Quick answer
You can't safely approve a cross-border remote work request on a manager's say-so alone. Every request needs to be screened for four things before anyone signs off: tax withholding exposure, immigration status, social security obligations, and permanent establishment risk. Route the decision through a structured workflow, manager, then HR, then a compliance or tax reviewer, with risk scoring at each step, and only approve once every category shows green.
Skip the screening and you don't find out about the problem until an audit, a tax authority letter, or a payroll error tells you.
Why "just say yes" is a tax landmine
Remote work requests feel like a scheduling question. They're actually a compliance question wearing a scheduling question's clothes.
The moment an employee performs work from a new country, three governments potentially get an interest in the arrangement: the employee's tax residency can shift, the employer may owe local payroll withholding, and the company itself can be treated as doing business in that jurisdiction. None of that requires a formal transfer, a new contract, or even a long stay. It just requires presence and activity.
And the window for discovering this quietly is shrinking. Tax authorities increasingly share data with each other, which means a remote work arrangement that once might have gone unnoticed for years now surfaces much faster.
The four risks hiding in every request
Every cross-border remote work request, whether it's four weeks or four years, needs to pass through the same four checkpoints: tax withholding, immigration, social security, and permanent establishment.
Each one has its own triggers, its own thresholds, and, critically, its own definition of "safe" that has nothing to do with the others. A request can clear immigration and still create a permanent establishment problem. It can be well under 183 days and still shift tax residency. That's why screening all four, every time, matters more than any single rule of thumb.
The traffic-light way to read a request
Instead of a single yes or no gate, score each request against each risk category with a simple traffic light. It's a faster read for approvers and it makes the reasoning behind a decision visible after the fact, which matters if anyone ever asks why a request was approved.
Green: clear to approve
- Home and host country have a totalization or social security agreement
- Duration falls well inside treaty-protected thresholds
- No local registration or PE indicators for the role
- Employee holds valid status to work remotely from that location
Amber: needs a closer look
- Duration is approaching a residency or treaty threshold
- Role involves client-facing work or contract signing authority
- No totalization agreement, but exposure looks modest
- Immigration status allows entry but not clearly remote work
Red: pause and escalate
- No lawful basis to work from the destination country
- Role creates a plausible fixed place of business abroad
- Extended or repeated stays with no local payroll set up
- Destination has no agreement covering social security
A request doesn't need all four categories to be red for you to pause. One red is enough to escalate. The categories aren't averaged, they're independent gates.
Build the approval into a workflow, not a reply
The fix isn't more caution from any one approver. It's removing the decision from a single inbox entirely. A defensible process moves the request through three roles in sequence, each answering a different question.
Step 01
Manager
Is this the right call for the team?
Confirms business justification, timing, and whether the role can actually be performed remotely from the requested location without disrupting the work.
Step 02
HR
Does this fit policy?
Checks the request against duration limits, eligible locations, and precedent, and flags anything that would set an inconsistent standard across the team.
Step 03
Compliance
What does this location require?
Runs the risk assessment across tax, immigration, social security, and PE, and is the only role with authority to clear an amber or red result.
The sequence matters. Compliance shouldn't be the first stop for every request, because that turns a fast-moving team into a bottleneck. But compliance should be the last stop before anyone starts working, every time, with no exceptions for "it's only a few weeks."
Spreadsheet approvals versus a structured workflow
| Question | Email and spreadsheet approach | Structured workflow |
|---|---|---|
| Who reviewed this request? | Whoever the email thread happened to include | Manager, HR, and compliance, every time, by design |
| What was the risk basis for approval? | Rarely documented anywhere durable | Recorded risk score per category, with a paper trail |
| How is a similar request handled next time? | Depends who remembers the last one | Same rules applied automatically, every request |
| What happens at day 150 of an approved stay? | Nothing, until someone happens to notice | Threshold alerts flag it before day 183 arrives |
Before you approve, run this checklist
- Destination country and exact duration are confirmed, not estimated
- Immigration status for remote work in that location has been verified
- Social security agreement status between home and host country is known
- Role responsibilities have been checked for PE indicators such as contracting authority or client-facing work
- A threshold alert is set for any date that would change the risk picture
Frequently asked questions
What is permanent establishment (PE) risk in remote work?
PE risk is the chance that a remote employee creates enough of a business presence in another country that local tax authorities treat your company as operating there, triggering corporate tax exposure, not just an individual tax question. It's most likely when a role involves negotiating or signing contracts, managing local clients, or otherwise acting on the company's behalf in that jurisdiction.
Do remote workers trigger tax residency after 183 days abroad?
183 days is a common treaty benchmark, but treating it as a universal safe harbor is a mistake. Some countries count the days differently, by tax year versus rolling 12 months, and other factors, like where the role's core activities happen, can create exposure before that threshold is ever reached.
Who should approve a cross-border remote work request?
No single person should carry that decision alone. A defensible process routes the request through a manager for business fit, HR for policy consistency, and a compliance or tax reviewer for the jurisdiction-specific risk assessment, with compliance holding the final say on anything that isn't clearly green.
Is a short remote work stint automatically low risk?
Not necessarily. Duration is one input, but immigration status, the nature of the role, and whether a social security agreement exists between the two countries can introduce risk in a matter of weeks, well before duration alone would raise a flag.
What's the difference between business travel risk and remote work risk?
Business travel tends to be short and task-specific, a conference or a client visit, and generally carries lower compliance risk. Remote work means sustained presence in a location, which is far more likely to shift tax residency, create social security obligations, or raise permanent establishment questions.
Screen every request before it's approved
Horizon by Topia runs tax, immigration, social security, and PE risk scoring on every cross-border remote work request, routed through a structured approval workflow and visualized on an interactive world map. Book a demo to see it run against your own locations.
Frequently Asked Questions
- What is permanent establishment (PE) risk in remote work?
- PE risk is the chance that a remote employee creates enough of a business presence in another country that local tax authorities treat your company as operating there, triggering corporate tax exposure, not just an individual tax question. It is most likely when a role involves negotiating or signing contracts, managing local clients, or otherwise acting on the company's behalf in that jurisdiction.
- Do remote workers trigger tax residency after 183 days abroad?
- 183 days is a common treaty benchmark, but treating it as a universal safe harbor is a mistake. Some countries count the days differently, by tax year versus rolling 12 months, and other factors, like where the role's core activities happen, can create exposure before that threshold is ever reached.
- Who should approve a cross-border remote work request?
- No single person should carry that decision alone. A defensible process routes the request through a manager for business fit, HR for policy consistency, and a compliance or tax reviewer for the jurisdiction-specific risk assessment, with compliance holding the final say on anything that is not clearly green.
- Is a short remote work stint automatically low risk?
- Not necessarily. Duration is one input, but immigration status, the nature of the role, and whether a social security agreement exists between the two countries can introduce risk in a matter of weeks, well before duration alone would raise a flag.
- What's the difference between business travel risk and remote work risk?
- Business travel tends to be short and task-specific, a conference or a client visit, and generally carries lower compliance risk. Remote work means sustained presence in a location, which is far more likely to shift tax residency, create social security obligations, or raise permanent establishment questions.




