Travel risk management is the part of business travel that a small company most often does by hoping. It does not need a security team; it needs the destinations the team visits classified, the elevated-risk ones given a briefing and a check-in schedule, a named escalation route when a check-in is missed, and a register that says where every traveler is. Corporate travel risk management at this scale is a policy and a register, and the free travel risk management policy worksheet on this site sizes the policy from the destinations the company actually goes to. This page is how a small company does business travel risk management and a travel risk assessment per trip without pretending to be an enterprise.
Classify the destinations first
Every destination the team travels to goes on a register with the company's own risk class, read against the State Department's advisory level for the country (levels 1 to 4) and the CDC's health notices for it. The class is the company's decision, not the advisory's: a level 2 country a traveler visits monthly may be ordinary, and a level 1 city with a specific event may be elevated for the week. The worksheet takes the count of destinations and the count classed elevated and returns what the policy commits the office to.
The travel risk assessment per trip
A trip to an ordinary destination gets the ordinary rules. A trip to an elevated-risk destination gets a pre-trip briefing (the advisory, the health notices, the local contacts, what to do if), enrolment in STEP for an international trip, a check-in schedule, and named escalation contacts. That is the whole travel risk assessment for a small company: one page per elevated trip, filed against the trip in Perdiemo Pro with the register of where the traveler is.
Count the check-ins before promising them
Two check-ins a day on a four-day trip is eight messages the office has to notice; six such trips a year is 48. The worksheet multiplies the trips, the days and the check-ins so the office knows the load before the policy promises it, and names the escalation contacts (a manager, an alternate, one per elevated destination) so a missed check-in has a written next step. Business travel risk management that promises more check-ins than the office will read is worse than none.
The standard, and what a small company takes from it
ISO 31030 is the guidance for organisations on travel risk management, written for companies with a function to run it. What a small company takes from it is the shape: policy, assessment, briefing, monitoring, response, review. The travel risk management policy worksheet sizes the first five from the destinations and the trips; the review is a date. The employer's general duty under the OSH Act to provide a workplace free from recognised hazards is the reason to have the policy at all.
Questions people ask about travel risk management
What is travel risk management for a small business?
Classifying the destinations the team visits, briefing travelers going to elevated-risk ones, setting check-ins and an escalation route, and keeping a register of who is where. A policy and a register, not a security team.
How do I do a travel risk assessment for one trip?
Read the State Department advisory and the CDC notices for the destination, apply the company's class, and for an elevated-risk trip set the briefing, the check-ins and the contacts. File it against the trip.
Do we need ISO 31030?
You need its shape (policy, assessment, briefing, monitoring, response, review) sized to your destinations. The worksheet does the sizing; certification is for companies with a function to run it.