Skip to main content
HAAVYN
How to Write a Corporate Travel Policy: 2026 Guide
duty-of-caretravel-riskcompliance

How to Write a Corporate Travel Policy: 2026 Guide

A company sends an employee to Peru. Local transport is arranged through an unvetted operator. The helicopter takes off in poor weather with a tired pilot, and it crashes. The employee is killed.

When the case - Dusek v StormHarbour Securities LLP - reached court, the questions were blunt: did the employer understand the foreseeable risks involved in that trip? Could those risks have been avoided? The answer to both was yes.

StormHarbour didn’t have a travel policy that required vetting local transport operators in high-risk environments. That gap cost them in court, and - far more seriously - cost an employee their life.

A well-written corporate travel policy won’t prevent every incident. But it forces you to think about foreseeable risks before someone is in the field, creates accountability across the booking and approval chain, and - if something goes wrong - demonstrates that your organisation took reasonable steps. This guide walks through what goes in, why each section matters from a duty of care perspective, and gives you a skeleton template to adapt.

Most HR and finance teams treat the travel policy as a cost management tool - the document that sets booking windows, caps hotel spend, and explains how to file expense claims. All of that matters. But if cost control is the policy’s only function, it’s incomplete.

Global business travel spending is projected to hit $1.57 trillion in 2025, according to GBTA. That volume means significant numbers of employees in high-variability environments, and significant legal exposure for every organisation that sends them there.

In the UK, the Health and Safety at Work Act 1974 requires employers to protect employee health and safety “so far as is reasonably practicable” - a standard that applies on the road and in the air, not just at a desk. The Corporate Manslaughter and Corporate Homicide Act 2007 added criminal liability: where serious management failures result in an employee’s death, the company faces criminal prosecution. Section 44 of the Employment Rights Act 1996 also gives employees an explicit right to refuse travel they reasonably believe poses serious and imminent danger - a right your policy should acknowledge.

In the US, the OSHA General Duty Clause requires employers to protect workers from foreseeable harm. Equivalent frameworks apply across Australia, the EU, and most other jurisdictions where your teams might operate.

The legal question isn’t whether you sent the traveller. It’s whether you identified the foreseeable risks and took reasonable steps to mitigate them. A documented travel policy is the primary way you demonstrate those steps to a court, regulator, or insurer.

The Eight Clauses Your Corporate Travel Policy Needs

1. Scope and Applicability

Define who the policy covers. Full-time employees, contractors, temporary staff, interns - the policy should explicitly state it applies to all travel undertaken on behalf of the company, regardless of employment type. Contractors working at your direction typically fall within your duty of care even if they’re not on your payroll.

Be specific about what counts as “business travel.” Day trips, domestic overnight stays, and international travel may require different treatment, but they should all be covered.

2. Pre-Trip Approval Workflow

Every business trip should require formal approval before booking. Your policy should specify:

  • Who has authority to approve (line manager, department head, designated travel desk)
  • What the request must include: destination, dates, business purpose, estimated cost, and accommodation details
  • The minimum required lead time before departure
  • Automatic escalation triggers - for example, any destination where the UK FCDO, US State Department, or Australian DFAT advises against all but essential travel requires additional senior sign-off

Without a structured approval workflow, bookings happen outside your systems, travellers end up in places you don’t know about, and your duty of care fails at the first hurdle.

3. Booking Procedures and Preferred Vendors

Mandate that all bookings go through an approved channel - a corporate travel management company, an approved online booking tool, or your internal travel desk. This isn’t purely about cost control. When something goes wrong at 2am in an unfamiliar city, you need to know where your people are and have a single point of contact who can help.

Specify approved airlines, minimum hotel safety standards, and ground transport requirements. The StormHarbour case turned partly on the use of an unvetted local helicopter operator. Your policy should require that local transport in elevated-risk environments is arranged through verified providers only.

4. Expense Guidelines and Per Diem Limits

Define what’s reimbursable, with specific limits by category:

  • Flights: class of travel based on journey length and seniority level
  • Hotels: nightly spending cap by city tier, with separate limits for Tier 1 cities (London, New York, Singapore) and other destinations
  • Meals: daily per diem rate, with a clear position on whether receipts are required
  • Ground transport: approved options and when taxis, rideshare, or rental cars are acceptable

Be specific. Vague policies produce inconsistent expense claims and disputes. They also make it harder to identify when someone has gone materially outside policy.

5. Duty of Care Requirements

This is the section most SME and mid-market travel policies either skip or relegate to a single paragraph at the end. It deserves its own section, and it should cover:

Pre-trip risk assessment. For any destination with elevated risk conditions, require a completed risk assessment before the trip is approved. This should cover current security conditions, health risks, local transport safety standards, and medical facility availability in the area.

Traveller registration. Every traveller should register their full itinerary - flight numbers, hotel name and address, local contact details - in your tracking system before departure. A dedicated travel risk platform handles this automatically. A shared document or spreadsheet works at smaller scale, though it won’t scale beyond around 20-30 travellers before it becomes unmanageable.

Emergency contact details. Every traveller should leave with three numbers: your organisation’s emergency contact, a 24/7 assistance line (provided by your insurer or travel risk platform), and the contact for the nearest embassy or consulate for their nationality.

Check-in protocols. For higher-risk destinations, define the required check-in frequency - daily check-ins are standard for destinations with elevated security risk. Specify what happens if a check-in is missed.

The right to refuse. Your policy should explicitly acknowledge that employees have the right to decline travel they believe poses serious risk, and should provide a clear escalation route for raising safety concerns without professional consequences.

ISO 31030:2021, the international standard for travel risk management, provides a detailed framework for all of this. Your policy doesn’t need to replicate the standard verbatim, but structuring your duty of care section to align with it significantly strengthens your legal position and your audit trail.

6. High-Risk Destination Protocols

Destinations carrying elevated threat levels warrant separate treatment in your policy. Define what “high-risk” means operationally - for example, any destination where a major government advisory agency advises against all but essential travel, or where your own risk assessment identifies specific active threats.

For those destinations, your policy should require:

  • Senior leadership or board-level sign-off on travel approval
  • A specialist pre-departure security briefing
  • Enhanced insurance coverage, including medical evacuation, and malicious risk coverage where relevant (terrorism, political violence, kidnap and ransom)
  • Defined check-in frequency and a specific person responsible for welfare monitoring
  • A documented extraction plan - who makes the call to pull someone out, and how

7. Insurance Requirements

Standard travel insurance is not adequate for high-risk environments. Your policy should specify minimum required cover by destination tier:

  • All international travel: comprehensive medical coverage, emergency medical evacuation, trip cancellation
  • Elevated-risk destinations: malicious risk insurance covering terrorism and political violence as a minimum
  • Active conflict zones or high-kidnap-risk environments: full K&R (kidnap and ransom) coverage, confirmed with your insurer before travel is approved

Require proof of insurance confirmation before the trip is cleared to proceed. Sending someone to a fragile market without appropriate cover is both a financial risk and a duty of care failure that courts take seriously.

8. Emergency Procedures and Crisis Communication

When something goes wrong, ambiguity makes things worse. Your policy should specify:

  • Who is the primary point of contact for a traveller reporting a problem?
  • What is the escalation chain if that person isn’t reachable?
  • What authority does your travel risk or security function have to make evacuation decisions without waiting for C-suite approval?
  • What are the notification timelines: when do you inform senior leadership, HR, next of kin?

Run a tabletop exercise against this section annually. Most teams find significant gaps when they actually try to follow their own procedures.

Communicating the Policy So Employees Actually Follow It

A 2025 study by GBTA and ALTOUR found that nearly a third of travel managers reported their employees hadn’t read or weren’t familiar with the company’s travel policy. That is a substantial legal exposure wrapped in an organisational failure.

Writing a good policy is half the job. Ensuring it’s understood and followed is the other half.

Keep it short. A 40-page PDF will not get read. The core policy should fit within 3,000 words. Use annexes for supporting detail like per diem tables, approved vendor lists, and risk assessment templates.

Make it accessible. Host it in your intranet, your HR system, and your travel booking platform. Include it in new-starter onboarding. Every employee who will travel for work should receive it before their first trip.

Require annual sign-off. Have employees confirm in writing (or digitally) that they’ve read the policy each year and whenever it’s updated. This creates a documented record that employees were informed - relevant in any subsequent dispute or claim.

Integrate it into the booking flow. The most effective policies are built into the booking process itself, so that out-of-policy choices trigger an approval request rather than going unnoticed. If your booking tool supports policy integration, use it.

Train frequent travellers. A one-hour annual session covering the policy, emergency procedures, and risk context for your key destinations is a worthwhile investment. It also demonstrates to courts and insurers that you took employee awareness seriously.

A Corporate Travel Policy Template: Skeleton Structure

Use this as your starting framework. Fill in the specifics - approval thresholds, spending limits, vendor names, and contact details - to reflect your organisation.


[Company Name] Corporate Travel Policy

1. Purpose and Scope - Who this applies to; what travel is covered (domestic, international, contractor travel)

2. Pre-Trip Approval - Approval levels by trip type and destination risk; required information; booking lead time requirements

3. Booking Procedures - Approved booking channels; preferred airlines, hotels, and ground transport; out-of-policy booking exception process

4. Expense Guidelines - Reimbursable categories and limits; per diem rates by location; receipt requirements and expense submission timelines

5. Duty of Care Requirements - Risk assessment requirements; traveller registration process; emergency contacts; check-in protocols; right to refuse

6. High-Risk Destination Protocols - Definition of high-risk; additional approval requirements; pre-departure briefing; enhanced insurance requirements; extraction planning

7. Insurance Requirements - Minimum cover by destination tier; proof of insurance requirements; how to access emergency assistance

8. Emergency Procedures - Contact chain; decision authority; notification timelines for incidents; crisis communication process

9. Compliance and Exceptions - Consequences of non-compliance; process for requesting exceptions; manager accountability

10. Review Schedule - When the policy will be reviewed (minimum annually, and after any serious incident or material change in the risk environment)


Building the Infrastructure Behind the Policy

A travel policy is only as effective as the systems that support it. Traveller registration that relies on a shared spreadsheet will fail under pressure. Risk intelligence that comes from an annual briefing document won’t reflect conditions on the ground this week. Insurance that excludes the destinations your teams actually visit leaves gaps that matter.

HAAVYN’s duty of care platform connects your travel policy to real-time threat intelligence, automated traveller registration, mobile check-in, and integrated insurance coverage designed for the environments where the risk is real. Your policy becomes a functioning safety system rather than a document that sits on an intranet.

If you’re building or reviewing your corporate travel risk programme, speak to our team - we can help you identify the gaps before they become incidents.


Frequently Asked Questions

Is a corporate travel policy legally required?

No jurisdiction mandates a document called a “corporate travel policy” by that name. But the legal obligation to protect employees from foreseeable harm - under the UK Health and Safety at Work Act 1974, OSHA in the US, and equivalent legislation elsewhere - requires documented processes that cover the same ground. In any claim or prosecution, you will need to demonstrate that policies and procedures existed and were communicated. A written travel policy is the standard mechanism for doing that.

What should a corporate travel policy include?

At minimum: a pre-trip approval workflow, booking procedures, expense guidelines, duty of care requirements (including risk assessment, traveller registration, and emergency contacts), high-risk destination protocols, insurance requirements, emergency procedures, and a review schedule. Most organisations also include a compliance and exceptions section setting out consequences for non-compliance.

How often should a corporate travel policy be reviewed?

Annually as a minimum. You should also review it following any serious travel incident, after significant changes to your travel programme, and whenever the risk environment in key destinations changes materially. A policy written in 2022 without updates is likely out of step with current risk conditions, current legal interpretations, and current insurance market expectations.

What is the difference between a travel policy and a duty of care policy?

They should overlap significantly - the best approach is to integrate them. A travel policy typically covers booking rules, expense limits, and approvals. A duty of care policy covers protecting employee safety: risk assessment, emergency procedures, insurance, and crisis response. Keeping them as separate documents increases the likelihood that one gets read and the other doesn’t. Build a travel policy with a robust, dedicated duty of care section, and treat them as one document.

How do I enforce a corporate travel policy?

Make compliance the path of least resistance. Integrate policy rules into your booking tool so out-of-policy selections trigger an approval request rather than an outright block. Require annual acknowledgement from all employees who travel. Ensure line managers understand their approval responsibilities - if the people approving travel aren’t applying the policy consistently, it won’t stick. And make it clear that exceptions exist but require a documented request, not an informal conversation.

Tags
duty-of-caretravel-riskcompliance
MS
Written by Madeline Sharpe

Content Writer