
Field Notes
Geostrategic Risk and the Duty of Care Gap: When Travel Risk Intelligence Becomes a Legal Liability
In January 2015, the English High Court found StormHarbour Securities liable for the death of an employee killed in a helicopter crash in the Peruvian Andes. The judgment in Dusek v StormHarbour Securities LLP was specific: the company had not sent him somewhere it knew to be unsafe. It had done nothing to find out whether it was safe, and that omission, not the accident itself, created the liability.1 A decade later, that principle has been operationalised into a rising standard that most corporate travel risk programmes are not meeting.

Why ISO 31030 Has Become the Geostrategic Benchmark in Duty-of-Care Claims
ISO 31030:2021 is not law and employers cannot be certified against it, but courts increasingly use it as the benchmark for a single question: did the employer do what a reasonable employer should have done? The answer in 2026 requires more than it did when the standard was published.
- Operationalised by procurement and insurance. ISO 31030-aligned travel risk programmes are now required as a contract condition by major procurement functions and used by insurers to price travel risk premiums. A programme considered adequate in 2021 likely falls below the standard courts apply today.2
- Statutory obligations are unchanged but more visible. The UK Health and Safety at Work Act 1974 extends the duty to protect employees to business travel. The US OSHA General Duty Clause applies similarly. The US Special Errand Rule means employers can face liability even when employees travel outside standard working hours, if the company controlled the travel arrangements.1
- Claims trajectory is upward. Civil claims for negligence in business travel incidents are rising. In English law jurisdictions, fatal accident claims of the Dusek type carry significant damages and separate litigation costs. In some Asian jurisdictions, settlements for serious incidents run between two and eight crore rupees per incident.6

The Three Gaps Where Geopolitical Risk Creates Employer Exposure
The organisations most exposed to duty-of-care claims are not those sending employees into manifestly dangerous places. They are those with monitoring gaps that allow foreseeable risk to become unmanaged risk.
- Shadow travel. Between 20 and 30 percent of corporate travel spend falls outside approved booking channels.4 An employee who books a connecting flight directly or extends a trip using personal accommodation steps outside the duty-of-care tracking system the company believes it has. The incident risk does not follow the booking system.
- Intelligence depth gap. The Dusek judgment was explicit that adequacy of risk assessment is proportional to foreseeability of the specific risk. A chartered flight to a remote project site with unstable aviation infrastructure, operated by a company in financial difficulty, requires a specific assessment, not a regional advisory.1 Most corporate travel risk systems provide level-two coverage: location tracking and generic country advisories sourced from government portals. That is not a proportionate response to foreseeable specific risk.
- Sectoral threat mismatch. G4S's 2025 World Security Report found that APAC company executives face the world's highest risk of violence from external actors.5 That finding is not reflected in most corporate travel risk programmes for the region, which remain oriented toward health and infrastructure rather than targeted threat. Executives in technology, aerospace, defence, and extractives require threat assessments calibrated to sector, profile, and specific itinerary.

What Decision-Grade Travel Risk Intelligence Requires from Risk Functions
The legal distinction that matters is between an employer who provided a risk assessment and one who provided a proportionate one. Proportionality is calibrated to the foreseeable risk, not to the average risk across all travel destinations.
- Profile-specific pre-travel briefings. A senior executive travelling to Jakarta for meetings with a company in active dispute with a local government entity needs more than a country advisory. The relevant picture is the specific threat environment for that company, that sector, and that executive's profile, cross-referenced against the current political calendar and local security infrastructure.
- Shadow travel monitoring. Duty-of-care obligations follow the employee, not the booking channel. Risk functions need a mechanism to capture itinerary data that falls outside approved systems. Without it, they cannot demonstrate proportionate care when an incident occurs outside the tracked perimeter.
- Board-level governance reporting. Travel risk is increasingly a CFO and HR governance issue, not a security operations matter alone.4 Boards with ESG and human rights due diligence obligations now carry direct accountability. The governance question is straightforward: if an incident occurs today in a high-risk region where we operate, can we demonstrate we had a proportionate risk assessment in place before it occurred?
- Watch indicator frameworks for high-risk regions. The intelligence gap between a generic country advisory and a named threat assessment is the gap Dusek identified in 2015. A watch indicator framework that tracks political calendar shifts, civil unrest data, and sector-specific threat indicators closes that gap before an incident rather than after a claim is filed. The digital nomad population exceeded 40 million in 2026.3 Business travel exposure is scaling again. The liability window is not narrowing.
Meridian Intell note: The Dusek principle has not changed since 2015. What has changed is the standard courts and insurers now apply to determine whether an employer met it. Organisations conducting governance reviews of their travel risk programmes should ask one question before anything else: if an incident happened today in a high-risk region where we operate, could we demonstrate we had a proportionate, specific risk assessment in place before it occurred?
Methodology: Analysis draws on published legal commentary from TRSS and Thorntons Law, G4S World Security Report data, ISO 31030 guidance, and publicly documented civil litigation precedents. All cited sources are publicly available.
Footnotes
1 Travel Risk Safety Specialists, Duty of Care Legal Obligations: What the Dusek v StormHarbour Case Means for Employers and Business Travel Liability, January 31, 2026. Available at travelrisksafety.com.
2 TRSS, ISO 31030 at Five Years: The Silent Benchmark in Duty-of-Care Law, April 23, 2026.
3 TRSS, Digital Nomads and Duty of Care: Managing Travel Risk for a Distributed Workforce, May 10, 2026.
4 Tripgain, Duty of Care in 2026: Why Travel Risk Has Become a Governance Issue, June 7, 2026.
5 G4S, World Security Report 2025. Available at g4s.com.
6 UnfairGaps.com, Duty of Care Compliance Liability: Employee Travel Risk Management, 2026.
About the author
Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.