On 29 June 2012, gunmen attacked a Norwegian Refugee Council convoy in Dadaab, Kenya, killing a driver and kidnapping four staff during a visit by the organisation's secretary general. The day before, managers had dropped the armed escort the NRC's own security plan required, reading nine months without a kidnapping as a fall in the threat. After a travel risk assessment, the step that matters is writing down what would force it to be reopened, and who does the reopening.
A travel risk assessment is an organisation's pre-trip review of threats along an itinerary, the risk rating it produces, and the measures approved to reduce it.
Dadaab 2012: nine quiet months were read as a lower threat
The NRC had worked in the Dadaab camps since 2006. On 13 October 2011, armed men abducted two Médecins Sans Frontières logisticians, Montserrat Serra and Blanca Thiebaut, from the IFO II camp while they worked on a hospital, according to MSF's own statement. That month the Kenyan authorities declared war on Al Shabaab. From late October, armed escorts were mandatory for aid convoys in Dadaab.
The UN raised its risk level for the area from 3 to 4, one short of evacuation. The NRC's security plan rated kidnapping "critical" and made escorts mandatory. No organisation had brought a VIP into the camps for several months. In early June 2012 the NRC decided its secretary general would visit IFO II, a newer and less established camp than the others, to draw donor attention to the refugee crisis.
The day before the visit, the country director, consulting the regional director in Nairobi and the head of field operations in Oslo, decided not to use the armed escort. The stated reasons were a lower profile and a lower risk of roadside bombs. The regional director pointed to nine months without a kidnapping as a sign the threat had receded. Security specialists were not consulted on the change.
The visit was also no secret. Staff knew in advance and third parties in Dadaab had been told. On 29 June, six armed men fired on the three-car convoy as it left the camp. A Kenyan driver hired that same day was shot dead. Steven Dennis, a Canadian staff member, was shot in the thigh and driven off with three colleagues. Kenyan authorities and a local militia freed all four near the Somali border four days later.
On 25 November 2015 the Oslo District Court found the NRC grossly negligent in safeguarding its staff during the visit and awarded Dennis NOK 4.4 million. It held that the kidnapping was foreseeable and probably would not have happened with an armed escort. Among the clear deviations from responsible conduct, as set out in the European Interagency Security Forum review of the ruling, it listed an "unclear and unwarranted re-assessment of the risks of both kidnapping and IEDs".
The court's reading of the nine quiet months is the part that travels to every trip approval. The most likely explanation for the quiet, it reasoned, was that no VIP visits had taken place and armed escorts had become mandatory. The absence of kidnappings was the controls working, not the threat leaving. The managers read it the other way and removed the control that had produced it.

Nothing in the approved plan marked the escort decision as a moment to reopen the assessment. The rating stayed "critical" on paper while the measures beneath it were rewritten in a day. The same move appears in risk matrix ratings, where one line of reasoning shifts a hazard into tolerable territory without anyone retesting what the rating assumed.
Take the mitigation your next travel approval leans on hardest and write down the change that would send it back for re-assessment before anyone boards. Start the Walk →
A travel risk assessment gets the destination right, then goes quiet
Travel risk assessment applies the wider discipline of risk assessment to people in transit, and it does real work. ISO 31030:2021, published in September 2021, gives organisations a structured approach to developing, implementing, evaluating and reviewing a travel risk management policy and program, and to assessing and treating travel risks. It builds on ISO 31000:2018 and frames the work around legal and duty of care responsibilities to travellers.
A competent assessment forces the questions an eager traveller would skip. What is the threat at the destination and along the route? Who is travelling, and how visible are they? Which measures bring the risk to a level the organisation will accept, and who signs off? In Dadaab the NRC's plan answered those questions correctly. It rated kidnapping critical and required an escort. The failure did not sit in the analysis. It sat in what happened to the analysis afterwards. At a venue, what to do after a terrorism risk assessment makes that handoff explicit by connecting each exposed area to the person responsible for protecting it.
That is where the format stops. An assessment is signed off once, against the conditions known on the day, and approval turns a conditional judgement into a standing permission. Like any output of the risk assessment process, it records a rating and the measures that justify it. It does not record which of those measures the rating depends on, or which change on the ground should send it back for review.
The same EISF review notes that the risk analysis and the measures built on it should be reviewed when changes are observed or incidents occur. The difficulty is that "changes" is not a list. Without one, each change is judged case by case by whoever is under pressure to keep the trip moving. In Dadaab, the managers organising the visit made the escort call without the specialists who had set the rule.
All three readings are reasonable, and none of them names who reopens the assessment when the ground moves. An approved rating is only as current as its least-checked condition. Ratings that rest on agreement rather than evidence, the gap examined in the step after risk analysis, decay fastest once the traveller is in the field.
Name the conditions that reopen a travel approval before departure
The artefact to check is the approved rating and the short list of conditions it depends on. For each mitigation in the approval, write the assumption beneath it as a plain condition: the escort is in place; the itinerary is the one assessed; the visit is known only to those who need to know; the threat level is the one on file. Change any one and the rating is no longer the one that was approved.
Then attach triggers. Four cover most trips. A security incident in or near the destination after sign-off. A change to itinerary, destination, duration or route. A change to escort, vehicles, drivers or accommodation. A change to the profile of the trip, such as a senior visitor or a published schedule. The Dadaab visit tripped two of them: a senior visitor whose schedule third parties already knew, and a withdrawn escort alongside a driver hired on the day.
Any trigger sends the assessment back to the person who set the rating, not to the person keeping the trip on schedule. A proposal to remove a mitigation counts as a trigger in its own right. The same discipline applies after a workplace risk assessment, where ratings are tested before controls are built on them.
Add one test for good news. A quiet record is evidence about the controls before it is evidence about the threat. Before any period without incidents is used to relax a measure, ask whether the measure produced the quiet. If it might have, the quiet cannot justify removing it.
This is monitoring designed into the decision rather than bolted on afterwards, the same logic as monitoring a decision against the conditions it assumed. In the Universal Decision-Making Method, what gets monitored is settled before the decision is finalised, so the signal to revisit exists before anyone needs it.
An approval without triggers is a permission that never expires. Conditions will change after sign-off. The only question is whether anyone agreed in advance which changes count.
The Norwegian Refugee Council had a security plan that rated kidnapping critical. What it didn't have was a rule for what would reopen the approval when the escort came off.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.