How do you create a duty of care framework for global employees?

A duty of care framework for global employees is a structured set of policies, systems, and response capabilities that an organisation puts in place to protect its people before, during, and after international travel. It covers risk assessment, pre-travel preparation, real-time monitoring, and emergency response. The sections below address the most common questions organisations face when building or strengthening that framework.

What does a duty of care framework actually include?

A duty of care framework for global employees includes four core components: a written travel risk policy, pre-travel risk briefings, real-time traveller tracking, and a documented emergency response procedure. Together, these elements ensure that an organisation can identify threats before they materialise, communicate with employees in the field, and act quickly when something goes wrong.

In practice, a well-built framework covers the entire travel lifecycle. Before a trip, employees receive destination-specific risk briefings covering security, health, and political conditions. During travel, the organisation maintains visibility of where employees are and monitors for developing threats. After an incident, there are clear escalation procedures that define who does what and in what order.

Strong frameworks also include supplier standards, meaning the organisation has vetted and contracted with medical assistance providers, security consultants, and evacuation specialists in advance rather than searching for them during a crisis. Aligning the framework with ISO 31030, the international standard for travel risk management, provides a recognised benchmark for organisations that want to demonstrate compliance and due diligence.

Who is responsible for duty of care in a global organisation?

Duty of care responsibility sits with the organisation as a legal entity, but operationally it is shared across multiple functions. The travel risk manager or security lead typically owns the day-to-day programme, while HR and people operations manage policy and employee communication. Senior leadership, including the CEO and COO, carry ultimate accountability because duty of care obligations are a board-level governance matter.

In organisations without a dedicated travel risk manager, responsibility often falls to HR directors, global mobility leads, or operations managers by default. This creates gaps, because those roles are not always equipped with the specialist knowledge needed to assess political risk, coordinate evacuations, or manage a crisis in a remote location.

The most effective model distributes responsibility clearly across three layers:

  • Strategic ownership: Senior leadership sets the risk appetite and approves the budget and policy
  • Programme management: A travel risk manager or security lead maintains the framework, monitors threats, and manages provider relationships
  • Operational execution: HR, travel management, and line managers implement pre-travel processes and act as the first point of contact for travelling employees

Organisations that assign ownership without providing the tools or authority to act create frameworks that look complete on paper but fail under pressure.

What legal obligations underpin duty of care for travelling employees?

Organisations have a legal obligation to take reasonable steps to protect employees from foreseeable harm, including harm that occurs during international business travel. In the UK, this is grounded in the Health and Safety at Work Act 1974 and the Management of Health and Safety at Work Regulations 1999. Similar legislation exists across most jurisdictions where multinational companies operate.

The key legal concept is foreseeability. If a risk was known or reasonably knowable, and the organisation failed to act on it, liability follows. Courts and regulators have consistently found that sending employees to destinations with documented security or health risks without adequate preparation constitutes a breach of duty.

Beyond domestic legislation, organisations operating internationally must also consider:

  • Host country employment law, which may impose additional obligations on employers
  • Insurance requirements, particularly where local regulations mandate specific coverage
  • Sector-specific regulations for industries such as financial services, energy, and humanitarian work
  • Corporate governance obligations, where duty of care failures can constitute a material risk requiring board disclosure

ISO 31030 does not carry legal force on its own, but aligning with it demonstrates that an organisation has taken a systematic, evidence-based approach to travel risk management. Regulators and courts treat that alignment as evidence of reasonable care.

How do you assess risk levels for different travel destinations?

Destination risk assessment involves evaluating the political stability, security environment, healthcare infrastructure, and travel logistics of a location against the specific profile of the traveller and the nature of the trip. A destination that is low risk for an experienced security professional may be high risk for a first-time traveller with a medical condition. Effective assessment is always context-specific.

Most organisations use a tiered risk rating system, typically ranging from low to extreme, applied at the country level and then refined at the city or region level. These ratings should draw on multiple intelligence sources rather than a single government advisory, because conditions on the ground often evolve faster than official guidance is updated.

What sources inform a destination risk assessment?

Reliable destination risk assessments draw on government travel advisories from multiple countries, specialist security intelligence feeds, medical risk data covering disease outbreaks and healthcare capacity, and on-the-ground reporting from local contacts or vetted providers. Relying solely on a single government’s advisory is a common shortcut that leaves meaningful gaps.

How often should destination risk ratings be reviewed?

Risk ratings should be reviewed continuously for high-risk destinations and at least quarterly for all others. Geopolitical conditions, civil unrest, and health threats can change rapidly. A travel risk management service that monitors destinations in real time allows organisations to update ratings as conditions shift rather than working from outdated assessments.

What tools and systems support real-time traveller tracking?

Real-time traveller tracking relies on a combination of mobile applications, web-based monitoring platforms, and communication systems that together give an organisation continuous visibility of where its people are and what threats are developing near them. Without these tools, duty of care exists only on paper.

The core components of an effective tracking and monitoring system include:

  • A traveller-facing mobile app that allows employees to share their location, receive incident alerts, and request emergency assistance from their phone
  • A command-level platform that gives operations teams a live map view of all travelling personnel, with the ability to create geofences and trigger alerts when travellers enter or exit defined zones
  • An emergency mass communication system capable of reaching all travellers simultaneously across multiple channels, including SMS, email, phone calls, and in-app notifications
  • An intelligence layer that surfaces relevant incidents along travel routes and near traveller locations, enabling faster and better-informed decisions

Business traveller tracking software is most effective when it integrates these functions into a single platform rather than requiring teams to switch between disconnected tools during a fast-moving incident. Fragmented systems slow response times and create information gaps at exactly the moments when clarity matters most.

How should organisations respond when a travel incident occurs?

When a travel incident occurs, an organisation should immediately activate its incident response protocol, which begins with confirming the safety and location of affected employees, assessing the nature and severity of the incident, and escalating to specialist support where required. Speed and clarity in the first minutes of a response determine outcomes.

A structured response follows a clear sequence:

  1. Confirm status: Establish contact with the affected traveller or travellers and verify their physical safety and current location
  2. Assess the incident: Determine whether the situation requires medical assistance, security support, evacuation, or a combination of all three
  3. Activate support: Contact pre-contracted medical, security, or evacuation providers who can deploy without delay
  4. Communicate: Keep the traveller informed, brief internal stakeholders, and document all actions taken
  5. Monitor and adapt: Maintain oversight as the situation develops and adjust the response plan as conditions change
  6. Review: After resolution, conduct a debrief to identify what worked, what failed, and what changes to make to the framework

The most common failure in incident response is not having pre-contracted providers in place. Organisations that try to source medical evacuation or security support in real time during a crisis face delays measured in days rather than hours. Contracting with a specialist ahead of time collapses that response window dramatically.

How NGS helps organisations build and operate a duty of care framework

Northcott Global Solutions provides end-to-end support for organisations that need to build, strengthen, or operationalise a duty of care framework for global employees. NGS aligns its Security and Travel Risk Management services with ISO 31030, covering every stage of the travel lifecycle.

  • Pre-travel: Destination risk assessments, pre-travel briefings, and policy development
  • During travel: Real-time traveller tracking and monitoring through the Aurora platform, with AI-powered incident intelligence via Polaris and mass emergency communication through SIREN
  • Incident response: 24/7 Global Operations Centre staffed by personnel with military, medical, and security backgrounds, with an average urban response time of 40 minutes or less
  • Emergency support: Medical and security evacuations, executive protection, and crisis management across more than 190 countries
  • Compliance: Framework documentation and consultancy to support ISO 31030 alignment and regulatory due diligence

If your organisation needs to strengthen its approach to corporate travel safety, contact NGS to discuss how a fully integrated travel risk management programme can protect your people wherever they operate.

Related Articles

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.