ChecklistTravel
ISO 31030 travel risk management: a duty of care checklist for business travel
ISO 31030 travel risk management means running business travel as a managed risk: a signed policy, assessments that consider the destination, the traveler and the activity, controls before and during the trip, a tested incident response and a review after every trip that matters. The checklist below turns the standard's guidance into items a travel, security or HR team can assign, evidence and audit, and shows where AI tools help and where people must decide.
On this page
- What ISO 31030 is, and what this checklist is not
- Duty of care sets the floor; ISO 31030 describes the program above it
- Governance and assessment items to settle before anyone books
- Controls for the trip itself: before departure and while away
- Incident response, post-trip review and program measures
- Where AI assists a travel risk program and where people decide
- Checklist items organizations tend to skip, and what it costs them
- Questions and answers
- Sources
What ISO 31030 is, and what this checklist is not
Duty of care sets the floor; ISO 31030 describes the program above it
Duty of care to traveling staff comes from general employment and safety law rather than travel-specific statutes, and it varies by country. In Great Britain, for example, the Health and Safety at Work etc. Act 1974, in section 2(1), requires every employer to ensure, so far as is reasonably practicable, the health, safety and welfare at work of its employees3. In the United States, the general duty clause at 29 U.S.C. 654(a)(1) requires employers to keep employment free from recognized hazards likely to cause death or serious physical harm4. How far these duties reach into a hotel room abroad is a question for lawyers, but neither stops at the office door.
What the law rarely says is how to organize the work. ISO 31030 fills that gap. It builds on the principles, framework and process of ISO 31000:2018 and aligns with ISO 45001:2018 on occupational health and safety2, so a company that already runs enterprise risk or safety management can extend the same governance to travel instead of creating a parallel system. It also widens the lens beyond physical safety to reputation, finance, business continuity, data and equipment2.
Governance and assessment items to settle before anyone books
These items decide who owns travel risk and how a trip is judged. Without them, the operational controls later in the list have nobody to answer to.
Controls for the trip itself: before departure and while away
Incident response, post-trip review and program measures
Where AI assists a travel risk program and where people decide
ColdAI's travel practice describes travel risk intelligence that combines geopolitical analysis, health advisories, weather and security information for corporate travel programs6. The division of labor below is how such tools should sit inside an ISO 31030 program.
| Task | What AI can do | What a person keeps | Failure to watch for |
|---|---|---|---|
| Monitoring risk intelligence | Summarize advisories and news feeds by location and theme | Judging credibility and changing a destination rating | Confident summaries of unverified reports |
| Matching alerts to travelers | Link an event's location and time to captured itineraries | Deciding whom to contact and how urgently | Missing travelers whose bookings were never captured |
| Pre-trip assessments | Draft an assessment from destination, activity and policy | Approving the trip and any traveler-specific controls | Generic drafts that ignore the traveler's profile |
| Traveler advisories | Draft briefings and alert messages in plain language | Checking facts and signing off before sending | Outdated or wrong instructions sent at speed |
| Incident decisions | Assemble a situation picture and options | Shelter, move or evacuate decisions | Automation bias when the picture is incomplete |
Approval steps for AI-drafted outputs follow the same patterns as other human-in-the-loop approvals.
Checklist items organizations tend to skip, and what it costs them
Treating insurance as the program
Early signalThe assistance provider's number is the only control travelers can name.
MitigationInsurance pays for help; the program decides whether the trip should happen and how. Keep both.
Collecting more location data than the risk justifies
Early signalContinuous tracking for routine domestic trips, with no deletion date.
MitigationUnder the General Data Protection Regulation (EU) 2016/679, personal data must be limited to what is necessary, health data falls under the special categories of Article 9, and Article 35 requires an impact assessment where processing is likely to result in a high risk5. Scale collection to the trip's rating and document why.
Destination-only assessments
Early signalEvery traveler to the same city receives the same briefing.
MitigationAdd traveler and activity factors to the assessment template and train approvers to ask about them.
Alert fatigue
Early signalTravelers receive messages about distant events and start ignoring all of them.
MitigationFilter alerts by proximity, severity and relevance to the itinerary before anything is sent.
Questions and answers
Can an organization be certified to ISO 31030?
Not in the way it can be certified to a requirements standard. ISO 31030 provides guidance rather than auditable requirements, so the credible evidence is a working program: a signed policy, completed assessments, training records, incident logs and reviews. Some organizations ask an independent party to assess their program against the standard, which is useful assurance but not a certificate of conformity.
Does ISO 31030 apply only to employees on business trips?
It applies to people traveling on the organization's behalf, which can include contractors, volunteers, students and guests the organization sponsors. Tourism and leisure travel are outside its scope unless the person is traveling for the organization. Each organization should decide explicitly who is in scope, write it into the policy and apply the booking and briefing rules to all of them.
How can we locate travelers in an emergency without tracking them all the time?
Start from captured itineraries, which tell you where people should be without any live tracking. Add check-ins or opt-in location sharing only for elevated-risk trips, and view live location only when an incident is declared. Write down what is collected, who can see it and when it is deleted, tell travelers in advance and assess the data protection impact where the law requires it.
What should happen when a traveler books outside the approved channel?
Treat it as a gap in the program rather than a personal failing. Make it easy to forward bookings so they are captured, ask why the approved channel was not used, and fix the reason, such as missing fares or poor booking tools. For elevated-risk destinations, make capture of the itinerary a condition of trip approval.
Sources
- ISO 31030:2021 Travel risk management: Guidance for organizations — International Organization for Standardization · checked 10 October 2026
- ISO 31030:2021 Managing travel risks: Guidance for organizations (ISO/TC 262) — International Organization for Standardization · checked 10 October 2026
- Health and Safety at Work etc. Act 1974, section 2 — legislation.gov.uk · checked 10 October 2026
- 29 U.S. Code § 654: Duties of employers and employees — Legal Information Institute, Cornell Law School · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Travel: travel risk intelligence for corporate travel programs — ColdAI