ISO 31030 Has Quietly Become the Legal Benchmark for Corporate Travel Risk. Most Organizations Are Unprepared.

Four years after the International Organization for Standardization published the first global standard for corporate travel risk management, the compliance picture is stark — and the legal consequences of the gap are no longer theoretical.

Those numbers reflect a systemic gap, not an isolated deficiency. They also reflect a persistent misunderstanding of what ISO 31030 actually requires — and what the absence of compliance now costs.

The standard, published in September 2021 and derived from ISO 31000, applies to any organization regardless of size or sector that sends personnel on work-related travel. Its five core requirements are operational in nature. None of them is satisfied by a travel insurance product. Insurance is a financial instrument. ISO 31030 demands an operational one.

What a compliant program must demonstrate — and where most organizations fall short:

Policy & Governance — Formal written policy with executive ownership and scheduled review. Most organizations: not documented. Pre-Trip Risk Assessment — Destination-specific threat analysis covering healthcare, security, and traveler profile. Most organizations: generic or absent. Traveler Communication — Active pre-departure briefings and real-time alerts, not static documents. Most organizations: partial at best. Real-Time Response — 24/7 capability to locate, contact, and assist travelers during incidents. Most organizations: insurance card only. Program Review — Post-incident analysis with structured improvement — iterative, not static. Most organizations: rarely practiced.

In Dusek v StormHarbour Securities LLP (2015 EWHC 37 QB), the UK High Court found an employer in breach of its duty of care after an employee was killed in a helicopter crash in Peru during a work trip. StormHarbour had arranged the flight but conducted no safety inquiry and no risk assessment.

Tomas Dusek, a financial professional, was sent to Peru to accompany investors on a site visit. His employer arranged a chartered helicopter with no safety inquiry, no vetting of the operator, and no risk assessment. The helicopter was unsuitable, the route dangerous, the weather poor, and the operator in financial distress. Dusek was killed in the crash.

Mr Justice Hamblen found StormHarbour in breach of its duty of care. The ruling established the proportionality principle: the higher the risk of a journey, the higher the employer's obligation to investigate and mitigate it.

"StormHarbour was required to have made at least some inquiry into the safety of the trip and carried out some form of risk assessment. Had it done so, it would not have permitted the trip." — Mr Justice Hamblen, 2015 EWHC 37 (QB)

ISO 31030 formalizes that principle at the organizational level. The jurisdictional framework is now global.

United States — OSHA General Duty Clause + Tort Law. Extends liability to any location employees perform work. ISO 31030 increasingly defines "reasonable precautions" in litigation. Active exposure. United Kingdom — Health & Safety at Work Act + Case Law. Dusek and Cassley rulings established proportionate duty of care, with graduated scrutiny based on destination risk. Active exposure. European Union — Loi de Vigilance (FR) / Supply Chain Act (DE). France and Germany have codified employer accountability across all environments where personnel operate. Active exposure.

A 2022 legal analysis by MAG Law concluded that ISO 31030 is increasingly the standard against which courts define what "reasonable precautions" means for organizations facing travel-related litigation.

Back to The Six Kind Journal