Short answer: duty of care in corporate travel is the employer's obligation to take reasonable steps to protect travelling employees: assess destination risk before the trip, inform travellers of it, know where they are during the trip, and be able to reach and assist them when something goes wrong. None of that is possible without complete booking data, which is why duty of care is as much a systems question as a policy question.
What duty of care means in travel
Duty of care is a general legal concept: an obligation to take reasonable care to avoid foreseeable harm to people you are responsible for. For employers, that obligation covers the workplace and, in most jurisdictions, extends to employees travelling on company business. The precise legal basis differs by country - health and safety legislation, labour codes, negligence law - so the specific standard you are held to is a question for local counsel, not a blog article.
What is consistent across jurisdictions is the practical shape of the obligation. An employer who sends someone to another city or country is expected to have thought about the risks of the destination, told the traveller what they need to know, arranged sensible precautions, and prepared for the case where something goes wrong: illness, accident, natural disaster, civil unrest, or an ordinary missed connection that leaves someone stranded at night. "We did not know where they were" is the sentence every travel risk programme exists to make impossible.
ISO 31030 and the travel risk framework
The reference point most programmes now use is ISO 31030, the International Organization for Standardization's guidance on travel risk management, published in 2021. It is a guidance standard rather than a certifiable one: it does not create legal obligations by itself, but it describes what a competent programme looks like, which makes it a useful benchmark for what "reasonable steps" means in practice.
The areas ISO 31030 covers map closely onto what travel managers already recognise as good practice: identifying threats and assessing risk before travel is authorised, security and medical arrangements proportionate to the risk, traveller tracking, two-way communication between travellers and the organisation, incident response procedures, and a maintained travel risk policy. The standard's underlying principle is that a documented risk assessment sits underneath every trip decision - which, for routine trips to low-risk destinations, can be as light as an automatic classification, and for high-risk destinations becomes a genuine review step.
The duty of care loop: before, during, after
Before the trip, the programme decides whether the trip needs review at all. Most trips do not: a same-country trip to a low-risk city can be auto-approved with a standard briefing. The value of a written travel policy here is that it defines which destinations trigger which route, so the decision is consistent rather than personal.
During the trip, the core capabilities are knowing where travellers are supposed to be (from itineraries), being able to reach them, and being able to help - whether through an assistance provider, the travel agency's own service desk, or simply a rebooking. Government travel advisories are the standard public risk source: the US Department of State, the UK Foreign, Commonwealth and Development Office and the Government of Canada all publish country-level travel advice that programmes commonly feed into destination ratings.
After the trip, close the loop. Review incidents and near-misses, and audit whether the programme could actually see everyone who travelled. That last question leads directly to the data problem.
Why booking data is the foundation
Every capability in the loop depends on data that originates at booking time. You cannot track a traveller whose itinerary you never received, brief a traveller whose trip you learned about afterwards, or count people in a city if half the hotel bookings were made on consumer websites. This is why duty of care discussions end up being conversations about booking channels:
| Duty of care capability | Booking data it depends on |
|---|---|
| Knowing who is where | Complete itineraries: flights, hotels, rail and ground, all in one place |
| Pre-trip risk routing | Destination known at booking time, so high-risk trips route to review before ticketing |
| Reaching the traveller | Current contact details and emergency contacts held in the traveller profile |
| Location-relevant alerts | Structured itinerary segments with dates, cities and airports, not PDF confirmations |
| Disruption rebooking | Live booking records the agency or tool can act on, not screenshots |
| Counting exposure | One reporting layer across every booking channel, including agent-assisted bookings |
The practical consequence: the booking tool is duty of care infrastructure. A corporate booking tool that captures structured itineraries, keeps traveller profiles current and routes high-risk destinations to review does more for a duty of care programme than any policy document, because it generates the data every later step consumes. Agencies serving corporate clients make the same argument from the other side: consolidated booking data is a large part of what a managed programme is for, as our comparison of OTAs and TMCs explains.
The leakage problem: bookings you cannot see
Programme leakage - travellers booking outside the managed channel - is the single biggest hole in most duty of care setups. A traveller who books a consumer website because it was cheaper or easier is invisible to tracking, invisible to alerts, and invisible to the person doing a headcount during an incident. Some programmes try to patch this by parsing forwarded confirmation emails, which helps but is inherently partial.
The durable fix is to make the managed channel the easiest way to book: fast search, fares that stand up to comparison, mobile-friendly, and light-touch approvals rather than blocks. Duty of care is one of the strongest internal arguments for investing in booking experience, because every improvement in adoption is an improvement in visibility.
Policy plus tooling: how the pieces fit
A workable division of labour looks like this. The policy defines destination risk tiers, who approves what, and what travellers must do (briefings, check-ins in higher-risk locations). The booking layer captures itineraries and profiles, enforces the routing rules, and feeds a single reporting store. A risk information source - government advisories at minimum, a commercial provider where the risk profile justifies it - classifies destinations. An assistance arrangement, whether a specialist provider or the agency's own 24/7 desk, handles the moment something actually happens.
For agencies and TMCs building their own platforms, this is a systems integration job: booking engine, traveller profiles, an alerting feed and a reporting layer that spans online and offline bookings. Some of it automates well - itinerary-triggered advisory messages are a natural case for the workflow automation we describe in AI automation for travel agencies - but the automation is only as good as the underlying data discipline.
Building a proportionate programme
Duty of care scales with risk, and a proportionate programme is more defensible than an impressive-sounding one that is not followed. A sensible minimum for a company of any size:
- A written statement of who owns travel risk and who decides in an incident
- Destination risk tiers based on named public sources, reviewed on a schedule
- One managed booking channel that captures every itinerary, with leakage measured
- Traveller profiles with current phone numbers and emergency contacts
- A pre-trip review step for high-risk destinations only, so it actually happens
- A tested way to contact all travellers in a location within hours, not days
- An assistance arrangement travellers know how to reach, printed on something they carry
- A post-incident review habit, however informal, that feeds back into the tiers
Companies with higher-risk travel - remote sites, elevated-risk countries, large volumes - should treat ISO 31030 as a checklist for the gaps: structured risk assessments, training, drills and formal incident management sit on top of the foundation above, they do not replace it.
This article is general information about travel technology and online marketing. It is not legal, tax or financial advice, and advertising platform policies change often. Check the current policy documents and take professional advice for your own situation.