Duty of Care Reaches the Boardroom: Travel Risk as Governance in 2026
A turbulent global risk outlook, sharpening director liability and a widening regulatory net have moved traveller safety from an operational checklist to a board-level governance duty — here is what that shift demands

For a long time, “duty of care” for travelling employees lived in the operational layer of an organisation — a travel policy, an insurance line, a booking tool. In 2026 it has climbed the org chart. A genuinely turbulent global risk environment, a tightening web of corporate-accountability regulation, and a growing willingness of courts and regulators to hold directors personally responsible for foreseeable harm have combined to make traveller safety a governance question, not merely an administrative one. Boards are increasingly expected to know how their people are protected when they travel, to be able to evidence it, and to answer for it when something goes wrong. This briefing looks at why duty of care has reached the boardroom, the legal and regulatory forces driving the shift, and how leading organisations are turning a compliance risk into a genuine governance discipline built around the ISO 31030 standard.
From Admin Task to Boardroom Duty
The shift is easiest to see in who now asks the questions. A decade ago, traveller safety was owned somewhere in HR, security or travel management, and the board saw it only after an incident. Today, duty of care is increasingly framed as a fiduciary responsibility — part of the board’s obligation to manage material risk to its people and, by extension, to the organisation. Several forces are pushing in the same direction: a more volatile world in which the probability of a serious travel incident is genuinely higher; investors and insurers asking harder questions about how human-capital risk is governed; and a legal environment in which “we had a policy” is no longer an adequate defence. The practical consequence is that boards can no longer treat traveller safety as delegated and invisible. They are expected to set the tone, approve the framework, and be able to demonstrate that it works.
The 2026 Risk Landscape the Board Is Reading
The backdrop to all of this is a risk outlook that leaders themselves describe as unstable. The World Economic Forum’s Global Risks Report 2026 identifies the leading short-term global risks as geoeconomic confrontation, misinformation and disinformation, societal polarisation, extreme weather, and state-based armed conflict — a mix of the geopolitical, the environmental and the informational. Around half of the experts surveyed expect a turbulent or stormy period over the next two years, with an even larger share pessimistic over the decade. For organisations that move people across borders, this is not abstract. Geoeconomic tension translates into sudden visa, sanctions and exit-control changes; conflict and polarisation into unrest and rapid deterioration of once-stable destinations; extreme weather into the disruption we have seen repeatedly this year. A board reading this landscape cannot reasonably conclude that traveller risk is static or low-priority — and that realisation is precisely what is driving duty of care up the agenda.
The Legal Teeth Behind Duty of Care
What turns duty of care from good practice into board-level obligation is that it now carries real legal consequences. In the UK, the Corporate Manslaughter and Corporate Homicide Act 2007 allows organisations to be prosecuted where gross failures in management cause death — including, in principle, the death of an employee sent into harm’s way without adequate assessment or support. In the US, OSHA’s General Duty Clause requires employers to provide a workplace free from recognised hazards, a duty that extends to employees working and travelling abroad. Increasingly, the exposure is framed around two failure modes: sending people into foreseeable danger without proper intelligence and mitigation, and responding inadequately when an incident occurs. Directors are not insulated from this. The combination of potential corporate liability, personal accountability and reputational damage means duty of care is now a risk the board must actively own rather than passively delegate.
CSDDD and the Direction of Accountability
The regulatory direction of travel reinforces the point, even where it does not yet bite directly. The EU’s Corporate Sustainability Due Diligence Directive (CSDDD), amended by the “Omnibus I” package (Directive (EU) 2026/470) and in force from 18 March 2026, requires large companies to identify and address human-rights and environmental harms across their own operations, subsidiaries and direct business partners. The amendments narrowed its scope from roughly 13,000 to around 6,000 companies — broadly EU firms with more than 5,000 employees and €1.5bn turnover, and comparable non-EU firms — with transposition due by July 2028 and application from July 2029, and penalties capped at 3% of worldwide turnover. Two honest caveats matter here: CSDDD is about human-rights and environmental due diligence, not travel safety specifically, and it does not apply until 2029. But the direction it signals is unmistakable — boards being made formally accountable for how they manage risk to people across their operations and value chains. Duty of care to travelling employees sits squarely within that widening expectation of board-level responsibility.
ISO 31030: The Framework Boards Are Adopting
If the board is now accountable, it needs a defensible framework to point to — and ISO 31030:2021, the international guidance standard for travel risk management, has become the de facto benchmark. It is a guidance standard rather than a certifiable one, but it gives organisations a structured, auditable way to demonstrate that duty of care is being managed properly. Its approach runs through seven connected components: board-approved governance and policy with clear ownership across HR, security and legal; systematic threat identification; risk assessment built around the interplay of destination, traveller and activity; proportionate risk treatment; communication and pre-trip briefing; 24/7 incident response; and continuous monitoring and improvement. The value for a board is that ISO 31030 converts a vague obligation into a concrete, evidenced management system. When a director is asked “how do you know your people are protected?”, being able to point to a live ISO 31030-aligned programme is a far stronger answer than a policy document in a drawer.
Making Duty of Care a Governance Discipline
Turning all of this into practice is less about spending more and more about governing better. It starts with putting duty of care on the board agenda as a standing item, with a named owner and a policy the board has actually approved. It means assessing destination, traveller and activity together rather than relying on a country rating alone — a low-risk country can still host a high-risk activity for a vulnerable traveller. It means a genuine 24/7 incident-response capability with clear benchmarks, such as making initial contact within around 30 minutes and being able to locate every affected traveller within roughly two hours. It means capturing complete traveller data from all booking channels, so “bleisure” trips and direct bookings do not leave people invisible to the organisation. And it means documenting the audit trail and treating D&O insurance as a backstop, never a substitute for mitigation. Done well, duty of care stops being a liability to be managed and becomes a mark of a well-governed organisation — one that can move its people through a turbulent world with confidence.
Governing Duty of Care From the Top
Put Duty of Care on the Board Agenda
Make traveller safety a standing board item with a board-approved policy and a named owner across HR, security and legal — not a task delegated out of sight.
Adopt ISO 31030 as Your Framework
Use the international travel-risk standard to convert a vague obligation into a structured, auditable management system the board can point to and defend.
Assess Destination, Traveller and Activity
Move beyond a single country rating. A low-risk destination can still present high risk for a specific traveller or activity — assess the three together.
Build 24/7 Response With Clear Benchmarks
Stand up a genuine round-the-clock incident capability, targeting initial contact within ~30 minutes and locating every affected traveller within ~2 hours.
Capture Complete Traveller Data
Pull booking data from all channels so bleisure trips and direct bookings do not leave travellers invisible. You cannot protect people you cannot locate.
Document the Audit Trail
Keep evidence that the framework is live and working, and treat D&O insurance as a backstop that supports mitigation rather than replacing it.
Duty of care has completed its journey from the back office to the boardroom. A turbulent risk outlook, real legal teeth behind employer obligations, and a regulatory current that keeps pushing accountability upward have together made traveller safety a governance responsibility that boards can no longer delegate and forget. The encouraging part is that the path forward is well mapped: ISO 31030 gives organisations a clear, defensible framework; the practical disciplines — board ownership, integrated risk assessment, round-the-clock response, complete traveller data and a documented audit trail — are established and achievable. Boards that embrace this now will not only reduce their legal and reputational exposure; they will build the confidence to keep operating, and keep sending their people out into the world, even as that world grows less predictable. In 2026, protecting your travellers is no longer just the right thing to do — it is a visible test of how well an organisation is governed.
Contact TRSS to build a board-ready, ISO 31030-aligned duty of care programme that stands up to scrutiny
Get in Touch