When Work Crosses Borders, Compliance Must Follow
The Employee is No Longer in One Place
Let’s take a couple of hypothetical situations. First, a European airline recruits a pilot who lives in France; said pilot is employed through an Irish group company, has a home base in Spain, and regularly operates routes to the Gulf. Second, a software specialist employed by a German entity works remotely from Luxembourg and travels to client sites in the US. Both arrangements are perfectly commercially logical, and are nowadays commonplace, but neither are operationally simple.
An employee’s contract may identify one employer, while payroll, operational direction, residence, physical work location, and immigration status all point to several others. The organisation may need to assess social security, A1 certification, S1 healthcare registration, payroll withholding, income tax, permanent establishment risk, employment rights, work authorisation, working times, data protection, and industry-specific certification. Consequently, cross-border workforce compliance quickly becomes an operational issue.
Naturally, the aviation and maritime industries have always had to factor in cross-border employment with multi-jurisdictional exposure, followed by complex audits. Indeed, both industries combine highly mobile employees with safety-critical responsibilities. Yet the same control challenge affects the logistics and manufacturing sectors, technology, construction, financial services, and other internationally active businesses.
The Map is Larger Than the Contract
An employment contract is essential, but it is only one document in a wider compliance system. In fact, these are four questions cross-border employers ought to answer:
- Where is the employee physically working?
- Which entity directs and benefits from the work?
- Which country’s social-security legislation applies?
- What evidence proves the answer?
These questions are further complicated by common employment metrics. Such as the contractual employer, the operational employer, the payroll entity, the employee’s country of residence, the country where work is physically performed, the competent social security authority, and the immigration or work-authorisation jurisdiction.
These are not necessarily the same. EU social-security coordination rules are designed to ensure that a person is covered by the legislation of one country at a time. However, the applicable country depends on the factual pattern, including whether the person is temporarily posted or habitually works in several Member States. Malta’s Department of Social Security, for example, applies those rules to situations including multi-state work, flight and cabin crew and people working on Maltese-flagged vessels.
A1, S1 and Remote Work
A1 is evidence, not a passport
A Portable Document A1 confirms which country’s social-security legislation applies to an employed or self-employed person working across borders. It may be relevant to temporary postings, habitual work in two or more Member States, certain self-employed or mixed employment situations and qualifying cross-border telework.
An A1 certificate is not a compliance passport. It answers one question: where social-security contributions belong. It does not determine where income tax is due, whether a work permit is required, whether local employment law applies or whether the employee’s activities create a taxable presence.
Cross-border employers should distinguish between a temporary posting under Article 12, habitual work in several Member States under Article 13, and arrangements covered by the cross-border telework framework. The same employee may move from one category to another when their roster, residence or work pattern changes. Consequently, an A1 application should not be treated as a one-time onboarding exercise.
In July 2026, the European Parliament approved a revision that includes a ‘prior notification’ system and exemptions for certain business trips and activities of no more than three consecutive days, while excluding construction from the short-term exemption. The reform still requires employers to monitor formal adoption, entry into force and transitional provisions. As a matter of course, employers need better records of travel purpose, duration, location(s), and work performed.
S1 completes the picture
The S1 is a healthcare-entitlement document for employees who live in one country but are insured in another. It can be relevant to posted workers, cross-border workers and their dependents. The document must be registered with the health-insurance authority in the country of residence.
In addition, there is an operational connection between the two processes: applicants are asked to provide a copy of the A1 document, and the S1 follows the A1’s validity period. This is a useful model for any international employer. Certificates should not be compartmentalised but form part of a connected employee file with a clear owner, including contracts, assignment dates, residence information, travel records, and payroll data.
Remote work is factual
Policies cannot override actual working behaviour. An employee may be approved to work remotely from home for two days a week but spend additional days working from a client site, a group office, or yet another country. Those days may matter for social security, tax, employment law, and data protection.
The difference between tax and social security is also critical. Current cross-border arrangements may contain separate thresholds for each. There is a practical tension between tax limits for remote work and the separate social-security framework. In fact, a company that tracks only “home-working days” may still miss business travel and third-country workdays that affect the analysis.

Audits Expose Operational Weaknesses
AOCs
Commercial aviation is a particularly demanding environment. Pilots and cabin crew work across borders, airlines use complex employment and operating arrangements, and authorities often struggle to identify the actual employer, the habitual place of work and the applicable legal framework.
Competent authorities under the EU air-operations framework must maintain oversight through audits, inspections and investigations, with access to records and other material relevant to the organisation’s compliance. EASA oversight guidance consequently connects management systems with documented accountability, risk management, competent and trained personnel, compliance monitoring, and records.
For a global operator, this can expose weaknesses in crew qualification, training records, licence and medical-document control, fatigue management, rostering, outsourced personnel, and lines of operational responsibility. The critical question is not simply whether a document exists, but whether the operator can demonstrate that the right person was qualified, trained, scheduled and authorised for the work performed. Constructively, AOC audits are much more than simple technical inspections, and may expose a number of similar or correlative insufficiencies, such as:
- insufficient or improperly qualified personnel;
- incomplete training or competence records;
- expired licences or medical documents;
- unclear lines of responsibility;
- inconsistent crew records;
- unverified outsourced or temporary workers;
- gaps between manuals and actual workforce practices;
- weak corrective-action evidence.
AOC Case Study
A recent example in the US shows how quickly a workforce record failure can become an operational and certification crisis. Last February, the FAA issued an emergency order revoking the Air Carrier Certificate of Houston-based Part 135 operator StarFlite Aviation; alleging that management personnel falsified training records for at least 10 pilots between 2019 and 2024, recording check rides and competency checks that had not taken place. According to the FAA, the operator consequently used unqualified pilots on at least 170 flights and lacked qualified management personnel to ensure safe operations.
The case illustrates the difference between having a training-record system and having an effective competence-control system. A mature operator must be able to reconcile pilot records with rosters, aircraft types, training providers, simulator approvals, licences, and actual flight activity.
Maritime audits
Maritime audits operate through a similarly integrated model. The IMO’s International Safety Management Code requires companies to establish and maintain a documented safety-management system covering safe operation and pollution prevention. The system must address risks affecting ships, personnel and the marine environment, with commitment and competence expected at every level of the organisation.
Subsequently, verification may cover the company’s shore-based management system and the shipboard system. The ISM process includes initial, annual, intermediate, renewal and additional verification, supported by objective evidence, interviews, document examination and observations of activities. The company’s Document of Compliance and the vessel’s Safety Management Certificate depend on the system functioning in practice, not merely existing on paper.
The Maritime Labour Convention (ILO) adds a direct workforce dimension. Flag-State and port-State inspections examine seafarers’ employment agreements, wages, hours of work and rest, accommodation, food, medical care, repatriation, and welfare arrangements. The ILO’s inspection guidelines expressly provide for deficiencies to be recorded and, where necessary, vessels to be detained.
Maritime audit case study
Last March, Australia’s maritime authority detained the Liberian-flagged bulk carrier Ocean Bright after receiving a complaint that crew members had not been paid for two months. AMSA found that eight seafarers were owed US$46,334 and identified 18 deficiencies. The vessel was released after the deficiencies were rectified but was banned from Australian ports for six months.
This consequential payroll failure also demonstrates the dangers of burdening a single compliance environment with employment records, crew welfare, vessel operations, and port access. Maritime audit readiness must include evidence that workforce obligations are being managed as part of safety and operational governance.
The same principle applies outside aviation and the maritime industry. A logistics company may need to reconcile driver deployment with working time records. A maritime operator may need to connect crew contracts, vessel assignments and flag-state requirements. A technology group may need to compare remote-work approvals with customer-site access and tax-risk assessments. A construction business may need to reconcile posted-worker notifications with project attendance and subcontractor invoices, and the list goes on.
Conclusively, the audit window is a governance test. It asks whether the organisation can demonstrate not only that it has policies, but that those policies are implemented and supported by reliable evidence.
Control Models for Cross-Border Employers
Preparing for high-stakes aviation and maritime operational audits
To be fully prepared and compliant, I would advise companies to implement five practical controls. First, global companies should maintain a live jurisdictional workforce register covering each employee and contractor’s employing entity, residence, physical work locations, expected work split, assignment dates, A1 and S1 status, work authorisation, payroll country, tax-review status, business travel, critical licences, and training.
Second, organizations should require approval before hiring someone resident abroad, authorising cross-border remote work, changing a work location, posting staff, deploying crew, using an employer-of-record model, allowing extended business travel, or changing payroll entities.
Third, cross-border employers should reconcile systems:
- payroll against employment contracts;
- rosters against countries of work;
- travel records against A1 scope;
- training records against assigned duties;
- work permits against deployment;
- invoices against worker classification;
- corrective actions against audit findings.

Finally, global firms can be proactive in commissioning independent workforce audits with the help of HR experts. Indeed, specialist outsourcing strengthens governance, brings jurisdictional knowledge to the table, offers clearer process ownership, and standardises records and sector-specific understanding to a fragmented workforce environment. In this way, organizations alleviate their in-house operations while also sharing operational risk.
By now it should be evident that cross-border employers most exposed to workforce risks are not necessarily those with the largest headcount, but those whose people, contracts, payrolls, travel patterns, and operational responsibilities, are spread multi-jurisdictionally.
From my perspective, the question is not whether a company needs an international mobility policy, but whether it has a workforce control system capable of identifying change before any legally sequential audits.



AOC Case Study
Maritime audit case study
Control Models for Cross-Border Employers