
Field Notes
Geopolitical Risk and the Duty of Care Gap: When Travel Risk Intelligence Becomes a Legal Liability
TL;DR
The 2015 Dusek v StormHarbour ruling found that liability begins not when an employer sends someone into danger, but when they fail to ask whether the danger exists. ISO 31030 has since operationalised that principle into a benchmark most travel risk programmes are not meeting.
In January 2015, the English High Court found StormHarbour Securities liable for the death of an employee killed in a helicopter crash in the Peruvian Andes. The judgment in Dusek v StormHarbour Securities LLP was specific: the company had not sent him somewhere it knew to be unsafe. It had done nothing to find out whether it was safe, and that omission, not the accident itself, created the liability.[^1] A decade later, that principle has been operationalised into a rising standard that most corporate travel risk programmes are not meeting.

Why ISO 31030 Has Become the Geostrategic Benchmark in Duty-of-Care Claims
ISO 31030:2021 is not law and employers cannot be certified against it, but courts increasingly use it as the benchmark for a single question: did the employer do what a reasonable employer should have done? The answer in 2026 requires more than it did when the standard was published.
- A published benchmark now exists. ISO 31030, Travel risk management: Guidance for organizations, was published in September 2021.[^2] It is guidance, not law, and no court is bound by it. What we infer: once a written standard exists and is widely adopted, a programme that predates it becomes harder to defend as reasonable, because the comparison is no longer to what peers happened to do but to a document the organisation could have read.
- Statutory obligations are unchanged but more visible. The UK Health and Safety at Work Act 1974 extends the duty to protect employees to business travel. The US OSHA General Duty Clause applies similarly. In the US, the special-errand exception to the "coming and going" rule can pull travel outside normal hours back inside the scope of employment where the trip serves the employer, though what qualifies is defined jurisdiction by jurisdiction.[^3]
- Claims trajectory is upward. Civil claims for negligence in business travel incidents are rising. In English law jurisdictions, fatal accident claims of the Dusek type carry significant damages and separate litigation costs.

The Three Gaps Where Geopolitical Risk Creates Employer Exposure
The organisations most exposed to duty-of-care claims are not those sending employees into manifestly dangerous places. They are those with monitoring gaps that allow foreseeable risk to become unmanaged risk.
- Shadow travel. Nearly a third of companies running a corporate booking tool report that 20 percent or more of travel spend is booked outside it.[^4] An employee who books a connecting flight directly or extends a trip using personal accommodation steps outside the duty-of-care tracking system the company believes it has. The incident risk does not follow the booking system.
- Intelligence depth gap. The Dusek judgment was explicit that adequacy of risk assessment is proportional to foreseeability of the specific risk. A chartered flight to a remote project site with unstable aviation infrastructure, operated by a company in financial difficulty, requires a specific assessment, not a regional advisory.[^1] Most corporate travel risk systems provide level-two coverage: location tracking and generic country advisories sourced from government portals. That is not a proportionate response to foreseeable specific risk.
- Sectoral threat mismatch. G4S and Allied Universal's World Security Report 2025 found APAC executives at greater risk of violence than those in any other region.[^5] That finding is not reflected in most corporate travel risk programmes for the region, which remain oriented toward health and infrastructure rather than targeted threat. Executives in technology, aerospace, defence, and extractives require threat assessments calibrated to sector, profile, and specific itinerary.

What Decision-Grade Travel Risk Intelligence Requires from Risk Functions
The legal distinction that matters is between an employer who provided a risk assessment and one who provided a proportionate one. Proportionality is calibrated to the foreseeable risk, not to the average risk across all travel destinations.
- Profile-specific pre-travel briefings. A senior executive travelling to Jakarta for meetings with a company in active dispute with a local government entity needs more than a country advisory. The relevant picture is the specific threat environment for that company, that sector, and that executive's profile, cross-referenced against the current political calendar and local security infrastructure.
- Shadow travel monitoring. Duty-of-care obligations follow the employee, not the booking channel. Risk functions need a mechanism to capture itinerary data that falls outside approved systems. Without it, they cannot demonstrate proportionate care when an incident occurs outside the tracked perimeter.
- Board-level governance reporting. What we infer: travel risk is migrating from a security operations matter into a finance and HR governance one, because the people who answer for it at board level are increasingly not the people who run it. Boards with ESG and human rights due diligence obligations now carry direct accountability. The governance question is straightforward: if an incident occurs today in a high-risk region where we operate, can we demonstrate we had a proportionate risk assessment in place before it occurred?
- Watch indicator frameworks for high-risk regions. The intelligence gap between a generic country advisory and a named threat assessment is the gap Dusek identified in 2015. A watch indicator framework that tracks political calendar shifts, civil unrest data, and sector-specific threat indicators closes that gap before an incident rather than after a claim is filed. The digital nomad population exceeded 40 million in 2026.3 Business travel exposure is scaling again. The liability window is not narrowing.
Fortius Intel note: The Dusek principle has not changed since 2015. What has changed is the standard courts and insurers now apply to determine whether an employer met it. Organisations conducting governance reviews of their travel risk programmes should ask one question before anything else: if an incident happened today in a high-risk region where we operate, could we demonstrate we had a proportionate, specific risk assessment in place before it occurred?
Methodology: Analysis draws on published legal commentary from TRSS and Thorntons Law, G4S World Security Report data, ISO 31030 guidance, and publicly documented civil litigation precedents. All cited sources are publicly available.
Footnotes
About the author
Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.