Quick answer: International business travel compresses hazards, threats, liability and psychological strain into short windows. Most travel risk programmes pass audits because they're built for the paperwork, not the pressure, and that's exactly why they fail the moment real disruption hits.
Originally published on LinkedIn: 18 January 2026.
A typical travel risk management program looks complete. Policy exists. A vendor is engaged. A portal generates destination ratings. A briefing template gets emailed before departure. An emergency number sits at the bottom of the page. On an audit, this program ticks every box. None of that tells you what happens when the flight is cancelled, the city turns unstable overnight, the traveller is exhausted and stressed, their manager is pushing for the deal to close anyway, and the organisation has to coordinate HR, security, legal, an insurer and an assistance provider across three time zones in real time. That is the actual test. Most programs have never sat it.
Measure capability, not documentation
Boards and risk committees should stop asking whether a policy exists and start asking whether the system works. That means tracking specific, measurable things: time to contact after an incident, time to triage, time to decision and who holds the authority to make it, time to assist for medical, security or logistics needs, the clarity of handoffs between functions, locate-and-assist success rates, and whether near misses actually change controls afterwards. If a program cannot produce numbers against those categories, it has a policy, not a capability. Most programs also over-focus on destination risk ratings and under-focus on where harm actually clusters, which is the interfaces and transitions inside the journey itself. The highest-exposure segments are usually not the flight. They are the last mile: ground movement by rideshare or informal transport on unfamiliar routes, venue transitions involving late-night movement with low phone battery and poor communications, remote travel into areas with weak coverage and thin medical infrastructure, and the ambiguous boundary between work obligations and personal time.
Trust, fatigue and the choreography of response
Travellers do not fail because they lack a policy. They fail because they are human: subject to fatigue, cognitive overload, decision latency under stress, and alert burden, where a high volume of communications turns signal into noise. A control that cannot survive fatigue and time pressure is not a control, it is documentation. Modern travel risk management also depends on check-ins, location awareness and incident reporting, all of which depend on trust. When travellers distrust the system, opt-outs rise, check-ins fail, and locate-and-assist capability collapses at the exact moment it is needed. A program with sophisticated technology and low trust is fragile by design. When disruption hits, the failure mode is rarely a lack of care. It is a lack of choreography across HR, line management, security, crisis leadership, legal, insurers, and medical and security assistance providers. If these functions have not agreed decision rights, escalation pathways and practised handoffs in advance, response slows and support becomes inconsistent.
Tony Ridley provides travel risk management and duty of care advisory for organisations that move people across borders. Contact us to discuss your requirements.