What does duty of care actually require of employers with a global workforce?
Duty of care for employers is not a vague aspiration. It is a legal obligation to take reasonable steps to protect employees from foreseeable harm. For organisations with people working internationally, that obligation extends to geopolitical risk, civil unrest, natural disaster, and terrorism in the locations where those employees are deployed. The standard against which a court or regulator will assess an organisation's response is whether it took appropriate action, in time, with the information it had available.
The practical test is straightforward: when something happened, did you know who was affected, and did you reach them? An employer who cannot demonstrate that they identified and communicated with at-risk employees in a timely way is an employer whose duty of care is difficult to defend. This is the obligation that drives the requirement for critical event management in global enterprise, not surveillance capability, but communication accountability.
Why do most enterprise organisations struggle to identify who is affected when an incident occurs?
Most large organisations hold the information they need to identify who is at risk during a critical event. HR systems hold employment records and base locations. Travel management platforms hold itineraries for business travellers. Contractor management systems hold deployment schedules. Access control systems hold records of who is on which site. The data exists. The problem is that none of these systems talk to each other, and few if any of them are connected to a notification capability.
When an incident is reported in a specific city or region, the security team's first action is usually to extract a spreadsheet from HR, cross-reference it with the travel management company, and begin manually contacting people whose details may or may not be current. That process takes time that a duty of care response cannot afford. The gap is not a data problem. It is an integration and response problem.
How does a CEM platform determine who to reach when an incident occurs in a specific location?
A critical event management platform does not require new data collection. It connects to the systems the organisation already operates and uses those records to build a dynamic picture of who is relevant to a given incident. When an event is declared in a specific location, the platform cross-references that location against deployment records, travel itineraries, site access data, and live location data for any employee who has chosen to share it.
What is the difference between travel risk management and critical event management?
Travel risk platforms are designed to help organisations manage the safety of people who are travelling on behalf of the business. They provide country risk intelligence, itinerary tracking for registered trips, and in some cases pre-trip approval workflows. They are valuable tools for a specific population: the business traveller who has booked through the corporate travel management system.
Critical event management addresses a broader and more complex population. It covers the business traveller, but it also covers the employee whose base location is in the affected region, the contractor working on a project in the impacted area, the visiting staff member whose trip was not booked through the corporate system, and the third party whose welfare the organisation is nonetheless responsible for under its supply chain duty of care obligations. CEM does not replace travel risk management. It encompasses it within a wider response and notification capability that covers everyone an organisation is responsible for, not just those who travel.
How should a global security team respond when an incident is declared in a region where employees are working?
The ideal response sequence is consistent regardless of the type of incident. The team identifies the event and its geographic scope, determines who from the organisation is present or assigned to that area based on existing records, issues a notification to that specific population with relevant protective actions, requests acknowledgement, monitors who has and has not responded, and escalates for those who cannot be reached. Every step is recorded, timestamped, and available for post incident review.
The reality in most organisations is that some of these steps happen and some do not. The notification may reach everyone on the HR system rather than only those in the affected area. Acknowledgement may not be tracked. Escalation may depend on someone remembering to check. Post incident documentation may be assembled after the fact from email chains. The gap between the right response and the typical response is a CEM gap, and it is most visible when the situation is most serious.
Who in the organisation is accountable for signing off that reasonable steps were taken?
In practice, the governance of reasonable steps operates across three levels. At the policy level, the organisation's Head of Security or equivalent defines the response standard: what notification must go out, to whom, and within what timeframe. At the command level, the incident commander, typically the most senior security or operations lead available at the time, takes responsibility for the decisions made during the response. At the audit level, the legal or compliance function reviews the post incident record to assess whether the response met the required standard, whether for internal governance, regulatory review, or legal proceedings.
Each of those three functions requires something different from a CEM platform. Policy needs confidence that the standard is operationally achievable. Command needs a real time decision support tool that captures every action as it is taken. Audit needs a clean, timestamped record that requires no reconstruction. A platform that serves all three is not just an operational tool. It is the evidence layer that makes reasonable steps defensible.
How does AtlasNXT support global duty of care for enterprise organisations?
AtlasNXT connects to the workforce and deployment data organisations already hold, integrating with HR systems, travel management platforms, and access control records to build a response ready population picture without requiring new monitoring infrastructure. When a critical event occurs, it identifies the relevant population from those existing records and delivers notifications across multiple channels simultaneously, with two way acknowledgement that generates an automatic record of who was reached and when.
For organisations with a duty of care obligation across a global workforce, that record is not a compliance formality. It is the evidence that the organisation identified who was affected, acted immediately, and followed through on non-respondents. To find out more about how AtlasNXT delivers on this requirement please get in touch.



