closes the pre-trip stage. The policy should name who can authorize elevated-risk travel and who can defer, modify, or cancel it. Record what was assessed, who approved it, and whether the traveler acknowledged the brief. That record is the first entry in the audit trail both standards expect.
"Duty of care is evidenced by the decisions an organization makes and carries through, not by the volume of information it collects."
Mid-trip
During the trip: keep the decision live
Risk acceptance at booking is not the end of the process. Unrest, extreme weather, or a transport shutdown can change the viability of a trip within hours, and both standards expect the organization to notice. The operating loop is short: detect a change, verify it, and decide what it means for the travelers actually exposed to it.
Seerist runs that loop against real itineraries rather than a map. PulseAI surfaces emerging signals early, Verified Events corroborates what has happened, and AskAnna answers focused questions about what an incident means for a destination or a business activity. Control Risks analysts add the judgment on whether a situation is targeted, spreading, or likely to disrupt the trip. Detection arrives with its context attached, which is what lets the team act in time.
During the trip: agree the triggers before you need them
Technology does not discharge duty of care by itself. The team still needs agreed triggers for a traveler check-in, for relocation or shelter in place, and for cancellation and evacuation planning. Setting those thresholds in advance turns a fast-moving alert into a governed decision rather than an improvised one.
Plan for the gaps as well. Travel agency data is often incomplete, some travelers book independently, and contractors or guests may never appear in the itinerary feed. A duty of care standard that only protects the travelers it can see is not yet complete.
Post-trip
After the trip: report what you knew, when you knew it, and what you did
Responsible duty of care produces a record, not just an outcome. Stakeholders need to understand why a trip proceeded, why it changed, or why it was stopped, and after an incident that account has to withstand scrutiny from insurers, regulators, or counsel. A defensible record reconstructs what the organization knew at each point, how it assessed the exposure, and who made the decision.
This is where verified, sourced intelligence earns its place. Reporting built on Seerist’s Verified Events and Control Risks analysis carries its provenance with it. Each judgment traces to a corroborated event, a named source, or an analyst assessment, and the timeline shows what the team knew at each decision point. That auditable trail is what either ISO standard means by evidence, and it is something unverified feeds cannot provide.
After the trip: review the standard and govern the data
Every completed trip, incident, or near miss is a chance to test the policy against what happened. Ask whether the team located affected people quickly, whether the instructions it sent were useful, and whether the record would satisfy an auditor working from the chosen standard. Fix what failed in bookings, alerts, or ownership before the next journey.
Traveler data deserves the same discipline. Location and itinerary information can be sensitive personal data, so collection should be proportionate, access should be controlled, and retention should follow policy and applicable law. Travelers should understand what is collected, why it is needed, and how it supports emergency assistance. Governing the data is part of the duty, not a separate compliance task.
What is duty of care for business travelers?
It is an employer’s responsibility to take reasonable measures to address foreseeable risks connected with business travel. In practice, that means assessing exposure before departure, monitoring material changes during the trip, and documenting the decisions made throughout. The exact legal standard depends on the relevant jurisdiction and circumstances.
Should a travel duty of care policy follow ISO 31030 or ISO 31000?
ISO 31030:2021 is dedicated to travel risk management and suits a standalone travel security program. ISO 31000:2018 is the enterprise risk framework and suits teams that report into a wider risk function, with ISO 31030 adopted as the travel layer. The two are designed to work together, so the decision is about where the policy is anchored rather than which one to exclude.
How does threat intelligence support travel duty of care?
Threat intelligence supplies the foreseeable-risk assessment before departure, the material-change detection during travel, and the sourced record afterwards. Its value comes from linking verified information and expert analysis to the travelers actually exposed, so decisions are timely and defensible. Intelligence supports the process, but it does not replace accountable decision-makers or emergency assistance.
Put verified intelligence behind every travel decision
See how Seerist helps security and risk teams connect destination intelligence, verified events, and expert analysis to faster, documented travel decisions under either standard.