Travel risk management and duty of care
We build the travel risk program an organization is legally and practically expected to have. It settles which trips need approval, what a traveler is told before departure, who answers the phone at 03:00 local time, and what actually happens when the answer is an evacuation.
What the work covers
A travel risk program decides things. Ours starts from the trips you actually make. We rate the destinations you use against the profile of the person traveling, because a female field engineer flying alone to Port Harcourt and a two-day board visit to Dubai are not the same risk on the same country rating. From there we set the approval thresholds, write the pre-travel briefings, define what tracking and check-in you need (and, more often, what you do not), and build the escalation chain that turns a call into a decision.
Where programs fail
At the end of the chain. A policy that says "contact the emergency line" without a named provider, a funded evacuation route and a hospital that will actually accept the patient is a policy that fails on its first real incident. We plan backwards from that moment.
The most common version of that is the app. A tool that shows country ratings and gives a traveler a button to press is genuinely useful, and it is not a program. Pressing the button raises an alert somewhere. What decides the outcome is who is on the other end, what that person may do without asking anyone, whether a receiving hospital was agreed in advance, and who pays for the aircraft. Buying the app and calling it duty of care is the saving we are asked to review most often.
Two more sit close behind. A country rating bought once and never applied to the trips people actually make. And a briefing sent as a PDF that nobody reads and nobody records as read. All three are cheap, and all three leave you with a paper trail showing what was purchased rather than what was done.
Who delivers on the ground
We plan and manage. The driver, the clinic, the security escort and the aircraft are local, and they are chosen for being local. A team on the ground reads its own terrain better than anyone flown in for the week. Our job is to hold one standard in every country the program touches. We select and vet the providers, brief them to one written standard, audit what they deliver, and stay your single point of accountability.
That is more than good practice. Wherever people employed by different companies work in the same place, the duty to coordinate protective measures and to satisfy yourself that the other company's people were properly instructed falls on you as well, and most occupational safety regimes say so in as many words. We carry out that verification and document it.
Standards we work to
Questions we get asked
Who answers the phone at night?
That depends on the mandate, and you learn what you are getting before it starts. For a single project it can be a named on-call rota with us. For a running program we work with partner operations centers, meaning global security operations centers staffed around the clock, which we use in every region and which hold our procedure and your escalation chain.
What we do not do is put a number in a policy and leave open who sits behind it. Who picks up, what that person may decide alone, and at what point we come in, is written into the program.
We already buy travel insurance and an assistance service. Is that a travel risk program?
No. Insurance pays after the event and an assistance line reacts to a call. Neither one decides whether the trip should happen, briefs the traveler, or tells your duty manager what to do in the twenty minutes before the assistance provider picks up. Those are the parts that reduce the incident count.
It also falls short legally. The duty of care asks for assessment, instruction and precaution, all of it work done before departure. An assistance number in a card holder evidences none of the three. Insurance and assistance belong in a program, as its last line.
How long does it take to stand one up?
A single number would be dishonest here, because the spread is real. One trip or a short project can be covered at short notice, in days if it has to be. A travel policy that holds up across a whole organization takes weeks, because approval thresholds, briefings and the escalation chain have to be agreed with HR, employee representatives and data protection. Add a crisis team that has to be built, staffed and exercised, and it becomes months.
After the first conversation we tell you which of those three sizes you are looking at, including when the honest answer is larger than the one you wanted.
Does this cover freelancers and subcontractors?
Yes, and it has to, though the duty arrives from a different direction than for your own staff. The employment relationship covers the people on your payroll. Everyone else falls under the coordination duty described above, which arises as soon as people employed by different companies work in the same place. On top of that sits liability for negligent selection. An employer who engages a provider it has not vetted answers for that choice.
In practice this means defining the scope of your travel policy beyond your payroll before the first incident. It also means the briefing given to the subcontractor's driver is part of your duty, not only his. We document both the briefing and the verification, so that you can evidence the duty was met.
Do you track our travelers?
It depends on where they are going, and the answer is yes more often than the question expects. In some environments, knowing roughly where somebody is when they stop answering is the difference between a search and a response, and people going into those places usually want it. On a trip to a European capital the same measure is surveillance with no benefit attached.
We take the privacy side seriously, because a measure people quietly opt out of protects nobody. So it is specified by risk tier. Check-in rules for most travel, where the missed check-in is itself the signal and compliance is high. Continuous location only where the destination warrants it, agreed with employee representatives where they exist and written into the policy. And where location is held, break the glass is usually the right design. The location stays invisible to everyone until a defined emergency opens it, with every access logged and reviewable.
Set up that way it survives the data protection conversation, rather than being quietly disabled six months later.
Other capabilities
Medical support and rescue planning
Medical concepts, staffing plans and the full MEDEVAC chain.
Learn moreClose protection and executive protection
Protective concepts, advance work and command, low profile by design.
Learn moreRisk and threat assessment
Country and site analysis, surveys and audits that end in decisions.
Learn moreCrisis and emergency management
Crisis structures with named roles, exercised before handover.
Learn moreTalk it through first
Every engagement starts with a confidential conversation, and it is free. Describe the operation and the concern. We will tell you whether this is the right capability, another one, or nothing at all.
enquiries@foxpedition.com