Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
This page provides a working, domain-by-domain control checklist for ADHICS compliance, covering the five domains confirmed directly against the current published standard: Human Resources Security, Asset Management, Physical and Environmental Security, Access Control, and Communications and Operations Management. Use it to self-assess before commissioning a formal gap assessment. It summarises the standard rather than replacing it, and the published standard itself remains the authoritative source.
Working through the checklist domain by domain, rather than control by control, tends to produce a more usable picture of where an entity actually stands.
This checklist is not exhaustive. It summarises the confirmed control requirements across five domains rather than replicating the full standard, and it does not replace the judgement of a qualified compliance professional or the authority of the published standard itself.
"Implemented but not evidenced" is the rating that causes most audit findings in practice. A password policy that genuinely exists and is genuinely enforced still fails an audit if nobody can produce the record showing when it was last reviewed or who approved it. Treating evidence as part of the control, not an afterthought once the control exists, is the single habit that prevents the most audit friction later. Our business security audits guide covers this evidence-gathering discipline in more general terms, beyond ADHICS specifically.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| HR security policy | A documented policy covering recruitment, employment, and termination security requirements | Signed, version-controlled policy document | |
| Background verification | Background checks for all employees, contractors, and third-party users before access is granted | Verification records for every in-scope individual | |
| Terms of employment | Contracts including security responsibilities, NDA, and disciplinary terms | Signed contracts and NDAs on file | |
| Security awareness training | Onboarding and periodic awareness training for all staff | Training completion records and attendance logs | |
| Role-based training | Training specific to elevated-risk roles before system access is granted | Role-specific training records tied to access grants | |
| Disciplinary process | A defined process for security breaches by staff | Documented disciplinary actions where breaches occurred | |
| Exit and access revocation | Access removed within 24 hours of termination, assets recovered | Exit clearance forms and access revocation logs |
The most common gap in this domain is not the policy itself but the exit process: many entities can show a hiring checklist but cannot produce evidence that access was actually revoked within the required 24-hour window for every departure in the past year.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Asset management policy | A documented policy covering ownership, classification, and retention | Signed policy referencing the standard's classification scheme | |
| Asset inventory | A complete, current inventory of all information assets, including medical devices | An up-to-date, centrally accessible inventory | |
| Asset ownership | A named owner assigned to every identified asset | Ownership records mapped to the inventory | |
| Classification and labelling | Every asset classified per the standard's four-tier scheme (Public, Restricted, Confidential, Secret) | Classification records aligned to the inventory | |
| BYOD controls | An authorisation process for personal devices accessing entity data | BYOD usage agreements signed by users | |
| Secure disposal | Controls ensuring disposed assets cannot be recovered | Disposal records naming owner, method, and authorisation |
Medical device inventory is where this domain most often falls short in practice. General IT asset inventories tend to be reasonably mature; a linked inventory that also covers medical devices and equipment, redacted of patient information, is far less commonly in place.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Physical security policy | A documented policy addressing secure storage and physical protection | Signed policy covering internal and external threats | |
| Secure area access | Defined security perimeters with authorised-only access | Access logs and authorised personnel lists | |
| Visitor and CCTV controls | Visitor logs and CCTV coverage at vantage points in secure areas | Retained CCTV footage and visitor logs | |
| Equipment siting and protection | Medical devices and equipment positioned and protected appropriately | Documented equipment placement guidelines | |
| Environmental controls | Fire suppression, detection, and temperature/humidity monitoring for data centres | Maintenance and testing records for environmental systems | |
| Off-site equipment protection | Authorisation and chain-of-custody controls for equipment taken off-site | Movement and possession logs |
Access records and CCTV footage retention are the two evidence types most often missing here, even where the physical controls themselves, locks, badges, cameras, are genuinely in place.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Access control policy | A documented policy covering granting, review, and revocation of access | Signed policy addressing role-based access principles | |
| Password complexity | Minimum 12 characters, mixed case, number, and special character; 5-attempt lockout; 3-password history | Technical configuration evidence from system settings | |
| User access management | Formal registration and de-registration process with unique accounts per user | User account creation and deactivation records | |
| Privileged access controls | Multi-factor authentication for privileged, administrative, and remote access | MFA configuration evidence and privileged account inventory | |
| Access reviews | Access and privileges reviewed at least annually | Annual access review records | |
| Network access control | Controlled, authenticated access to network services and remote channels | Network access logs and authentication configuration | |
| Wireless security | Internal wireless not broadcast, trusted-device-only access | Wireless configuration and authorisation records |
Annual access review is the control most often found "implemented but not evidenced": the review happens informally, but no dated record exists showing who was reviewed, by whom, and when.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Change management | A Change Advisory Board and documented change approval process | Change records with approval, testing, and rollback evidence | |
| Malware protection | Anti-malware deployed and current across servers, workstations, and mobile devices | Deployment coverage reports and update logs | |
| Backup and restoration | Regular backups with periodically tested restoration | Backup logs and documented restoration test results | |
| Logging and monitoring | Centralised, protected logging with defined alerting and escalation criteria | Log retention records and alert response evidence | |
| Annual VAPT | Yearly vulnerability assessment and penetration testing of systems, web/mobile applications, and connected medical devices | Testing reports, remediation tracking, and revalidation results | |
| Patch management | Formal, prioritised patching with critical patches applied promptly | Patch deployment and validation records | |
| Data leakage prevention | DLP controls to prevent unauthorised loss of health information | DLP deployment and incident records | |
| Information exchange controls | Secure exchange procedures, with health information not leaving the UAE without DoH exemption | Data flow documentation and cross-border exemption records, where applicable |
The annual VAPT requirement is worth flagging on its own: it is stated directly and unambiguously in the standard, yet it is one of the controls most commonly found missing entirely rather than simply under-evidenced, since organisations without an established testing programme often have not commissioned any structured penetration test at all. Our enterprise penetration testing guide and vulnerability assessment service cover how to scope this specific obligation.
Sequencing remediation against these patterns, rather than working alphabetically through the checklist, tends to close the highest-risk gaps first.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cyber Compliance | 15/09/2026
Cyber Compliance | 15/09/2026
Cyber Compliance | 21/08/2026
How many controls does ADHICS contain?
692 controls across 11 domains, per the Department of Health's own published guidance.Do all ADHICS controls apply to every health entity?
No. Applicability depends on entity type and, for hospitals, bed capacity, across four control categories.What evidence do ADHICS auditors ask for?
Dated, verifiable records: policies, logs, training completions, and test results tied to each control.What is an ADHICS gap assessment?
An independent review identifying where current practice falls short of the standard. See our enterprise cyber risk management service.How often should we review ADHICS controls?
At least annually for access reviews and VAPT specifically; more often where the risk environment changes.What is the difference between ADHICS V1 and V2?
V2 consolidated three earlier standards into one framework. See our ADHICS compliance guide.Can we self-assess ADHICS compliance?
Yes, as a starting point. See our vulnerability assessment service for the technical testing that a self-assessment cannot replace.