Quick answer: A shared medium risk country rating is not a traveller assessment, and the gap between the two is where duty of care programmes create liability. Why generic travel risk platform ratings expose organisations to vicarious liability claims.
Originally published on LinkedIn: 15 May 2026.
A shared "medium risk" country rating is not a traveller assessment. It is a classification of a country's aggregate environment, and treating it as equivalent to individual risk analysis is where duty of care programmes fail, leaving both the organisation and its travel risk management providers exposed to liability claims.
The Case: Two Travellers, One Rating
Consider a common scenario: two employees are travelling to Jakarta next week, and a platform rates both of them medium risk. Is that sufficient? No. The rating tells you something about Indonesia's aggregate threat environment. It tells you nothing about Jakarta specifically, the purpose of the trip, the places each individual might go, what they do while there, or their personal vulnerabilities and context. Critically, it does not establish whether "medium risk" is even the same finding for both travellers.
To test that, each traveller's individual factor profile has to be worked through separately. Do their nationalities, professional roles, or personal histories create differential threat exposure in Jakarta specifically? A corporate auditor, an NGO worker engaged in labour-related activity, a government-adjacent contractor, and a sales executive may travel to the same city, but they do not share the same risk profile. Do their functions attract adversarial interest from state actors, criminal networks, labour interests, or ideologically motivated groups operating in-country? Has either traveller experienced prior targeting, harassment, or public controversy that creates exposure independent of their job title?
Then there are the transient factors that are almost always unknown at the point of booking: each traveller's current emotional and psychological state, their digital footprint, and whether anyone has actually asked them these questions or the platform simply logged a reservation. Jakarta's active threat picture includes petty crime, cyber-enabled fraud targeting business visitors, and periodic civil unrest around political or labour events. Where a traveller's identity, visibility, behaviour, or schedule intersects with known targeting patterns, a "medium" rating may be underweighted for one person and accurate, or even overweighted, for the other. The platform assessed a country. It has not assessed the travellers. Conflating the two is the failure point, and it is the organisation and its providers who carry the resulting accountability.
People Are Not Neat Little Boxes
Corporate risk functions favour a standardised model, but a single template for rating individual risk is not achievable, because people do not fit neat categories and do not stay fixed for long. Personal risk mixes fixed-state variables, gender, age, nationality, with transient factors such as behaviour, choices, and specific activities. Averaging a workforce into one risk category conceals the very variables that define exposure. The absence of specific, differentiated people-risk categories does not indicate low risk; it indicates institutional ignorance and a lack of the Strength of Knowledge (SoK) needed to identify which threat actors affect which individuals.
Travel Is a Phase Transition
Travellers are not the same risk profile at home as abroad. The moment someone moves, their status shifts, from local to foreigner, tourist, or outsider, and each stage of the journey introduces new variables affecting vulnerability and threat exposure. This is an operational requirement, not a philosophical observation: a valid security analysis must be documented, evidenced, and compared across every stage and context of the journey, because the individual, the context, and the location are all constantly changing.
The Risk Vending Machine
Automated software that outputs "Low/Medium/High" ratings at scale is often Risk Management Theatre rather than risk management. These platforms are built to make non-professionals feel safe and satisfy auditors, but they routinely fail the travellers they are meant to protect, for three reasons: they obscure the Strength of Knowledge and the age of the underlying data, preventing genuine subjective professional judgement; they carry zero contextual relevance to an organisation's specific operational culture; and they conceal the human and sociological dependencies that define real-world danger. If the calculation cannot be seen, the result cannot be trusted.
Standards as Editorial Veneer
Many organisations cite standards such as ISO 31000 as a compliance signal while skipping the foundational steps. If communication and consultation with stakeholders, and the establishment of context, have not been evidenced, the organisation cannot legitimately move to risk identification, doing so invalidates the audit trail. Context cannot be outsourced. Purchasing a generic risk rating from an external provider directly contradicts the requirement to establish context, and as Smith and Brooks (2013) note, many standards do not even engage with the concept of threat. Following a standard ritualistically, without establishing specific relevance, moves an organisation toward failure rather than safety.
From Ritual to Resilience
The question for every executive is whether they are managing specific threats, hazards, and perils, or simply administering reports, tasks, and dashboard views. Resilience is a lifestyle of constant maintenance, not a fixed state, and mistaking the theatre of superficial security for actual protection invites a disaster that has already begun. Safety, security, and resilience are infinite games with no finish line: as an organisation becomes more valuable and efficient, its security debt rises in parallel, and a static strategy is already failing against adversaries who are not.
Tony Ridley, MSc CSyP FSyI SRMCP, advises boards and executive teams on the gap between platform-generated country ratings and defensible, individual traveller risk assessment, the exact gap that drives vicarious liability exposure in corporate travel programmes. Organisations relying on aggregate "medium risk" labels for duty of care sign-off should have that reliance independently reviewed before, not after, an incident tests it.