TripAgent.ai

For business · Travel risk management

Travel risk management software: duty of care, employee travel tracking and ISO 31030

Itinerary Studio
Ready Planning
Days

The free demo plans trips up to 5 days; a free account goes to 7.

Who is going
Budget for the trip (USD, optional)
Pace
Travellers
Start date (optional)
What you are into (pick up to 5)

Building your day-by-day plan

Picking real places, sequencing them so the days flow, and costing every item. This takes up to a minute.

Your whole trip, planned in one pass

Set where, how long, your budget and your pace. TripAgent writes the days out hour by hour, with real places and a cost on every line.

Free to try, no signup needed · the first two days are shown in full

Most writing about this category starts with the legal obligation and stays there, which is why so many travel risk programs look complete on paper and fall apart the first time a flight is canceled at 11pm. The obligation is real, but it is not the hard part. The hard part is operational: at any given moment, can you say with confidence which city each of your traveling employees is in, and can you reach them there?

Last updated August 2026

Day-by-day itinerary · a cost on every line · rebuilds any day on request

The short answer

Travel risk management software is the system a company uses to know where its travelers are, assess a destination before anyone flies, reach people during an incident, and document that it did all three. In the US market it is priced per traveler per year, roughly $25 at the tracking-only end and $250 or more where medical and security assistance is bundled in, so the number that drives your bill is how many people actually travel, not headcount. The standard everyone cites is ISO 31030, and the most useful thing to know about it is that it is a guidance document rather than a requirements standard, which means there is no ISO 31030 certification to buy and any vendor offering one is describing its own audit, not an ISO scheme. TripAgent.ai covers the itinerary half of this problem: it holds the current plan and prices it, and any day can be rebuilt the moment the trip changes shape. It is not a medical or security assistance provider, and if you send people into genuinely high-risk destinations you should buy that cover separately.

That question has an unglamorous answer. It depends almost entirely on whether the itinerary data is current, and itinerary data goes stale the instant someone rebooks outside your system. This page covers what the software category actually does, what it costs per traveler in the US in 2026, what ISO 31030 asks for and what it pointedly does not offer, and where a planning tool like TripAgent.ai genuinely helps versus where you need a specialist vendor instead.

Vendor capabilities and the pricing range below were read in August 2026. Where a figure is a market range rather than a published rate, it is described as a range, because almost nothing in this category carries a public price list.

FLIGHTS HOTELS ACTIVITIES DAY-BY-DAY

Tell it your trip get a full itinerary

Plans change it rebuilds any day on request

Why it works

Three things that decide what you actually need

The bill follows travelers, not headcount

This category prices per traveler per year, roughly $25 for tracking only up to $250 and beyond with medical and security assistance. A 900-person company with 60 real travelers pays for 60. Count the people who actually fly before you take any quote seriously, because vendors will happily quote against your whole org chart.

ISO 31030 is guidance, not a certificate

ISO 31030:2021 is titled guidance for organizations, and that word is doing real work. It is not a requirements standard, so there is no accredited certification track behind it. You can align a program to it and say so honestly. You cannot become certified in it, and neither can your vendor.

Location data is only as fresh as the booking

Every tracking feature in this category runs on itinerary data, mobile signals or manual check-ins. The itinerary is the backbone and the other two are patches. If people book outside your platform when things go wrong, your map is showing you where they were supposed to be, which is the exact moment it matters least.

What it handles

Tell it your trip, get a costed day-by-day itinerary

Share your destination, dates and budget and TripAgent.ai writes a day-by-day itinerary with real places, times and a cost estimate on every line. You set the preferences, approve anything, and let it run.

  • Names the real US price range per traveler per year instead of quoting a single vendor
  • Separates what specialist risk platforms do from what a booking tool can cover
  • Corrects the most common ISO 31030 mistake before it reaches a board slide
  • Lists the five duty of care obligations a program is judged on
  • Explains why traveler location data goes stale and what actually fixes it
  • Says plainly when you should buy a specialist vendor rather than us
YOUR ITINERARY Costed
Flight out DAY 1 · 8:40 AM
Hotel check-in DAY 1 · 3:00 PM
Old town walking tour DAY 2 · 10:00 AM
Flight home DAY 4 · 6:15 PM
trip in · itinerary costed rebuilds any day on request

Honest comparison

Specialist travel risk platform vs a booking tool that holds the itinerary

These are two different purchases that overlap in one place, traveler location. This table is written to help you work out whether you need both, and it is explicit about the things TripAgent.ai does not do. Pricing in this category is quoted rather than published, so treat the range as a planning figure and confirm it against your own quote.

What you are buying Specialist travel risk platform TripAgent.ai
Typical US price $25 to $250 or more per traveler per year, quoted, usually with a minimum traveler count $19 a month flat for the whole planning product, published, no traveler minimum
Where traveler location comes from Itinerary feeds from your agency or booking tool, mobile app signals, and manual check-ins, combined The itinerary itself, because the plan lives here and is rebuilt in place
Pre-trip destination risk rating Yes, from an in-house intelligence team, with country and city level ratings and daily updates No. Bring your own source. State Department advisories and CDC destination pages are free and public
Medical and security assistance Yes at the higher tiers: evacuation, vetted local providers, a 24/7 crisis desk staffed by people No. This is the clearest reason to buy a specialist product alongside rather than instead
Mass notification and safety check-in Yes. Two-way messaging, are-you-safe checks, escalation trees, response tracking for the audit file No. Traveler contact here is per trip, not a crisis communication system
the day rebuilt after a disruption Rarely. Most platforms detect the disruption, alert, and hand off to a human agent to rebuild the affected day Yes. The day is rebuilt on request when a flight is canceled, and the traveler makes the new booking
Who buys it internally Security, risk, HR or legal, often on a budget line that has nothing to do with travel Whoever plans and manages the travel
Contract shape Annual, per traveler, quoted after a scoping call, commonly with a minimum count and a term Monthly, published rate, cancel any time
Best for Companies sending people to genuinely high-risk destinations, or carrying a board-level duty of care obligation Companies whose real gap is that nobody is certain what the current itinerary is

What is travel risk management?

Travel risk management is the practice of identifying what could go wrong on a work trip, reducing that exposure before departure, responding when something does happen, and keeping a record of all of it. It applies to every business trip, not only trips to obviously dangerous places, because the most common incidents are medical events, road accidents and disruption, not the ones that make the news.

The reason it exists as a discipline rather than a paragraph in a travel policy is that the obligation sits with the employer. When you direct an employee to travel for work, you take on responsibility for foreseeable harm on that trip. Where the legal line falls varies by jurisdiction and by how the employment relationship is structured, but the practical standard organizations are measured against is consistent: did you assess the risk, did you tell the traveler, could you find and reach them, and can you show what you did.

That last clause is why documentation keeps appearing in this category. A program that worked but left no record is very hard to defend after the fact, which is why almost every specialist platform sells its audit trail as hard as its intelligence feed.

What is ISO 31030?

ISO 31030:2021, titled Travel risk management, guidance for organizations, is the international standard describing how to build and run a travel risk program. It covers policy, program development, threat and hazard identification, risk assessment, and prevention and mitigation strategies, and it frames all of it as a cycle you develop, implement, evaluate and review rather than a one-time setup.

It is deliberately not prescriptive about tools. The standard does not tell you to buy tracking software or to contract a medical assistance provider. It tells you to establish governance and ownership so it is clear who makes travel risk decisions and under what policy, to assess risk before travel at the destination, itinerary and traveler level, and to prepare employees so they understand the exposure they are walking into and what to do about it.

For most US companies the practical value of ISO 31030 is as a checklist and a common vocabulary. It gives you a defensible structure to point at, and it gives your vendors and your insurer a shared set of terms. That is genuinely useful. It is also the entire benefit, which brings us to the question people get wrong most often.

Can you get ISO 31030 certified?

No. ISO 31030 is a guidance standard rather than a requirements-based standard, and only requirements-based standards carry an accredited certification scheme. There is no ISO 31030 auditor, no certificate, and no registrar that can issue one. Adoption is voluntary, and the honest phrasing for a program built against it is aligned with ISO 31030, not certified to it.

This matters commercially because the distinction gets blurred in sales conversations. A vendor may offer an ISO 31030 assessment, readiness review or alignment badge. Those can be perfectly legitimate consulting products, and some are genuinely good, but they are that vendor assessing you against its own reading of the guidance. They are not an ISO certification and should not go on a board slide as one.

The useful test is one question: who accredits the body issuing this, and against which requirements clauses. For a standard like ISO 27001 that question has a clean answer. For ISO 31030 it does not, because the clauses are recommendations. Ask it early and it will save an awkward correction later.

How much does travel risk management software cost?

Expect roughly $25 per traveler per year at the tracking-only end of the market and $250 or more per traveler per year where medical and security assistance, evacuation cover and a 24/7 crisis desk are included. Almost nothing in this category is publicly priced, so those are market planning figures rather than published rates, and every real number arrives after a scoping call.

The variable that moves your bill most is the definition of traveler. Some vendors count every employee who could travel, some count everyone with a trip in the last twelve months, and some count concurrent travelers. Between the widest and narrowest of those definitions the same company can see a three or four times difference on identical coverage. Settle the definition before you compare two quotes, or you are not comparing the same thing.

The second variable is what happens when someone needs help. Tracking and alerting are cheap because they are software. Medical evacuation, vetted in-country providers and a staffed crisis desk are expensive because they are people and logistics on standby. If a quote looks unusually low for full assistance, that is the line item to interrogate.

How do companies track employees while traveling?

Three sources, usually combined. Itinerary data from the booking tool or travel agency gives the planned route and is the backbone. Mobile app signals give an actual position when the traveler has the app installed and consented. Manual check-ins fill the gaps, either traveler-initiated or prompted by the platform. Each source fails differently, which is why serious programs run more than one.

Itinerary data is the most complete and the most fragile. It covers every trip booked through the channel and nothing booked outside it, so the moment a traveler rebooks directly with an airline during a disruption, your map is confidently wrong. This is not a rare edge case. It is what happens on exactly the night you most need the data to be right.

Mobile signals fix that, at a cost. They require the app, an opt-in, and a privacy posture you can defend to your own employees and, if you have people in California or an EU-based entity, to a regulator. Consent-based location tracking is normal in this category and is generally accepted when it is scoped to work trips and clearly explained. Continuous tracking outside trips is where programs get into trouble.

The structural fix for the itinerary problem is to make day rebuilds happen inside the system rather than around it. If the rest of the day is re-planned where the itinerary lives, the plan stays accurate through the disruption instead of breaking at it. That is the specific gap TripAgent.ai closes: the traveler asks for the affected day and gets it back re-sequenced around the new timing. It does not reissue the ticket - you rebook through your own channel - and closing this gap is not the same as running a full risk program.

How do you build a travel risk management program?

Start by writing down who owns it. Most programs that stall do so because travel risk sits between travel, HR, security and legal, and each assumes another owns the decision. Name one accountable owner, define what they can decide alone and what escalates, and put it in the travel policy rather than a separate document nobody reads.

Then work through the five obligations a program is judged on, in order.

Pre-trip risk assessment: rate the destination and the itinerary before approval, using a consistent source. State Department advisories and CDC destination health pages are free, public and sufficient for most domestic and low-risk international travel. Buy an intelligence feed when you routinely send people somewhere those sources rate as elevated.

Traveler preparation: tell the traveler what the rating means and what to do. A one-page destination brief attached to the itinerary beats a training module nobody finishes.

Real-time location awareness: keep the itinerary current, which means keeping bookings and changes inside one channel. This is the obligation most likely to be quietly broken.

Incident response: have a documented path from an event to a named human, with an out-of-hours route that does not depend on one person answering a phone.

Post-trip review: log incidents and near-misses. This is the cheapest of the five and the one most often skipped, and it is what turns a policy into a program that improves.

Who are the travel risk management companies?

The enterprise tier is led by International SOS, Crisis24, Healix International, Global Guardian and Control Risks. These are assistance companies first and software companies second: what you are buying is a global network of vetted medical and security providers, an intelligence team, and a crisis desk, with a platform on top. They are the right answer for organizations with genuinely exposed travel, and they are priced accordingly.

Below that sit specialist platforms including Riskline, Safeture, Solace Global and A3M, which serve mid-market programs. The trade is generally more software and less standing assistance capability, at a materially lower price per traveler.

Then there is the layer most companies actually start with and rarely name as a purchase: the booking platform that holds the itinerary. Corporate travel tools including SAP Concur, Navan and TravelPerk all feed traveler location data into this picture, and several bundle basic duty of care reporting. TripAgent.ai belongs in this layer. It is worth being precise about what that means. A planning tool can tell you where people are meant to be, and keep that accurate as long as the itinerary is kept current. It cannot evacuate anyone.

If you are choosing where to spend first, the sequence that works for most US companies is: fix the itinerary channel, adopt free public risk sources, write the response path down, and only then price an assistance contract against the trips that genuinely need one.

Why TripAgent.ai

One travel agent that plans, sequences and prices for you

Not a blank search box, not a dozen research tabs, and not a bare list of attractions. Your whole trip planned day by day, with real places, times and a cost on every line, and any day rebuildable in one click.

Day-by-day itinerary

TripAgent.ai turns your destination, dates and budget into a realistic day-by-day plan, with the right pace and travel times built in, not a blank search box.

Prices everything

Every place, meal and ticket carries a cost estimate, with a total per day and for the trip, matched to your budget, so you know the number before you go looking to book.

Rebuilds any day on request

A change of plans or a closed attraction, and you rebuild that one day while the rest of the trip stays exactly as it was.

Good questions

Questions US travel and risk managers ask

It is the employer obligation to take reasonable steps to protect employees from foreseeable harm on work trips. In practice it is judged on five things: assessing the destination before approval, briefing the traveler, knowing where they are, being reachable and able to respond when something happens, and keeping a record of all four. It applies to a sales trip to Denver, not only to high-risk destinations.
Usually not as a separate purchase. Under roughly 50 travelers a year on ordinary domestic and low-risk international routes, the obligation is met by a single booking channel that keeps itineraries current, free public risk sources, and a written response path with a named owner. Buy a specialist platform when destinations get genuinely risky, when a client or insurer requires it, or when the traveler count makes manual tracking unrealistic.
Consent-based tracking scoped to business travel is generally accepted, and it is the normal design in this category. The problems come from scope and disclosure rather than the tracking itself: tracking outside work trips, collecting location without a clear opt-in, or failing to disclose it. California and EU-linked entities carry additional obligations. Write the scope down, get explicit consent, and let travelers turn it off outside trips.
No, and the two are often confused in quotes. Insurance reimburses financial loss after a covered event. Travel risk management is about preventing and responding to the event: knowing where people are, reaching them, and getting them help or getting them out. Higher-tier assistance contracts do include evacuation, which is a service rather than a reimbursement, but they do not replace a policy.
By keeping the itinerary true. TripAgent plans the trip, so it holds the itinerary, the timings and the costed day-by-day view, and any day can be rebuilt in seconds when something changes. That closes the failure mode where your traveler map is accurate right up until the moment travel goes wrong. It does not provide medical or security assistance.
Destination rating from a consistent source, health requirements and vaccinations, the specific itinerary including ground transport and any overnight transfers, traveler factors such as solo travel and medical history where voluntarily disclosed, the accommodation, local emergency and embassy contacts, and the communication plan. Attach it to the trip approval so the assessment is dated and recorded rather than remembered.

Explore more

More ways to plan and cost your trip with TripAgent.ai

Stop juggling tabs. Tell us the trip and it plans itself.

Share your destination, dates and budget and TripAgent.ai writes a day-by-day itinerary with real places, times and a cost estimate on every line.

See pricing

A cost on every line · day-by-day itinerary · rebuilds any day on request