Initiative Training Group Book a Consultation
Boardroom

Dispatches → Category

Why Duty of Care Is Becoming a Board-Level Issue

A practical overview of ownership, approvals, preparation, response and review.

James Gribben

19 July 2026 · 8 min read

Protecting travelling employees is no longer something directors can leave entirely to HR, security or the traveller.

When an employee travels for work, the organisation does not pack away its responsibilities with the out-of-office message.

The traveller may be thousands of miles from headquarters, using an unfamiliar airport, staying in a hotel selected by a booking system and working in conditions the board has never seen. Yet the journey still takes place on the organisation's behalf, on the strength of a decision taken at home.

That last point is the one directors most often miss, and it is why duty of care is a governance matter rather than a travel-management one.

The liability is created before the traveller leaves

There is a common assumption that responsibility for an overseas incident sits somewhere overseas. The legal position is more interesting than that, and considerably less comfortable for the board.

The Health and Safety at Work etc. Act 1974 does not generally apply outside Great Britain. Work carried out abroad falls under the health and safety law of the country concerned, and the statutory extensions that do exist are directed principally at offshore installations and the territorial sea rather than at business travellers. A company can face liability under the Act where the breach of the relevant duty occurred in Great Britain — and it may still be liable in connection with an incident that happened elsewhere.

Read that carefully, because it relocates the risk rather than removing it.

The breach that occurs in Great Britain is the planning. The risk assessment nobody completed. The briefing nobody gave. The approval granted without information. The emergency arrangements nobody tested. Those decisions are taken at head office, under the board's governance, long before anyone reaches an airport.

The civil position reinforces the same conclusion. An employer's common law duty of care travels with the employee, and a worker injured or made ill overseas as a consequence of how the trip was organised may bring a claim against their employer. The Management of Health and Safety at Work Regulations 1999 also require employers to carry out a suitable and sufficient assessment of the risks their employees are exposed to at work — a duty that bites on the assessment itself, wherever the work is ultimately performed.

The board-level conclusion is straightforward. The organisation's exposure is manufactured domestically, in the arrangements it makes, and it is governed domestically too.

Business travel creates organisational exposure

Travel risk is rarely confined to dramatic destinations.

A traveller can be affected by illness, road traffic collisions, extreme heat, crime, civil disruption, cyber fraud, cancelled flights or changing border requirements. A routine journey can deteriorate quickly, particularly when nobody is monitoring conditions after the booking has been made.

The board-level question is therefore not:

Was the destination considered safe?

It is:

Did the organisation make a reasonable decision, prepare the traveller, monitor foreseeable change and retain the ability to assist?

Those are questions about policy, authority, resources and accountability — which is to say, precisely the matters boards exist to govern rather than to admire from a comfortable distance.

Where Directors are personally exposed, and where they are not

Precision matters here, because the subject attracts a good deal of loose commentary.

Under the Corporate Manslaughter and Corporate Homicide Act 2007, an organisation may commit an offence where the way its activities were managed or organised causes a death and amounts to a gross breach of a relevant duty of care, with the way senior management organised those activities forming a substantial element of the breach. The relevant duty is defined by reference to existing duties in the law of negligence, including the duty an employer owes its employees; the Act creates no new duties.

Directors should understand two things about it.

First, that Act does not create personal criminal liability. Section 18 provides that an individual cannot be guilty of aiding, abetting, counselling or procuring the commission of the corporate offence. Prosecutions under it are of the organisation.

Second, that provides considerably less comfort than it first appears. Individual liability is untouched elsewhere: a director may face prosecution for gross negligence manslaughter, and section 37 of the Health and Safety at Work Act allows proceedings against an officer of the organisation where an offence by the body corporate was committed with their consent or connivance, or was attributable to their neglect. Organisations and individuals can be prosecuted for health and safety offences on the same facts as a corporate manslaughter case.

So the honest summary for a board is this. The corporate offence looks at how senior management organised the activity. The personal exposure arrives through a different door. Both are examining the same thing: whether the people at the top established a credible system, or assumed one existed.

What good governance looks like here

This does not mean the board should approve hotels or inspect airport transfers.

The Health and Safety Executive and the Institute of Directors set out the leadership expectation plainly in their joint guidance for directors: health and safety is a board-level responsibility, requiring the board to plan, deliver, monitor and review, with a named director responsible for it. Delegating the work is sensible. Delegating all interest in the outcome is not.

The board should be satisfied that a small number of questions have credible answers.

Five questions for the board

  1. Who owns travel risk? Not which department — which named individual, with what authority and what budget.
  2. What level of travel risk will we accept, and who may approve exceptions? If the answer varies by whichever manager is available, there is no risk appetite, only a habit.
  3. How are travellers actually prepared, and how do we know? A briefing that exists as an attachment nobody opened is not preparation.
  4. Who monitors change after approval, and who can act on it? Conditions move. An approval is a snapshot of a moment that has passed.
  5. When did we last test the emergency arrangements, and what did we learn? Including out of hours, when most incidents happen.

A board that cannot get straight answers to those five has found its gap analysis

Assurance is not the same as reporting

Boards are routinely shown travel risk information that reassures without informing: compliance percentages, incident counts, a supplier's service-level report.

Useful assurance is different in kind. It shows evidence that the system works when tested — a recorded exercise of the emergency arrangements with findings and actions; confirmation that the out-of-hours number was called and answered by someone able to make a decision; a review of a real incident, including what failed; the identity of travellers currently in a disrupted location, produced within minutes rather than by email chain.

The distinction is between being told that controls exist and seeing what happened when someone leaned on them.

This is what we call the Policy Illusion: the comfortable belief that because a travel policy exists, travel risk is being managed. A policy describes intentions. A programme produces decisions — and it produces them at three in the morning, when a border has closed and somebody has to authorise a hotel, a flight and a driver without waiting for the office to open.

The existence of a policy will not answer criticism if nobody followed it, monitored it or knew who could authorise help.

The commercial case, which usually moves faster than the legal one

Directors weighing expenditure should note that the argument is not solely defensive.

Clients, insurers, funders and tender processes increasingly ask how an organisation manages travel risk, particularly where staff work in demanding environments. An organisation that can evidence its arrangements answers those questions in a paragraph. An organisation that cannot may find the question decides the contract.

Insurance deserves specific attention. Travel and liability cover is written on conditions, and assumptions about what a policy will pay for do not survive contact with an exclusion — high-risk destinations, travel against government advice, undeclared activities. The board should know whether the organisation's arrangements support its cover or quietly undermine it.

And there is a workforce dimension. People notice how an organisation behaves when a colleague is in difficulty abroad. It is remembered long after the incident, by those who were not involved as much as by those who were.

ISO 31030 provides the structure

ISO 31030 gives guidance on developing, implementing, evaluating and reviewing travel risk management arrangements, covering policy, risk assessment, prevention, mitigation, communication and response.

It does not remove the board's responsibility, and it does not guarantee that incidents will not occur. What it provides is a structured, recognised basis for demonstrating that travel decisions are made deliberately — and a framework a director can point to when asked what standard the organisation applied.

Duty of care is becoming a board-level issue because the consequences of getting it wrong already were.

A written position for your board. The ITG ISO 31030 Travel Risk Management Assessment establishes where responsibility currently sits, which controls are working, and where the organisation is relying on assumption rather than evidence — set out in a form directors can take to an audit or risk committee. Most boards find the picture is clearer than they expected and the ownership less settled than they assumed.

Initiative Training Group helps organisations assess and strengthen their travel risk management arrangements.

Sources

  1. Health and Safety at Work etc. Act 1974, section 2 (general duties of employers) and section 37 (offences by bodies corporate) — legislation.gov.uk
  2. The Health and Safety at Work etc. Act 1974 (Application outside Great Britain) Order 2013 — legislation.gov.uk
  3. Management of Health and Safety at Work Regulations 1999, regulation 3 (risk assessment) — legislation.gov.uk
  4. Corporate Manslaughter and Corporate Homicide Act 2007, sections 1, 2 and 18 — legislation.gov.uk
  5. Crown Prosecution Service, prosecution guidance on corporate manslaughter — cps.gov.uk
  6. HSE and Institute of Directors, Leading health and safety at work (INDG417) — hse.gov.uk
  7. ISO 31030:2021, Travel risk management — Guidance for organizationsiso.org

This article is general commentary on governance and is not legal advice. Organisations should take their own advice on their specific circumstances.

Written by James Gribben

Role / Title, Initiative Training Group

← Back to Dispatches

Related reading

Prefer the deeper guides and templates?

Visit the Knowledge Centre