Corporate travel policy and duty of care: how a small agency wins a company account
What a travel policy contains, how approvals should work, what duty of care means in practice, and what an agency can honestly promise about tracking travellers and answering out of hours.
A small agency wins a company account by arriving with two things the company does not have: a travel policy it can adopt, and a credible answer to the question of what happens when an employee is in trouble abroad at three in the morning. Price is rarely the deciding factor, because a company comparing you with a booking site is not comparing fares. It is comparing who picks up the phone.
None of what follows is legal advice. Employer obligations towards travelling staff exist in most countries, but they sit in different laws and the detail differs by country, so the useful role for an agency is to know which questions the company's own adviser or insurer has to answer, and to cover the operational half properly.
What a corporate travel policy actually contains
A policy is a short document that removes arguments. If it needs a meeting to interpret, it is too clever. The sections that earn their place:
- Who it applies to. Employees, but also contractors, interns, board members and anyone travelling at the company's request. This is the clause most policies forget, and the one that matters most when something happens.
- How trips get booked. One channel, named. A policy that permits booking anywhere makes every other clause unenforceable, and it destroys the company's ability to know where its people are.
- When to book. An advance booking window, with the reason stated: fares and rooms cost more late. This single clause usually saves more than anything else in the document.
- Flights. Cabin class by flight duration, the rule on choosing a cheaper indirect routing or not, baggage, seat selection, lounge access, and what happens to unused or changed tickets.
- Accommodation. A nightly cap by city or by band of cities, reviewed once a year, plus the rule on which hotels are preferred and why. Safety and location, not just price.
- Ground transport. Rail versus air on short legs, taxis and ride hailing, rental cars and who is allowed to drive, and whether driving a private car for work is covered.
- Meals and incidentals. Per diem or receipts, decided once. Both work. Mixing them does not.
- Expenses. What needs a receipt, the submission deadline, the currency conversion rule, and what will simply not be reimbursed.
- Staying reachable abroad. Who pays for mobile data outside the country, how the traveller gets a working connection on landing rather than hunting for airport Wi-Fi, and the expectation that the company can reach them and they can reach the emergency number. Unreachable staff are the most common practical failure of an otherwise good policy.
- Insurance, health and documents. What the business travel policy covers, who arranges visas, which vaccinations or health advice apply, and who pays.
- Risk and destinations. Which destinations need an extra approval, and who gives it.
- Personal travel attached to a business trip. Increasingly common, and worth a paragraph: what the company pays for, where its insurance stops, and who is responsible during the personal days.
- Exceptions. How to ask, who decides, how fast, and the fact that exceptions are recorded.
Put the whole thing in one document with a named owner and a review date. A policy without an owner is a file nobody updates.
Who approves what, and how fast
Approval flows fail in one of two directions. Either everything needs sign off, in which case people book around the system and the company loses visibility, or nothing does, in which case the policy is decoration.
A workable structure:
- Trip approval before booking, from the line manager or the budget owner, on the basis of purpose and estimated cost, not on the basis of the specific flight.
- In policy bookings need no second approval. If a booking sits inside the rules, the agency or the tool just books it. This is the clause that makes the policy worth having.
- Out of policy bookings go to one named approver, with a stated response time. If the approver does not respond within it, define what happens, because in practice that decision gets made anyway, by whoever is standing at an airport.
- Higher risk destinations escalate, usually to whoever owns health and safety or security, not to the traveller's manager. Write down what triggers the escalation, such as a government travel advisory level or a specific country list, and which source you use for it.
- Emergency changes are approved after the fact. A stranded traveller rebooks and explains later. Any other rule is ignored in the moment and then punished afterwards, which is the worst of both.
- Nobody approves their own trip. Including the founder. Especially the founder.
Keep a written record of exceptions. After a year, the pattern in the exceptions tells the company what to change in the policy, which is a conversation an agency can lead and be valued for.
What duty of care means in practice
Duty of care is not a document. It is the set of things a company can demonstrate it did, before and during a trip, to keep its people reasonably safe. In practice it comes down to six capabilities:
- Know where people are. Which requires the single booking channel above, and an itinerary record the company can actually see.
- Be able to reach them, quickly, and be reachable in return. Current mobile numbers, a working connection abroad, and a number the traveller can call at any hour that is answered by a person.
- Assess the trip before it happens, proportionately. A sales call in a neighbouring country is a two minute check. A site visit in a remote region is a real assessment, with a named person signing it off.
- Brief the traveller on what is specific to the destination: local emergency numbers, medical access, the insurer's assistance line, transport risks, anything they need to avoid, and who to call first.
- Have a plan for when it goes wrong, with one named owner of the incident, a way to account for every traveller in the affected area, and an assistance or medical provider whose details the traveller already has.
- Keep the records. Policy, approvals, assessments, briefings, incident logs. Demonstrating diligence after the fact is impossible without them.
Almost all of that is process, not spend, which is why a company of thirty people can do it properly and most do not.
Where the duty comes from, and why the detail differs by country
This is the part to state accurately and then hand over. Obligations towards travelling employees generally come from ordinary workplace health and safety law rather than from anything travel specific:
- In the European Union, the framework directive on safety and health at work, Directive 89/391/EEC of 12 June 1989, requires the employer to ensure the safety and health of workers in every aspect related to the work, and to assess risks. It is implemented by each member state in its own national law, which is where the detail lives.
- In Italy, that implementation is Legislative Decree 81/2008, alongside Article 2087 of the Civil Code, which requires the employer to protect the physical integrity of employees.
- In the United Kingdom, section 2 of the Health and Safety at Work etc. Act 1974 requires employers to ensure, so far as is reasonably practicable, the health, safety and welfare at work of their employees.
- In the United States, the general duty clause of the Occupational Safety and Health Act of 1970 obliges employers to provide a workplace free from recognised hazards, but its reach does not extend to workplaces abroad in the way people often assume. Exposure for international travel tends to arise instead through workers' compensation and negligence, which vary by state.
- As guidance rather than law, ISO 31030:2021, Travel risk management, guidance for organizations, published in 2021, is the reference most large travel programmes are now written against. It is guidance, not certifiable, and it is a useful checklist for a company that has nothing.
Two honest caveats to say out loud in the meeting. The detail differs by country and by the traveller's contract, and whether a specific arrangement is sufficient is a question for the company's own legal adviser and insurer, not for its travel agency. Saying that plainly makes you more credible, not less.
One more thing worth knowing, because it affects what you are selling: EU package travel law excludes packages bought under a general agreement for arranging business travel between a business traveller's employer and a trader. A corporate account is therefore not automatically covered by the consumer protections that apply to a leisure package, which is one reason the contract with the company has to spell out what you do.
What the company must provide, and what the agency provides
Most failed corporate accounts fail because this was never divided explicitly.
The company has to provide:
- a named owner of the policy and a named incident owner, plus a deputy for both
- current traveller profiles: full name as in the passport, mobile number, document details and expiry, and whatever medical or accessibility information the traveller chooses to share
- emergency contact details, collected with the traveller's knowledge and kept current
- insurance and assistance provider details, with the policy number the traveller will be asked for
- a decision maker reachable outside office hours, with authority to spend
- the list of everyone who travels on the company's behalf, contractors included
- the rule on personal deviations, and communication of the policy to the people it binds
The agency provides:
- booking inside the policy without asking, and flagging what falls outside it
- a complete itinerary record per traveller, and reporting the company can use
- an out of hours number that is answered by someone able to rebook, with the honest limits of it stated in the contract
- proactive notice of disruption: strikes, cancellations, schedule changes, and the rebooking that follows
- pre trip practical information and document requirements
- unused ticket and refund tracking, which is where the money the company did not know it was losing turns up
- an annual review of the policy against what actually happened
And the agency must be equally clear about what it is not. An agency is not a security company, a medical provider or an evacuation service. Those come from an insurer or a specialist assistance provider, and the correct pitch is that you know when to hand over and you have the number.
Traveller tracking: what to promise and what not to
This is where agencies overpromise and lose accounts later.
What you can honestly offer is itinerary visibility: for trips booked through you, the company can see who is scheduled to be where, and when there is an incident in a region you can list the travellers whose bookings place them there. That is valuable and it is the basis of most corporate travel programmes.
What that is not is knowing where a person is. Booked itineraries do not show a train bought at a station, a hotel changed on arrival, a personal weekend added in another city, or a flight bought outside the channel. The policy clause about a single booking channel exists precisely to narrow that gap, and it never closes it completely. Say so.
Live location tracking of employees is a different thing again, and it carries obligations of its own. In the EU, processing employee location data falls under the GDPR: it needs a lawful basis, it has to be proportionate to a real purpose, and employees have to be informed. The Article 29 Working Party's opinion on data processing at work notes that consent is rarely a sound basis in an employment relationship because of the imbalance between the parties, which is why these programmes normally rest on legitimate interests or a legal obligation plus a documented assessment. The practical advice to give a company is to collect what the duty of care requires, say why, keep it for a defined period, and not to build surveillance it cannot justify. Again, national implementation differs, and the company's own adviser decides.
How to bring this to a company that has no policy
Most small and medium companies do not have a travel policy. They have a spreadsheet, a credit card and somebody in finance who is tired of expense claims. That is your opening, and the pitch is not about fares.
Bring one page with four things on it: a draft policy skeleton with their cabin and hotel rules left blank, the approval flow, the duty of care checklist above, and the division of responsibilities. Ask three questions in the meeting: who is called if an employee is hospitalised abroad, how they would produce a list of everyone currently out of the country, and what happens tonight if a flight is cancelled at eleven. Nobody answers all three well.
Then ask for something small: one department, or one quarter, or the trips to a single region. A company that has never outsourced travel will not hand over everything at once, and a clean small start beats a stalled large one.
The account is won on the operational half
The company's lawyer will decide what its obligations are. What you are selling is everything underneath that: the single channel, the itinerary record, the approval flow that people do not route around, the briefing that goes out before departure and the number that gets answered at three in the morning.
The connectivity clause is a small part of that, and the reason it is in the list is that an unreachable traveller makes every other part of a duty of care programme useless. If you want that part to be something you provide rather than something you troubleshoot, it is included in our partner programme.
Quick answers
Is a corporate travel policy a legal requirement?
Generally no, as a document. What is required in most countries is that the employer manages risks to employees' health and safety, which for travel includes knowing where people are, assessing trips proportionately and being able to respond. A written policy is the ordinary way to demonstrate that, not the obligation itself. The detail differs by country, so the company should check its own national law with its own adviser.
What does duty of care mean for a company with only a few travellers?
The same capabilities, at a smaller scale: one booking channel, current contact details for each traveller, an assistance provider whose number the traveller has, a short pre trip briefing for anywhere unusual, and one named person who owns an incident. That is achievable for a company of ten people in an afternoon.
Can an agency really tell a company where its travellers are?
It can say where their booked itineraries place them, for trips booked through the agency, and that is what corporate programmes rely on. It cannot know where the person actually is. Anything beyond itinerary visibility means processing employee location data, which brings data protection obligations and should not be promised casually.
Sources: Council Directive 89/391/EEC on the introduction of measures to encourage improvements in the safety and health of workers at work (12 June 1989), Article 5; Legislative Decree 81/2008 and Article 2087 of the Italian Civil Code (Italy); Health and Safety at Work etc. Act 1974, section 2 (United Kingdom); Occupational Safety and Health Act of 1970, general duty clause, section 5(a)(1) (United States); ISO 31030:2021, Travel risk management, guidance for organizations (2021); Directive (EU) 2015/2302 on package travel (25 November 2015), Article 2(2)(c) on business travel arranged under a general agreement; Regulation (EU) 2016/679 (GDPR, 27 April 2016); Article 29 Data Protection Working Party, Opinion 2/2017 on data processing at work (8 June 2017). National implementation and employer obligations differ by country, and this is not legal advice. Checked 27 September 2026.