Skip to main content
NexITC

FIELD NOTE · CYBERSECURITY

What an ADHICS v2 inspection actually asks for

Beyond the checklist-level control inspection, ADHICS v2 inspectors probe on specific dimensions — access management scrutiny, clinical data protection depth, third-party access controls, incident response readiness. Here's what the inspection actually covers and how to prepare.

Practice Lead — Cybersecurity1 September 20267 min read
  • compliance
  • adhics-v2
  • control-mapping

Healthcare entities in Abu Dhabi and across UAE subject to ADHICS (Abu Dhabi Healthcare Information and Cyber Security) v2 requirements are entering a familiar audit cycle: the inspection is scheduled, the compliance function assembles evidence packages, the security team surfaces gaps in the last two weeks before the audit date, and the audit itself produces findings that surface control implementation weaknesses rather than genuine breaches.

The pattern is common enough that it obscures a specific question: what does an ADHICS v2 inspection actually ask for, and how does the inspection cadence differ from the general "cybersecurity audit" pattern that produces the recurring surprise?

The inspection scope

ADHICS v2 inspection covers three primary evidence areas:

Governance evidence. Documented security policies, procedures, and standards mapped to specific ADHICS v2 control requirements. Evidence of board or senior management involvement in security governance. Risk assessment methodology and current risk register. Incident response plan with defined roles and escalation paths.

Technical control evidence. Implementation evidence per specific ADHICS v2 technical control — access management, network segmentation, endpoint security, cryptography, backup and recovery, logging and monitoring, vulnerability management, patch management. Evidence per control includes configuration screenshots, policy documents, operational logs, and — critically — evidence that the control operates as documented, not just that it exists.

Operational evidence. Evidence that security operations run on defined cadence — vulnerability scanning frequency, patch management SLAs, incident response drill records, user access review cadence, backup verification test results. The distinction matters: policies-and-procedures-plus-operational-evidence is inspection-defensible; policies-and-procedures-alone is not.

The specific questions inspectors typically ask

Beyond the checklist-level control inspection, ADHICS v2 inspectors typically probe on specific dimensions:

Access management scrutiny. How does user access management operate for clinical systems? Who reviews access privileges and on what cadence? What happens when a clinician moves between departments — is access adjusted, and how quickly? For privileged access (system administrators, database administrators, security operations), what additional controls apply?

Test question inspectors ask: request user access audit trail for a randomly selected clinical staff member over the past six months. The audit trail must show every access grant, modification, and revocation with timestamp and approval evidence.

Clinical data protection depth. How is clinical data protected at rest and in transit? What encryption standards apply? For patient identifiers specifically (Emirates ID linkages, medical record numbers), what additional controls apply? For cross-border data transfers (if any), what controls address ADHICS-specific requirements plus PDPL cross-border transfer controls?

Test question: trace a specific patient record from creation through storage, retrieval, transmission, and (if applicable) cross-border transfer. Evidence encryption at each stage, access controls applied, and audit trail comprehensiveness.

Third-party access controls. How is third-party access managed — vendors, contractors, consultants, medical device suppliers, laboratory partners? What contractual controls apply (Data Processing Agreements, security addendums, right-to-audit clauses)? What operational controls apply (network segmentation for vendor access, time-limited credentials, monitoring)?

Test question: request the full inventory of third parties with access to clinical systems, with the associated contractual controls, security assessments, and operational controls per third party.

Incident response operational readiness. When was the last incident response drill conducted? What was the scenario? What were the findings? What remediation actions were implemented? For actual incidents (if any), what was the detection-to-containment time, and how does it compare against ADHICS v2 target expectations?

Test question: walk through the last actual security incident from detection through resolution. Timeline, actions taken, communications, and post-incident review outcomes.

Backup and recovery verification. When was the last backup restoration test conducted? Did the restoration succeed? For clinical systems specifically (electronic health records, radiology imaging, laboratory information systems), how frequently are backups tested?

Test question: identify a specific critical clinical system, request evidence of the last successful backup restoration test, and describe the restoration procedure.

Where inspection findings typically surface

Two patterns account for the majority of ADHICS v2 inspection findings:

Control-exists-but-operates-inconsistently. The control is documented in policy, implemented in the tooling, but operational evidence shows inconsistent execution. Access reviews happen quarterly per policy but the last three quarters show gaps. Vulnerability scanning runs on schedule but critical findings from two quarters back remain unremediated. Backup tests are documented as monthly but actual test evidence covers only two of the past six months.

Third-party controls gap. The entity's own controls are strong, but third-party access — vendors, consultants, medical device suppliers — is either not comprehensively inventoried or lacks equivalent contractual and operational controls. Third-party gaps often surface late in the audit because the compliance function tracks internal controls but doesn't consistently maintain third-party inventory.

Rare but higher-severity findings:

Missing evidence for a required control. Control is documented as implemented, but no operational evidence supports the claim. This finding typically indicates either the control has drifted out of operation or was never fully implemented despite documentation.

Evidence tampering or inconsistency. Rare, but occurs when compliance function assembles evidence packages under time pressure and manufactures evidence to fill gaps. Inspectors are trained to detect this pattern — inconsistent timestamps, missing supporting evidence, evidence that doesn't align with system-generated logs.

The preparation cadence that actually works

Preparation for ADHICS v2 inspection is a 90-day sprint if the underlying security posture is reasonable, and a 6-month remediation programme if it isn't. The 90-day sprint pattern:

Days 1-30: Evidence assembly. Comprehensive inventory of controls implemented against ADHICS v2 requirements. Evidence gathering per control. Gap identification — controls documented but lacking operational evidence.

Days 31-60: Gap remediation. Highest-priority gaps addressed with rapid operational fixes (access reviews executed, vulnerability findings remediated, backup tests conducted). Lower-priority gaps documented with remediation timelines.

Days 61-90: Rehearsal and readiness verification. Mock inspection against the six primary test question categories. Evidence packages verified for completeness. Team briefings on inspector interaction protocols. Final gap closure.

The output is not "audit-ready" as a binary state — it is a defensible evidence position with acknowledged gaps and documented remediation timelines. Auditors respond to honesty about gaps in progress substantially better than to attempted concealment.

What this means for CISO preparation

Two shifts from the typical "audit sprint" pattern:

Continuous evidence generation beats audit-time evidence assembly. Entities that generate evidence continuously (monthly access reviews with automated logging, quarterly vulnerability posture reports with remediation tracking, weekly backup verification with test evidence) spend audit preparation on packaging rather than generating. The continuous-evidence model is substantially lower total operational cost than the audit-sprint model.

Third-party inventory maintenance is inspection-critical. The single most common inspection surprise is a third-party access relationship that wasn't in the compliance function's inventory. Maintaining a comprehensive third-party inventory with associated controls documentation is inspection-critical work that many entities under-invest in.

ADHICS v2 inspection is not adversarial — it is a compliance verification process with a defined scope and defined test methodology. Entities that understand the specific test questions can prepare specifically for them. Entities that treat the inspection as a general cybersecurity audit surface the same findings each cycle.

Adjacent engagement patterns

Where this shows up in the catalogue.

NexITC's A3 Compliance Fast-Track UAE engagement covers ADHICS v2 alignment. Related engagement patterns: B8 Controls Implementation Build for gap remediation execution, C6 ComplianceOps UAE for continuous evidence generation cadence, B9 Zero-Trust Core Build for access management and network segmentation depth.

Case study reference: B9 Zero-Trust Core Build™Healthcare illustrative composite →

Reading this to size up a specific decision? Talk to the practice.

Book a clinic. Practice Lead attends. Insights explain how the practice thinks; a clinic conversation explains what that means for your specific engagement.