ADHICS compliance
ADHICS Compliance in the UAE: A Practical Readiness Guide
A practical way for healthcare organisations to turn ADHICS requirements into accountable work, evidence, and a defensible readiness plan.

Start with a readiness decision, not a document collection exercise
ADHICS readiness becomes difficult when it is treated as a last-minute hunt for policies. A stronger starting point is to agree what the organisation is trying to demonstrate: that security and privacy responsibilities are owned, controls operate in the real environment, and evidence can be traced to the people and systems that produce it.
For a healthcare organisation, this means bringing clinical, IT, information security, privacy, facilities, HR, procurement, and leadership into one operating view. The Department of Health resources should remain the primary reference for the current standard, implementation guidance, forms, and templates.
Build the baseline across five workstreams
A useful readiness assessment separates the work into manageable workstreams. Each workstream needs a named accountable owner, a short list of decisions, and a date for checking whether the evidence still reflects the live service.
Governance: confirm executive sponsorship, committee cadence, responsibility assignments, and escalation routes.
Risk and assets: connect important services, information assets, suppliers, medical technology, threats, treatments, and review dates.
Policies and people: map policies to operational procedures, training, access changes, and disciplinary or exception processes.
Technology and operations: establish what is actually configured, monitored, backed up, tested, and reviewed.
Evidence and assurance: define the artefact, owner, period covered, reviewer, and conclusion for each control area.
Make evidence easy to test
An audit-ready evidence pack is not a folder containing every possible document. It is a controlled record that answers a reviewer’s questions quickly: which requirement is being supported, who owns it, what period it covers, where the source record is held, and whether a reviewer has assessed it.
Teams often improve speed by maintaining a live control-to-evidence register. Where a technical record is generated automatically, retain the source or approved export rather than manually retyping a conclusion. Where a process is performed by people, combine the procedure with recent records that show it was followed.
Use a 30, 60, and 90-day plan
In the first 30 days, establish scope, leadership ownership, critical systems, priority risks, and the status of core policies. In the next 30 days, close the evidence gaps that affect high-risk services, access, suppliers, incident readiness, and data handling. By 90 days, management should be reviewing a stable dashboard of open gaps, exceptions, treatment owners, and evidence freshness.
The goal is not to claim that a programme is complete. It is to make the organisation’s actual risk decisions, remediation commitments, and assurance activity visible enough to manage.
Questions to ask before calling the programme ready
Before treating a readiness exercise as complete, ask whether the evidence represents the current environment, whether ownership survives staff changes, and whether critical suppliers and connected systems are included. Also ask whether leadership can see accepted risks and overdue actions without assembling a new spreadsheet for every meeting.
FAQ
What is an ADHICS readiness check?
It is a structured review of scope, ownership, controls, evidence, risks, and open actions against the applicable current DoH material.
Who should own ADHICS compliance?
Executive accountability should be explicit, while operational ownership is shared across the functions that run clinical, technology, security, privacy, and supplier processes.
What makes evidence audit-ready?
It is current, traceable to a requirement and owner, covers the relevant period, and can be reviewed without relying on unsupported narrative.
Sources and further reading
- AAMEN programme and ADHICS V2 resources — Department of Health - Abu Dhabi
- Abu Dhabi Healthcare Information and Cyber Security Standard V2 — Department of Health - Abu Dhabi
- Department of Health standards library — Department of Health - Abu Dhabi
- UAE data protection laws — UAE Government
Related news
Turn guidance into a managed compliance programme with GRSCIA.