Initiative Training Group Book a Consultation
Boardroom

Dispatches → Category

Building an ISO 31030-aligned travel policy from scratch

A practical overview of ownership, approvals, preparation, response and review.

James Gribben

19 July 2026 · 8 min read

Most organisations already have a travel policy. It explains how to book a train, which class of airfare may be used and whether an employee can claim for breakfast. Useful, certainly, but it is an expenses policy wearing a slightly grander hat.

This is the Policy Illusion: the reassuring belief that having a document titled “Travel Policy” on SharePoint means the organisation is managing travel risk. It isn’t. It’s managing receipts.

ISO 31030 provides a framework for putting that right. It does not offer a policy that can be copied, renamed and redeposited on SharePoint. It provides guidance for building a system around the organisation's actual travellers, destinations, activities and capabilities.
That distinction matters.

Start with what the policy is meant to achieve

The purpose of a travel risk policy is not to prevent travel. Nor is it to produce enough paperwork to make every journey feel like a military deployment. Its purpose is to help the organisation make informed, consistent and defensible decisions.

A useful policy should:

  • protect travellers;
  • support business activity;
  • define responsibilities;
  • establish how risk is assessed;
  • explain how incidents will be managed.

The controls must be proportionate.

A routine meeting in Brussels does not require the same preparation as a project in a fragile state. Treating every trip as high risk creates bureaucracy that staff will quietly work around. Treating every trip as routine creates unpleasant surprises.

Be clear about who and what it covers

The policy should state who it applies to. That may include employees, directors, contractors, consultants and, in some cases, accompanying family members. It should also define the types of travel covered: domestic travel, international travel, remote assignments and trips combining business with personal leave. The uncomfortable questions should be answered before somebody is stranded. When does the organisation's responsibility begin? What happens if the traveller extends the trip privately? Does company support continue during personal days? Who pays if private arrangements disrupt the business journey? Ambiguity may feel flexible. It usually becomes expensive.

Put someone in charge — and make sure they are competent

Travel risk management cannot belong vaguely to "the business". A senior person should own the programme and possess enough authority to ensure the policy is implemented, funded and reviewed. Responsibilities should be clear. Senior leadership approves the policy and determines the organisation's appetite for risk. Managers approve travel. HR considers welfare and individual needs. Security, health and safety, insurance and operations provide specialist advice. Travellers follow instructions, complete preparation and report concerns. ISO 31030 also asks a question many organisations prefer to avoid: are the people running the programme actually competent to do so? Assessing travel risk, briefing travellers and managing an overseas incident are skills, not instincts. The policy should state how those responsible will be trained, and how that competence is maintained. A risk assessment is only as good as the person completing it, and enthusiasm is not a qualification. The organisation owes travellers proper support. Travellers, in return, must provide accurate information and comply with reasonable controls. Duty of care is not a magic spell that removes all personal responsibility

Decide how much risk the organisation can support

One of the most important parts of the policy is the organisation's travel risk appetite. Which destinations require additional approval? Who may approve high-risk travel? When must specialist advice be obtained? What risks will the organisation simply not accept? These decisions should not depend on which manager is available or how loudly the traveller insists that everything will be fine. Here is the point most commentary on ISO 31030 misses: risk appetite must reflect capability. A multinational with local offices, medical support and tested evacuation arrangements may be able to manage travel that would be reckless for a small business with no local presence and no emergency provider. The destination is only half the equation. The other half is whether the organisation is genuinely equipped to manage what may happen there. Two organisations can send travellers to the same city on the same day, and one of them is taking a far greater risk — not because the threat differs, but because the safety net does.

Assess the journey, not merely the country

A destination risk assessment should examine the actual itinerary and activity. It may consider crime, unrest, terrorism, health, road safety, medical provision, local law, culture, accommodation, communications and cyber threats. Country ratings are useful, but they are not enough. Risk can vary greatly within the same country. A city centre may be operating normally while a border region is unstable. A daytime road journey may be acceptable while the same route after dark is not. The traveller must also be considered. Age, health, mobility, experience and language ability may affect the level of risk or the support required. So may characteristics the organisation finds harder to discuss: gender, nationality, dual nationality, religion and sexual orientation can all materially change a traveller's exposure in certain jurisdictions. A policy that cannot say this plainly cannot manage it. This is not about labelling people as vulnerable. It is about understanding that the same journey can affect different travellers in different ways — and giving them the information and choices that reflect it.

Make approval proportional

The approval process should be simple enough to use and robust enough to matter. Low-risk, familiar travel may require little more than a recorded itinerary, contact details and confirmation of insurance. Higher-risk travel may require a formal assessment, senior approval, a traveller briefing, communications plan, medical arrangements and emergency procedures. The process should escalate with the risk. If every journey requires six forms and a committee meeting, staff will book around the system. If nothing requires approval until after the booking has been made, there is barely a system to work around. On insurance: "confirmation of insurance" should mean confirmation that the cover actually applies. Travel insurance routinely excludes high-risk destinations, certain activities and journeys undertaken against government advice, and many policies quietly lapse the moment the trip stops matching what was declared. Discovering an exclusion clause from a hospital bed in another country is an education nobody needs.

Choose suppliers before you need them

The policy should address how travel suppliers are selected and reviewed: travel management companies, assistance and evacuation providers, accommodation, ground transport and local security support. These arrangements are controls, not conveniences. A vetted hotel with reliable communications is a risk decision. A local driver who knows which routes to avoid is a risk decision. An assistance provider that answers the phone at 3 a.m. is very much a risk decision. Selecting these providers during a crisis means selecting from whoever answers first. The time to test a supplier is before the organisation depends on them.

Prepare and support the traveller

Before departure, the traveller should receive information suited to the journey: security advice, health guidance, cultural information, emergency contacts, insurance details and communications procedures. Telling somebody to "remain vigilant" does not qualify as preparation. It is what organisations say when they would like to sound responsible without doing anything especially demanding. Support during travel must also be credible. The organisation should know where its travellers are expected to be, how to contact them and how to respond when conditions change. Technology can help, but an app is not a programme. Somebody still has to monitor the information, make decisions and act. Monitoring also means acting on what changes. A trip approved three weeks ago was approved against conditions that may no longer exist. The policy should define what triggers a re-assessment of approved or in-progress travel — a change in government advice, civil unrest, a health alert, a supplier failure — and who has the authority to amend, delay or recall the journey. Approval is a snapshot. Risk is a moving picture.

Handle traveller data properly

A travel risk programme runs on personal information: itineraries, locations, medical conditions, emergency contacts, sometimes real-time tracking. That data deserves the same discipline as the travel itself. The policy should state what is collected, why, who can see it, how long it is kept and how travellers' privacy is protected — particularly for tracking and medical information. In the UK and EU this is not optional courtesy; it is data protection law. A programme that safeguards the traveller while mishandling their data has simply relocated the risk.

Plan for when things go wrong

The policy should connect directly to emergency procedures. The organisation should know how it will respond to serious illness, injury, crime, detention, civil unrest, missing travellers, natural disasters and evacuation. The critical questions are straightforward. Who receives the call? Who leads the response? Who has authority to spend money, suspend travel or relocate staff? Which external providers will be used? How will the family be supported? These arrangements must work outside office hours. A 24-hour emergency number that rings unanswered on an empty desk is not support. It is a practical joke with legal implications. Evacuation should also be treated realistically. Leaving the country may not always be possible or sensible. The safer option may be to shelter in place, move to another city or use commercial transport while it remains available. The policy should define who makes that decision and on what basis.

Write it down, or it never happened

Every significant decision in the programme — the assessment, the approval, the briefing, the change of plan, the reason a warning was or was not acted upon — should leave a record. This is not bureaucracy for its own sake. If an incident ends in front of a coroner, a regulator or an employment tribunal, the organisation will be asked to show not just that it made a reasonable decision, but that it made one at all. An undocumented judgement call, however sensible at the time, is indistinguishable from negligence in hindsight. Documentation is also what allows the programme to learn. It is difficult to review a decision nobody recorded.

Learn from every journey

Travellers should report incidents, near misses, unsafe accommodation, transport failures and weaknesses in support. Higher-risk journeys should be reviewed after completion. What worked? What failed? Was the assessment accurate? Did the supplier perform properly? Were communications effective? The organisation should also monitor basic indicators: completed assessments, approval compliance, incidents, response times, supplier failures and corrective actions. The purpose is not to create a dashboard full of impressive colours. It is to discover whether the system works — and a policy that never changes as a result is not mature, merely old.

The policy is only the beginning

An ISO 31030-aligned policy should be supported by practical tools, each answering a question the policy raises:

  • a risk-rating framework — so "high risk" means the same thing to everyone;
  • destination and traveller assessments — so decisions rest on the actual journey and the actual person;
  • approval procedures — so authority matches risk;
  • booking and supplier standards — so the safety net exists before it is needed;
  • communication protocols — so travellers are reachable and informed;
  • incident response and evacuation plans — so the first hour of a crisis is not spent deciding who is in charge;
  • reporting and review processes — so the system improves instead of ageing.

The policy sets the direction. These tools make it real.
Building the system does not require a vast security department or a control room lined with glowing screens. It requires clear ownership, proportionate assessment, workable procedures and an honest understanding of what the organisation can and cannot support.
Begin with how travel happens now. Who approves it? Where is the itinerary held? Who receives an emergency call? How are travellers briefed? What happens when the destination deteriorates?
The answers will expose the gaps. That is precisely the point.
A good travel risk policy does not eliminate risk. It ensures that risk is recognised, decisions are deliberate and travellers are not left to discover the organisation's limitations from an overseas hospital, police station or closed airport.
That is what meaningful alignment with ISO 31030 looks like.

Assess your current arrangements

The Initiative Training Group ISO 31030 Travel Risk Readiness Assessment takes your existing arrangements — however informal — and scores them across governance, risk assessment, traveller preparation, communications and emergency response.

You receive a clear picture of where the programme stands, which gaps carry the greatest exposure, and what to fix first.

Most organisations discover the gaps are fewer than they feared and more serious than they assumed. Better to make that discovery now, in working hours, with time to act on it.

Written by James Gribben

Role / Title, Initiative Training Group

← Back to Dispatches

Related reading

Prefer the deeper guides and templates?

Visit the Knowledge Centre