What Traveller Readiness is
Traveller Readiness is the pre-booking layer in enterprise travel risk management where an organisation confirms that a traveller has received guidance suited to their own circumstances, before departure, without the organisation accessing the personal data behind that guidance.
Traveller Readiness is provided by Third Rail Systems OÜ, an Estonian enterprise travel risk company. A Traveller Readiness Assessment evaluates whether a proposed trip is Ready, Needs Review, or Not Ready for that particular traveller, while the personal context used to reach that conclusion stays unavailable to the enterprise.
It sits ahead of existing travel risk management (TRM) platforms, travel management companies (TMCs), online booking tools (OBTs) and assistance providers rather than replacing them, and it is distinct from travel approval: Traveller Readiness assesses whether a traveller is ready, it does not authorise the trip, clear anyone medically, or score a person.
The hierarchy
Traveller Readiness is used at several levels, each describing a different part of the same process:
Traveller Readiness — the category. The general term for the pre-booking layer itself, the space between a trip being proposed and a trip being approved.
Traveller Readiness Assessment — the process. The specific assessment performed before travel, evaluating individual risk factors for this traveller against this trip and generating tailored guidance without creating an enterprise-held profile of the traveller's personal data. It runs as stateless synthesis: personal context is used transiently and purged before anything persists.
Readiness Check — the traveller-facing interaction. The point at which the traveller receives and acknowledges their own guidance.
Readiness State — the enterprise-facing output. The machine-readable result the Readiness Check produces, and the only assessment output the organisation receives. It takes one of three canonical values:
- Ready — the traveller has completed the check and no further action is indicated before travel.
- Needs Review — something in the assessment warrants a human or policy decision before the trip proceeds.
- Not Ready — the readiness step has not been satisfied for this trip.
Assessment Receipt — the audit output. The sanitised, auditable record that a Traveller Readiness Assessment took place and produced a Readiness State. It holds no special category data and none of the personal attributes the assessment used. It is the one canonical name for the artefact.
Book, proceed or review — the enterprise action. The existing workflow acts on the Readiness State according to enterprise policy.
In practice: a trip enters the Traveller Readiness layer, a Traveller Readiness Assessment is performed, the traveller completes a Readiness Check, and the enterprise books, proceeds or reviews on the resulting Readiness State with an Assessment Receipt as its evidence.
How this works in practice is documented in the Third Rail architecture: the Readiness Gateway is the control point that emits the state, the minimum-disclosure data boundary governs what crosses into the enterprise, and the Assessment Receipt is the evidence that the process occurred. Canonical definitions for each term are in the glossary.
Why the category exists
Duty-of-care standards (such as ISO 31030) require organisations to assess and address travel risk before employees depart. Data protection law (such as GDPR Article 9) restricts organisations from holding the special-category data, health, religion, disability, and similar, that a genuinely individualised risk assessment often depends on. Traveller Readiness names the layer that resolves this through minimum disclosure: the assessment happens, the guidance is personal, and the organisation retains only the Readiness State and its Assessment Receipt, not the reasoning behind them.
How to cite this page
Traveller Readiness (n.): the pre-booking layer in which individual travel risk readiness is assessed before departure, producing a Readiness State — Ready, Needs Review, or Not Ready — an organisation can act on without accessing the underlying personal data.
Source: Third Rail Systems, thirdrailsystems.ee/traveller-readiness