ISO 31030 Explained: Why It's More Important Than Ever for Travel Risk Management Teams
ISO 31030 took decades of travel risk practice and wrote it down as an international standard, yet most organizations still fall short of it. Here's what the standard actually covers, why adoption lags, and why a worsening risk landscape makes it the benchmark duty of care gets measured against.

For years, travel risk management ran on institutional knowledge and borrowed best practices. Security leaders built programs from what worked at their last company, what they picked up from peers, or what felt right given the threats in front of them. There was no formal standard and no shared definition of what a complete program should include. Two companies could both claim they had a travel risk program and mean completely different things.
That changed in September 2021, when the International Organization for Standardization published ISO 31030, formally titled Travel risk management: Guidance for organizations. The standard took decades of industry experience and codified it into a single document that defines what duty of care actually requires for traveling employees. It's a specification, written down, that anyone can hold a program against.
Adoption has been slow. An Everbridge study found that 76% of surveyed C-suite executives did not have a solid travel risk management program in place as defined by ISO 31030. At the same time, the International SOS Risk Outlook Report notes a sharp year over year increase in destinations rated elevated or high risk. The risk environment keeps getting worse while most organizations still operate without a program that meets the standard. That gap deserves attention, and it's the reason this article exists.
Where the standard came from, and what it is
ISO is a federation of 168 national standards bodies, the same organization behind quality management standards like ISO 9001 and information security standards like ISO 27001. ISO 31030 was derived from ISO 31000, the general risk management standard, and adapted specifically for organizational travel. The people who drafted it came from the industry: security practitioners, medical assistance providers, travel managers, and academics who had spent careers watching programs succeed and fail.
One thing to get straight early: ISO 31030 is a guidance standard, not a certifiable one. There's no audit, no certificate to hang on the wall, and no law that says you have to comply. You use it by assessing your own program against the guidance, then closing the gaps that matter for your travel footprint and risk profile.
Some leaders hear "voluntary guidance" and relax. That's a mistake, and the legal history covered later in this piece shows why. Courts and regulators care about what a reasonable organization would have done, and once an international standard exists, "reasonable" has a written definition.
What ISO 31030 actually covers
The standard lays out the full lifecycle of travel risk management, from the decision to travel through post-trip review. It also casts a wider net than most people expect. The risks in scope run from road accidents and routine health incidents through disease outbreaks, natural disasters, conflict, crime, and security threats, and it explicitly includes travelers' mental health alongside their physical safety. It pushes program owners to look past the dramatic scenarios and consider unglamorous factors like road conditions, the reliability of local telecommunications, and the quality of nearby medical care. In most travel programs, a road accident on the way from the airport is a far more likely event than a kidnapping.
The core requirements break down like this.
Risk assessment tied to destination, traveler, and activity. You evaluate where someone is going, who they are, and what they'll be doing there. Those three data points drive the security profile for that trip. A healthy 30-year-old attending a conference in Copenhagen and a senior executive with a heart condition visiting a mine site in the Sahel need very different levels of preparation, and the standard makes that explicit. Traveler profile matters: experience, medical needs, and personal risk factors all change the exposure. Risk assessment can't be generic, and it can't be skipped.
Travel policy and authorization. The standard expects clear rules for how travel gets approved. That means mandatory booking channels so the organization actually knows where people are, approval thresholds tied to destination risk ratings, destination restrictions where warranted, and a defined path for exceptions. If an itinerary changes mid-trip in a way that falls outside policy, someone responsible should find out about it quickly rather than after the fact.
Clear governance and accountability. Someone owns the program. Roles are defined across security, travel, HR, legal, and medical functions, and there's a process for escalation and decision-making when a trip involves elevated risk. Plenty of organizations ran on implicit ownership for years, where everyone assumed someone else was watching. ISO 31030 formalizes it.
Traveler preparation and communication. Employees get briefed on the risks they'll face and the resources available to them before they leave. That includes pre-trip security briefings, safety training where the risk justifies it, in-country support contacts, and clear guidance on what to do when something goes wrong. It continues during the trip: real-time alerts when a situation develops near a traveler, check-in procedures, and reliable ways to reach people through more than one channel.
Vetted transportation and accommodation. The standard covers the logistics layer too. Ground transportation providers, routes, hotels, and other vendors get assessed for traveler safety, and sourcing decisions in higher-risk locations take security into account rather than price alone.
Incident response and duty of care protocols. When an incident occurs, there's a plan. The standard expects organizations to define how they'll respond to medical emergencies, security events, natural disasters, and other crises affecting traveling employees, including escalation paths, assistance and evacuation arrangements, and coordination with business continuity.
Continuous monitoring and improvement. Programs get reviewed. Incidents and near misses get analyzed. The organization measures performance, learns from what happened, and updates the program accordingly instead of letting it fossilize.
None of this is revolutionary if you've been doing travel risk management for a decade. It's the first time these requirements have been written down in one standard that applies across industries and geographies, and that changes what happens when programs get compared, audited, or challenged.
Why adoption is still low
The 76% gap exists for a few reasons. Some organizations see ISO 31030 as unnecessary bureaucracy, another compliance box that doesn't add real value. Others lack the resources to build a program from scratch or retrofit an existing one to meet the guidance. Many simply don't know the standard exists.
Structure plays a big role too. Travel risk touches security, travel management, HR, legal, medical, and regional leadership, and those teams rarely share systems or data. Everbridge's work with enterprise programs keeps surfacing the same failure points: fragmented ownership across departments, inconsistent approval processes, limited visibility into where travelers actually are, delayed awareness of critical events, manual outreach and check-ins, and unclear escalation paths when things go wrong. A standard can name those problems, but someone inside the organization still has to fix them.
There's also a perception problem. Travel risk management often gets treated as a subset of HR or procurement rather than a security function. When it lives in the wrong part of the organization, it doesn't get the attention or the budget it needs. ISO 31030 helps clarify that this is a risk management discipline with real duty of care implications, but that message hasn't reached every executive team yet.
The legal backdrop
Duty of care is a legal obligation, and courts have already shown what happens when organizations fall short of it. The case people in this field cite most is Dennis v Norwegian Refugee Council. Steve Dennis, an aid worker, was shot and kidnapped during an attack in Dadaab, Kenya in 2012. He sued his employer, and in 2015 the Oslo District Court found the organization grossly negligent, ruling that the risks were foreseeable and that the organization had failed to manage them. He was awarded millions of kroner in damages, and the case reshaped how the entire aid sector thinks about staff security.
That precedent matters well beyond the humanitarian world. When a traveling employee is harmed and litigation follows, the question becomes whether the organization took reasonable steps to protect them. Before 2021, "reasonable" was argued case by case with expert witnesses. Now there's an international standard that describes what a competent program looks like, and it's hard to imagine plaintiffs' lawyers not using it as the measuring stick.
Why the standard matters more now
The risk landscape has shifted. The International SOS Risk Outlook shows more destinations moving into elevated and high-risk categories each year. Geopolitical instability, civil unrest, health crises, and climate-related disruption are all increasing at the same time. Employees are traveling to more places, often with less advance notice, and the threats they face are more varied than they were even five years ago.
ISO 31030 gives you a baseline. It defines what a defensible program looks like if something goes wrong and you need to demonstrate that you took reasonable steps to protect your people. It won't guarantee that nothing bad happens. It is evidence that you built a program designed to reduce risk and respond effectively when incidents occur, and in a courtroom or a board meeting, that evidence carries weight.
The benefits reach further than legal defensibility. Organizations that align with the standard report gains that show up on the business side: the ability to operate confidently in higher-risk markets, stronger assurance to investors, banks, and business partners that travel risk is under control, better supply chain credibility with customers, improved staff confidence and retention, and in some cases lower insurance premiums because the organization can demonstrate effective control of travel-related risk. A well-run program is a business enabler, and the standard gives you the vocabulary to make that case internally.
For organizations that already have a travel risk program, the standard works as an audit tool. You map your current processes against it and the gaps become visible fast. For organizations starting from scratch, it's a blueprint that saves you from reinventing decades of hard-won lessons.
What to do with it
If you're responsible for travel risk management, get a copy of ISO 31030 and read it. It's not long, and it's written in plain language. Compare it to what you currently have in place and write down every gap you find.
Experience from consultancies that run these gap analyses suggests the same weak spots come up again and again: no mandatory booking process, no pre-travel authorization step, no pre-trip risk assessments, travel policies that never mention risk at all, sourcing processes that ignore security, and no safety training for travelers heading somewhere difficult. Check those areas first, because the odds are good at least one of them applies.
Then prioritize based on your organization's actual travel patterns and exposure. If executives go to high-risk destinations regularly, focus on incident response and traveler preparation. If nobody can say who owns the program, start with governance. A program that fixes its two biggest gaps this quarter beats a five-year plan that never gets funded.
Finally, use the standard to build internal support. When you need budget or executive buy-in, ISO 31030 gives you a reference point that isn't just your opinion. It's an international standard that reflects industry consensus on what duty of care requires, backed by case law showing what failure costs. That's a much stronger position to argue from than "trust me, we need this."
The organizations that treat ISO 31030 as a working document rather than a compliance exercise will be the ones with programs that hold up when they're tested. Given where the risk numbers are heading, more of them will be tested.