Skip to main content
Butter bar
Know your resilience gaps before disruption hits
Butter bar
Gartner® Market Guide for Emergency and Mass Notification Systems

Duty of care for business travelers: What employers must do in 2026

Traveling Employee 650x650

An employer’s duty of care for business travelers is the legal and ethical obligation to proactively protect traveling employees from foreseeable risks—by locating, assessing, and communicating with them before, during, and after every trip. In 2026, this obligation has never been more complex. Geoeconomic confrontation tops the World Economic Forum’s Global Risks Report 2026, state-based armed conflict ranks second, and mega-events like the FIFA World Cup 2026 are adding unprecedented crowd, transport, and cyber risk to 16 host cities across three countries. Meanwhile, new regulations in Europe—DORA and NIS2—are raising the compliance bar for operational resilience and duty-of-care reporting. This guide gives security, travel, and HR leaders a practitioner-level framework for meeting those obligations. 

What is duty of care for business travelers?

Duty of care refers to an organization’s obligation to protect the health, safety, and overall wellbeing of employees while they are traveling for work. This responsibility extends well beyond booking safe flights and hotels. It requires organizations to actively anticipate potential risks, provide employees with relevant and timely information, and ensure they can deliver support no matter where employees are located.

In practice, duty of care means creating a structured approach to traveler safety that spans the entire journey—from pre-trip planning and risk assessments to real-time monitoring and post-incident support. Organizations must be prepared to act quickly and effectively at every stage. As global travel grows more complex and the threat landscape widens, duty of care is no longer optional. It is a core component of responsible business operations and a prerequisite for maintaining workplace safety across a distributed workforce.

Duty of care vs. travel risk management (TRM): What’s the difference?

Duty of care and travel risk management are closely related but not interchangeable. Duty of care represents the obligation—the legal and ethical responsibility an organization has to protect its people. Travel risk management (TRM) is the execution framework that enables organizations to fulfill that obligation in a consistent and scalable way.

A mature TRM program operationalizes duty of care through three essential capabilities:

  • Locate employees wherever they are, using itinerary data, mobile signals, and user-provided information.
  • Assess the risks affecting them with reliable, continuously updated intelligence.
  • Contact them through effective two-way communication channels.

Without these capabilities, organizations may understand their responsibilities but lack the tools to act on them. Everbridge Travel Protector unifies all three capabilities in a single platform, connecting itinerary tracking, risk intelligence, and mass notification so security teams can move from awareness to action in seconds. Together, duty of care and TRM form a complete strategy for protecting business travelers.

Why is duty of care important for business travelers today?

The risk landscape for business travel has evolved dramatically. Organizations must now contend with a wide range of interconnected threats—geopolitical instability, climate-driven disruptions, cyber risks, and ongoing public health concerns—that can emerge quickly and escalate without warning.

The WEF Global Risks Report 2026 warns that geoeconomic tools such as tariffs, sanctions, and export controls are being deployed with increasing frequency by major powers, creating material risk to cross-border operations. Prolonged state-based armed conflicts continue to disrupt energy, food, and supply chains, posing direct travel and operational hazards for businesses in and near affected regions. At the same time, critical infrastructure—satellites, undersea cables, ports, and energy pipelines—is increasingly being targeted through physical or cyber-physical interventions.

Failing to meet duty of care obligations carries serious consequences. Beyond immediate risk to employee safety, organizations face legal liability, reputational damage, and operational disruption. Conversely, organizations that invest in strong duty of care practices build trust, improve employee confidence in travel, and maintain continuity in global operations. In today’s environment, duty of care is both a risk mitigation strategy and a competitive advantage.

What are the key risks facing business travelers?

Business travelers face a wide spectrum of risks that vary by destination, timing, and individual circumstances. These risks are rarely isolated—they overlap and compound one another, requiring a comprehensive and proactive approach.

Geopolitical risks
Civil unrest, political instability, and geoeconomic confrontation can disrupt travel plans and create immediate safety concerns. The WEF identifies the increasing use of sanctions, investment screening, and export controls as mechanisms that directly affect sectors like AI chip supply chains, biotech, and rare earths—meaning even routine business trips to certain regions may carry elevated risk. Organizations should prepare travelers in advance with destination-specific guidance, monitor developments in real time, and be ready to account for and assist employees if conditions deteriorate.

Cyber risks
Cyber threats have become increasingly prominent as employees rely on mobile devices and public networks while traveling. The WEF Global Risks Report 2026 explicitly flags cyber espionage and digital infrastructure disruption as growing concerns. Pre-trip training on secure device usage is essential, but organizations must also monitor for threats during travel and respond quickly to any incidents involving compromised data or systems.

Weather-related
Climate-driven disruptions are growing in both frequency and severity. Organizations should assess seasonal and regional patterns before travel, provide real-time alerts during trips, and support employees with rebooking, evacuation, or continuity planning when disruptions occur.

Crime
Crime risks vary widely by location but remain a constant concern. Preparing travelers with local safety knowledge, ensuring they have access to emergency communication tools, and providing support in the event of an incident are all critical components of a strong duty of care program.

Mega-event risk: World Cup 2026

The FIFA World Cup 2026 introduces a concentrated set of risks for any organization with employees traveling to or based in the 16 host cities across the United States, Canada, and Mexico. The expanded 48-team format will produce roughly 104 matches across 39 days beginning June 11, 2026, in Mexico City—placing extraordinary pressure on local transport, accommodation, and public safety infrastructure.

Key considerations include:

  • Crowd density at stadiums, fan zones, and transport hubs raises the potential for crush incidents, pickpocketing, and opportunistic crime during and around match times.
  • Transport disruption is expected as host cities absorb surge demand on public transit and inter-city corridors. The U.S. Federal Transit Administration has issued guidance to help host cities prepare contingency plans for moving fans—corporate travel teams should incorporate these expectations into their own advisories.
  • Multi-jurisdictional security: policing standards, emergency-response protocols, and public-order approaches differ between the U.S., Canada, and Mexico. Duty-of-care plans must account for local law-enforcement capacities in each host city.
  • Cyber and operational risk: sustained pressure on digital infrastructure (ticketing, payments, travel apps) increases the likelihood of opportunistic phishing, fake ticket scams, and localized ICT outages that could affect traveler communications.

Organizations should instruct travelers to avoid fan zones during high-risk match times if not attending, stagger movements around peak ingress and egress windows, and use vetted transport providers. For a detailed city-by-city risk breakdown, see the Everbridge World Cup 2026 Host City Risk Guide.

How should employers monitor and contact traveling employees?

To effectively fulfill duty of care responsibilities, organizations must maintain visibility into where their employees are and the ability to communicate with them at any time. This requires more than manual processes or periodic check-ins—it demands integrated systems that provide real-time insight and responsiveness.

Modern travel risk management platforms enable organizations to track employee locations using a combination of itinerary data, mobile signals, and user-provided information, all within a framework that respects employee consent and privacy. This visibility allows organizations to quickly identify who may be affected by an emerging risk and take immediate action.

Equally important is the ability to communicate through multiple channels—SMS, push notification, email, and voice. Two-way communication ensures that organizations can not only send alerts but also receive confirmations, status updates, or requests for assistance from employees. This creates a dynamic feedback loop that improves situational awareness and enables faster, more effective responses during incidents. Everbridge Travel Protector automates this locate-assess-contact cycle, reducing response times from hours to minutes.

How can organizations ensure duty of care for a global workforce?

Duty of care extends beyond business travelers to include employees working across different regions—whether they are in offices, remote locations, or hybrid environments. Ensuring the safety of a global workforce requires a consistent and scalable approach that accounts for regional differences while maintaining centralized oversight.

Organizations should begin by establishing a comprehensive travel risk management program that integrates employee safety principles across the entire workforce. This includes:

  • Maintaining real-time visibility into employee locations across all work arrangements.
  • Delivering relevant, location-specific risk intelligence tailored to each employee’s context.
  • Enabling timely, multi-channel communication regardless of where employees are based.
  • Ensuring compliance with regional regulatory requirements, including emerging frameworks like DORA and NIS2 in Europe (discussed below).

A centralized platform that unifies these capabilities allows global security teams to operate with a single source of truth while still adapting to local conditions.

How can companies protect business travelers specifically while on the road?

While global workforce protection provides a broad foundation, business travel introduces unique challenges that require more focused and real-time attention. Employees on the move are exposed to changing environments, unfamiliar conditions, and increased uncertainty—making continuous monitoring and support essential.

Organizations must ensure that traveler itineraries are tracked dynamically and updated as plans change. Risk alerts should be tailored to the traveler’s exact location and delivered in real time, allowing employees to make informed decisions as situations evolve. Additionally, providing immediate access to assistance—whether for medical emergencies, travel disruptions, or security incidents—is critical to maintaining safety and confidence throughout the journey.

Practical steps include:

  • Requiring itinerary registration and emergency contact details before departure.
  • Mandating travel insurance with event-disruption coverage for trips coinciding with mega-events.
  • Delivering digital-security briefings (corporate VPN use, avoidance of fake ticketing sites, mobile device protections).
  • Establishing clear escalation paths from on-the-ground employees to corporate crisis teams.

By focusing specifically on the travel experience, organizations ensure that duty of care is not just a policy but an active, ongoing practice that supports employees at every stage of their trip.

Key risks for corporate travelers and employer actions 

Understanding risks conceptually is important, but organizations also need a clear, actionable framework for responding to them. The table below summarizes the most pressing 2026 risks alongside early warning signs and recommended actions across each phase of travel.

What standards and regulations apply to duty of care?

Organizations looking to formalize their duty of care approach should align with recognized international standards and regulatory frameworks. These standards provide guidance on best practices and help ensure that programs are both effective and defensible.

ISO 31030 offers specific guidance on managing travel-related risks, helping organizations build structured and consistent travel risk management programs. ISO 45001 focuses more broadly on occupational health and safety, providing a framework for protecting employees in all work environments. The OSHA General Duty Clause requires U.S. employers to maintain a safe workplace—an obligation that courts have extended to employees traveling for business purposes.

DORA and NIS2: New compliance dimensions for duty of care

Two European regulations that took effect in January 2025 have significant implications for how organizations manage duty of care:

  • DORA (Digital Operational Resilience Act) requires financial-sector entities and their critical ICT providers to maintain operational resilience, including incident reporting and business continuity testing. For organizations with traveling employees who depend on digital systems, DORA’s requirements reinforce the need for resilient communication and monitoring infrastructure that works even when primary channels fail.
  • NIS2 (Network and Information Security Directive) broadens cybersecurity obligations across essential and important sectors in the EU, mandating risk management measures and incident notification within tight timelines. Organizations must ensure their duty-of-care programs account for cyber incidents affecting travelers—such as compromised devices or disrupted communications—and that they can meet NIS2’s reporting requirements.

Aligning with these standards not only improves safety outcomes but also demonstrates a commitment to responsible governance and positions organizations well for regulatory scrutiny.

Jurisdiction and scope

Duty of care obligations are not uniform across all regions. Legal requirements can vary significantly by country, state, or jurisdiction, and organizations must ensure they understand and comply with the specific regulations that apply to their operations and their travelers’ destinations.

This is especially relevant in 2026 as the FIFA World Cup spans three countries with different legal systems, labor laws, and emergency-response frameworks. Organizations should work with legal counsel to map their obligations in each jurisdiction where employees will travel.

This article provides general guidance rather than legal advice. Organizations should consult qualified legal professionals to understand the specific duty of care requirements applicable to their operations.

How does Everbridge support duty of care?

With consent-based traveler tracking, automated alerts, and integrated incident management capabilities, organizations can move from reactive to proactive risk management. This not only improves employee safety but also enhances organizational resilience in the face of an increasingly complex global risk environment.

Everbridge provides an integrated platform that helps organizations fulfill their duty of care obligations across the full travel lifecycle. By unifying traveler location intelligence, real-time risk data, and multi-channel communication in a single system, Everbridge enables security and travel teams to move from awareness to action without switching between disconnected tools.

Key capabilities include:

  • Travel Protector: Automatically ingests traveler itineraries, correlates them with real-time risk intelligence from thousands of verified sources, and enables two-way communication so organizations can locate, assess, and contact travelers within minutes of an emerging incident.
  • Dynamic risk visualization: Maps employee locations against active threats—including mega-event risks like the FIFA World Cup 2026—so security teams can see exposure at a glance and prioritize response.
  • Automated check-ins and wellness confirmations: Enables organizations to verify employee safety through scheduled or event-triggered check-ins, reducing manual effort and ensuring no one falls through the cracks.
  • Workplace safety integration: Extends duty of care beyond travelers to the broader workforce, supporting organizations that need a unified approach to employee safety across offices, remote locations, and travel.
  • Compliance support: Helps organizations document their duty-of-care actions and maintain audit trails aligned with ISO 31030, ISO 45001, DORA, and NIS2 requirements.

Frequently Asked Questions

What is an employer’s duty of care for business travelers?

An employer’s duty of care is the legal and ethical obligation to protect traveling employees from foreseeable risks by assessing destinations, monitoring locations and threats during trips, maintaining multi-channel communication, and providing post-incident support; platforms like Everbridge help operationalize those practices. This obligation is grounded in frameworks such as ISO 31030, ISO 45001, and the OSHA General Duty Clause and is affected by regulations like DORA and NIS2.

How does travel risk management differ from duty of care? 

Duty of care is the obligation; travel risk management (TRM) is the operational framework and toolset (location tracking, risk intelligence, two-way communication) that lets organizations meet that obligation consistently and at scale.

What technology supports employee check-in systems? 

Check-in systems combine automated itinerary ingestion, mobile app check-ins, GPS/network-based location services (with consent), and two-way mass notification to collect and aggregate responses; Everbridge Travel Protector brings these elements together and automates escalation for non-responses.

How to implement a lone worker safety program? 

Start by identifying lone-worker roles, assess risks, set mandatory check-in protocols and escalation procedures, deploy resilient check-in and panic-alert technology, train staff, and continuously monitor and refine the program—Everbridge’s employee safety solutions support these steps with automated check-ins, location intelligence, and panic-button functionality.

How does traveler tracking work in Everbridge? 

Everbridge uses a combination of travel itinerary data, mobile location signals, and employee-provided information to create real-time visibility into where travelers are located. This is done within a framework that emphasizes transparency, consent, and data protection. 

What about data privacy and consent? 

Organizations must be transparent about how employee data is collected, used, and stored. Employees should have the ability to opt in or out where appropriate, and data retention policies should align with relevant privacy regulations to ensure compliance and trust. 

What regulations apply to duty of care for international travelers? 

Key frameworks include ISO 31030 (travel risk management), ISO 45001 (occupational health and safety), and the OSHA General Duty Clause; in Europe, DORA and NIS2 add operational resilience and cybersecurity reporting obligations that organizations must account for in their duty-of-care programs.

Explore Everbridge TRM with an instant personalized demo. Choose the topics that are most relevant to your business need.

Request a Demo