Your Employees Are Traveling. Do You Know
Where They Are and What's Coming for Them?

In 2025, a company sent a senior manager to assess a hydroelectric project in the Peruvian Andes. The employer arranged a chartered helicopter for the remote site visit but conducted no meaningful vetting of the operator, the pilot, or the flight conditions. When the case reached court, the judge was direct: a routine commercial flight requires little scrutiny, but a helicopter flight in a remote mountain region is categorically different. The higher the risk, the higher the duty to investigate and mitigate. A proper risk assessment, the court concluded, would have identified the danger and stopped the trip from going ahead (Centuroglobal, 2026). The case illustrates a principle that is hardening across every jurisdiction where companies send employees abroad and that most corporate travel programs have not yet internalized that duty of care is not a policy document. It is a proportional, active, and continuously updated obligation that scales with the risk, and its breach carries legal, financial, and human consequences that no waiver, insurance policy, or travel booking platform can fully address. In 2026, that obligation has become significantly more demanding, not because the legal standard has changed, but because the threat environment employees are traveling into has grown more complex, more interconnected, and more capable of generating harm with less warning than at any point in the modern business travel era.

The Threat Landscape Has Changed. Most Programs Have Not.

The International SOS Risk Outlook 2026 identified 159 state-based conflicts in 2025, the most since the 1940s (FCM Travel, 2026). In the same report, 47 percent of organizations identified geopolitical instability as the leading driver of global uncertainty, and nearly 49 percent of risk managers stated that threats are now “increasingly interconnected,” requiring coordinated responses across security and medical functions simultaneously rather than sequentially (CTM Business Travel, 2026; 1000 Mile Travel Group, 2026). The critical phrase in that finding is “increasingly interconnected.” The threat environment facing business travelers in 2026 is not a collection of discrete, separable risks that can be managed through separate checklists — a health column, a security column, a weather column. It is a compound risk environment in which a geopolitical flare-up triggers civil unrest that closes an airport that grounds a traveler in a location where the digital infrastructure has been compromised by a state-sponsored cyber campaign. Each risk accelerates the others. And 57 percent of risk managers surveyed by International SOS reported that new threats emerge faster than they can be addressed, meaning the window for decision-making is not merely short, it is shrinking (FCM Travel, 2026).

The cyber dimension of travel risk has expanded in ways that many corporate security programs have not yet absorbed. World Travel Protection’s 2026 analysis characterized the current environment as one where “the physical and digital worlds are inextricably linked” — where mobile devices on which travelers carry everything from corporate VPN credentials to banking access have made business travelers “prime targets for sophisticated cybercriminals, whether they’re in transit, already at their hotel, or connected to any private network” (World Travel Protection, 2026, para. 2). Destinations once considered safe from physical or geopolitical threats can harbor significant digital risk: unsecured hotel networks, fake charging stations, and SIM-swap attacks targeting travelers in transit represent threat vectors that a security briefing focused on civil unrest and kidnapping risk will not address. The Zurich Insurance analysis of the 2026 business travel paradox noted that “leaving employees to manage a cyber incident alone while traveling significantly elevates stress, impacts employee mental wellbeing, and creates avoidable operational and personal risk”, and that over half of business travelers surveyed had encountered emergencies or serious incidents while abroad, in what was once considered exceptional but has become routine (Zurich, 2026, para. 4).

The geopolitical dimension has become structurally less predictable at exactly the moment when travel volumes have recovered to pre-pandemic levels and business travel is serving more mission-critical functions than ever. Global Guardian’s 2026 Global Risk Map, which rates countries across crime, health, natural disasters, infrastructure, political stability, civil unrest, and terrorism, documented escalating tensions between India and Pakistan following an April 2025 terror attack, ongoing conflict in Ukraine with direct implications for regional travel risk across Eastern Europe, a significant rise in terrorism in the Western world partly fueled by ideological convergence around the Gaza conflict, and expanding “mano dura” security models across Latin America creating unpredictable law enforcement environments for foreign nationals (Global Guardian, 2025). None of these developments appeared on most corporate destination risk ratings 18 months before they materialized. The CTM Business Travel analysis was precise in the implications: annual policy reviews are no longer sufficient, and “continuous monitoring and scenario planning are essential” for travel programs operating in this environment (CTM Business Travel, 2026, para. 5).

What Duty of Care Actually Requires and Where Programs Fall Short

Duty of care is the legal and moral obligation to protect employees from foreseeable harm during the course of their employment, including travel conducted on the employer’s behalf (AlertMedia, 2026a). In the United States, OSHA’s General Duty Clause requires employers to provide employment “free from recognized hazards that are causing or are likely to cause death or serious physical harm”, language that courts have applied to travel contexts in ways that extend well beyond the immediate worksite (AlertMedia, 2026b). Internationally, the standard is frequently more stringent: European jurisdictions impose criminal prosecution exposure, fines of up to 10 percent of annual turnover, and civil liability for employers who fail to meet their travel duty of care obligations (Centuroglobal, 2026). ISO 31030:2021 — the international standard for travel risk management — is now the benchmark against which courts in multiple jurisdictions assess whether an employer’s duty of care was reasonable (Centuroglobal, 2026). An employer who cannot demonstrate compliance with ISO 31030 has, in those jurisdictions, effectively failed the reasonableness test before the case-specific facts are even examined.

The operational gap between the legal standard and the typical corporate travel program is wide and well-documented. Only 20 percent of organizations feel confident they can verify risk information quickly enough to make effective decisions when a situation develops, despite 80 percent believing that speed of risk detection provides a competitive advantage (CTM Business Travel, 2026). Only 22 percent of companies can track remote worker travel, creating a specific liability exposure in which employees on “hush trips,” working from destinations without informing their employer, are still legally covered by the employer’s duty of care if something happens to them (Centuroglobal, 2026). Over a quarter of business travelers, including nearly a third of Gen Z employees, admit they do not know how to respond to emergencies abroad, a gap that represents direct corporate exposure, given that the employer controls the pre-travel briefing process that could close it (Zurich, 2026). Moreover, 60 percent of business travelers surveyed stated they would leave their employer if they felt their safety was not a priority during travel, creating a talent retention dimension to duty of care failures that compounds the legal and reputational exposure (Zurich, 2026).

The legal consequences of program failure are not theoretical. In a documented case in New South Wales, an employee won a lawsuit after a car accident on the way home from a work trip due to “work-induced fatigue”, despite the employer having a fatigue prevention plan that the court found inadequate in practice (AlertMedia, 2026c). The court’s focus was on proportionality: the plan existed but was not implemented in a way that actually addressed the foreseeable risk. The Dusek case, documented by Centuroglobal, reached the same conclusion through a different fact pattern: the employer arranged a helicopter flight in a high-risk environment without meaningful vetting of the operator, and a proper pre-trip assessment would have stopped the trip entirely (Centuroglobal, 2026). Business Travel News’ legal analysis noted that overseas travelers who are kidnapped have successfully argued that an employer’s conduct during the ransom negotiation, specifically, prolonged hard bargaining that extended the captivity, constituted additional actionable harm (Business Travel News, 2026). The scope of employer liability in international travel contexts is broader than most corporate legal teams have modeled, and it extends well past the moment of initial incident into the quality of the response. 

What an Intelligence-Led Travel Risk Program Looks Like

The distinction between a compliance-oriented travel risk program and an intelligence-led one is not primarily technological. It is a difference in how the organization conceptualizes its obligation. A compliance program defines a set of policies, distributes a travel risk guide, and processes incident reports after they occur. An intelligence-led program starts from the question that AlertMedia’s formulation captures most concisely: “Duty of care isn’t just emergencies. It’s knowing where your people are before, during, and after travel” (Expensify, 2026, para. 3). That framing reorients the program from reactive documentation to continuous situational awareness, which is operationally more demanding and strategically more defensible.

Real-time traveler visibility is the foundational capability on which everything else in an intelligence-led program depends. An organization cannot make effective decisions about an employee in a deteriorating situation if it does not know precisely where that employee is, what their planned movements are, and how to reach them through redundant communication channels. The FoneTrac analysis of corporate travel security identified the core failure mode it addresses: “Security leaders are no longer reliant on fragmented spreadsheets, after-the-fact check-ins, or manual outreach” — replacing these with consolidated traveler location awareness, real-time threat intelligence, and two-way communication in a single operational picture (FoneTrac, 2026, para. 6). The scenario it illustrates is instructive: a multinational energy firm with hundreds of employees across Latin America, Southeast Asia, and Eastern Europe simultaneously, where a localized disruption near a refinery or a sudden airport closure can spiral into crisis if the organization lacks the centralized visibility to identify who is affected, who is not, and what decision each situation requires.

Pre-travel threat briefings represent the second core capability — and the one most frequently treated as a checkbox rather than a substantive intelligence product. Global Guardian’s executive travel risk analysis identified the components of a briefing that actually meets the proportionality standard courts apply: political stability assessment, kidnapping-for-ransom and executive-targeted theft risk, terrorism indicators, health infrastructure quality, legal environment including arbitrary detention risk, and monitoring of open, deep, and dark web sources for direct targeting indicators including activist campaigns and coordinated protest planning (Global Guardian, 2026). A briefing that covers none of these, or covers them through a static country-rating system that has not been updated in the weeks before travel, does not meet the standard an intelligence-led program requires or the standard courts applying ISO 31030 expect. FCM Travel’s Jo Lloyd, Head of Account Management and Consulting, observed that many organizations “remain dangerously reliant on vague policies, which often means, in a crisis, minutes are lost, clarity evaporates, and employees are left to figure it out alone” (FCM Travel, 2026, para. 8).

Dynamic risk tiering by destination — rather than static country ratings — is the operational mechanism through which an intelligence-led program accounts for the rapidly shifting, compounding threat environment documented in the ISOS Risk Outlook. A country rated medium-risk by an annual assessment may contain high-risk cities, high-risk transit routes, high-risk event windows (elections, anniversaries, sporting events), and high-risk individual profile categories (female travelers, executives of specific nationalities or industries) that a static national rating does not capture. The proportionality principle established in the Dusek case applies here: the higher the specific risk for a specific traveler in a specific destination, the greater the duty to assess, brief, and mitigate it.

When Things Go Wrong Mid-Trip

The quality of an organization’s response when an incident occurs during travel is, in many liability contexts, as important as its pre-travel preparation. Global Guardian’s analysis of incident response frameworks identified the specific capabilities that must be pre-planned, not improvised: extraction procedures for civil unrest, targeted violence, and kidnapping attempt scenarios; identified safe havens; protocols for coordination with local embassies and host country officials; family notification procedures; and crisis communication plans that balance stakeholder transparency with the traveler’s privacy and safety (Global Guardian, 2026). Each of these elements requires advance preparation — local intelligence, vetted local contacts, tested communication protocols — that cannot be assembled in real time while an incident is developing and an employee is at risk.

The decision framework for evacuation versus shelter-in-place is the specific gap that most corporate programs leave unaddressed. Knowing that civil unrest has broken out near a traveler’s location is useful information. Knowing whether to advise the traveler to shelter, move to a pre-identified safe haven, proceed to the airport, or wait for extraction requires a risk assessment capability — current intelligence about the nature and trajectory of the unrest, the operational status of transport infrastructure, the location and capacity of nearby medical facilities, and the availability of vetted local partners who can provide ground truth — that a travel booking platform or a generic incident alert service cannot supply. AlertMedia’s formulation of the capability gap is precisely accurate: in a crisis, high-impact threats require preventative steps taken before travel, but what actually tests an organization is the “emergency response plan” that must be fully operational and already understood by every relevant person when a real situation unfolds (AlertMedia, 2026a, para. 9).

Conclusion

The 2026 duty of care environment for business travel is characterized by three simultaneous developments that compound each other: the threat landscape is more complex and more rapidly shifting than at any point since the 1940s by conflict count. The legal and regulatory standard for employer obligation is hardening across jurisdictions, with ISO 31030 providing courts with a concrete benchmark against which to measure program adequacy, and the gap between what most corporate travel programs actually deliver and what genuine intelligence-led protection requires remains substantial. Sixty percent of business travelers would leave an employer who fails to make their safety a priority abroad — a statistic that frames duty of care not merely as a legal compliance problem but as a strategic talent and operational resilience question (Zurich, 2026). The organizations that will navigate the next decade of geopolitically volatile, digitally complex, rapidly shifting business travel without a significant incident, a significant lawsuit, or a significant talent consequence are the ones that have made the transition from compliance checkbox to active intelligence function — and that have the institutional knowledge, the vetted local networks, and the operational capability to intervene effectively when the situation demands it. 

References

AlertMedia. (2026a). Business travel duty of care: Guidelines and tips. https://www.alertmedia.com/blog/business-travel-care/

AlertMedia. (2026b). Guide to duty of care: Examples and impact. https://www.alertmedia.com/blog/duty-of-care-at-work/

AlertMedia. (2026c). Duty of care case law and your business: A summary. https://www.alertmedia.com/blog/duty-of-care-case-law/

Business Travel News. (2026). Liability versus duty of care. https://www.businesstravelnews.com/Research/Travel-Risk-Management/Liability-Versus-Duty-of-Care

Centuroglobal. (2026, February 11). Business travel duty of care: What every HR manager must know in 2026. https://www.centuroglobal.com/article/business-travel-duty-of-care/

Corporate Travel Management. (2026, February 26). Business travel risk management strategy 2026. https://www.travelctm.com/global/blog/business-travel-risk-management-strategy-2026/

Everbridge. (2026). Duty of care for business travelers: What employers must know. https://www.everbridge.com/blog/duty-of-care-for-business-travelers/

Expensify. (2026, February 5). Corporate travel risk management: A modern guide for 2026. https://use.expensify.com/resource-center/guides/corporate-travel-risk-management

FCM Travel. (2026). Five business travel risk categories to consider in 2026 and beyond. https://www.fcmtravel.com/en/travel-insights/travel-hub/insights/Five-business-travel-risk-categories-consider-2026-and-beyond

FoneTrac. (2026, January 12). Corporate travel security as strategy: Visibility, alignment and integrated protection in 2026. https://www.fonetrac-go.com/blog/2026/01/corporate-travel-security-as-strategy-2026/

Global Guardian. (2025, September 29). Forecasting the world’s threats: Global Guardian releases 2026 Global Risk Map. https://www.globalguardian.com/newsroom/2026-risk-map-press-release

Global Guardian. (2026). Executive travel risk: What boards need to know about duty of care. https://www.globalguardian.com/global-digest/executive-travel-risk

1000 Mile Travel Group. (2026, March 21). How to strengthen your business travel risk management strategy in 2026. https://www.1000miletravel.com/blog/strengthen-risk-management-strategy/

World Travel Protection. (2026). Travel risk management 2026: Digital threats and duty of care. https://worldtravelprotection.com/travel-insights/navigating-travel-risk-2026-digital-threats-duty-of-care/

Zurich Insurance. (2026, February 26). The business-travel paradox: More essential, more precarious. https://www.zurich.com/insights/travel/the-business-travel-paradox