You are here:

ADHICS vs ISO 27001 – Key Differences

A red stethoscope resting on a silver laptop keyboard, symbolizing the intersection of healthcare, digital security, and IT compliance auditing in Abu Dhabi.

A healthcare provider in Abu Dhabi holds a current ISO 27001 certificate. The ISMS is documented, internal audits are up to date, the Statement of Applicability is signed off. Then the Department of Health audit arrives, and the findings report runs longer than anyone on the team expected.

This is not a rare outcome. And in our experience it is almost never caused by missing documentation.

The assumption behind it is understandable. Map ADHICS controls against ISO 27001 and the overlap looks substantial both protect confidentiality, integrity and availability, both demand governance, both expect risk assessment and continual improvement. It is easy to conclude that an ISO 27001 certificate carries you most of the way to ADHICS compliance.

It does not, and the reason has less to do with scope than with how each standard is assessed. ISO 27001 certifies that you operate a functioning management system. ADHICS examines whether your operations actually did what your documents said they would — across two separate audits, scored against a floor in every domain rather than an average across all of them.

This blog covers three things: how the two standards differ in scope, how their audits differ in practice, and how their scoring logic differs in a way that changes where you should spend remediation effort.

What is ADHICS?

The Abu Dhabi Healthcare Information and Cyber Security Standard is the mandatory information security regulation for the Emirate’s healthcare sector. The current version, ADHICS V2, was issued by the Department of Health – Abu Dhabi, published in May 2024 and effective from August 2024. It supersedes the original 2019 standard (V0.9) along with the 2020 Internet of Medical Things and Patient Healthcare Data Privacy standards.

It applies to healthcare service providers, payers and insurers, laboratories, pharmacies, and technology vendors serving the sector. Structurally it comprises 11 security domains, 131 controls and 577 sub-controls, with controls classified as either Always Applicable or Risk-Based.

Applicability is tiered by entity type and risk profile — Basic, Transitional, Advanced, and Service Provider so a diagnostic centre and a 200-bed hospital are not held to an identical control set. That tiering matters later, because it determines what your audit is actually scored against.

What is ISO 27001?

ISO 27001 is the international standard for information security management systems. The current edition, ISO/IEC 27001:2022, was published in October 2022 and replaced the 2013 version.

Clauses 4 to 10 carry the mandatory management system requirements — context, leadership, planning, support, operation, performance evaluation and improvement. Annex A provides a reference set of 93 controls across four themes: organizational, people, physical and technological.

The critical mechanism is the Statement of Applicability. Organizations select controls based on their own risk assessment and document the justification for including or excluding each one. Annex A is a reference list to be considered, not a mandate to be implemented in full. This flexibility is ISO 27001’s central design principle — and it is the single feature that does not transfer to ADHICS.

ADHICS vs ISO 27001: Quick Comparison

AspectADHICSISO 27001
NatureRegulatory standardInternational certification standard
ApplicabilityHealthcare sector in Abu DhabiAll industries globally
ApproachMandated controls with tiered applicability; risk-based selection permitted only within defined limitsRisk-based; the organization determines its own control baseline
ComplianceMandatoryVoluntary
Audit TypeDoH process audit and technological auditStage 1 and Stage 2 audit by an accredited certification body
ScoringOverall threshold plus a minimum score in every domainConformity judgment; findings raised as major or minor non-conformities
FocusPatient data protection and healthcare service continuityBroad information security management
PenaltiesRegulatory consequences for non-complianceNo direct penalties; loss of certification
DocumentationPrescribed, healthcare-specificISMS documentation, scoped by the organization
Risk ManagementInforms control selection within a mandated floorDetermines the control baseline itself

Key Differences Between ADHICS and ISO 27001

1. Purpose and compliance obligation

ADHICS exists to establish a mandatory security baseline for healthcare entities operating under DoH regulation. Its objectives are sector-specific: protecting electronic medical records, securing clinical systems, sustaining patient care during disruption, and maintaining trust in national infrastructure such as the Malaffi health information exchange.

Compliance is not elective. If you fall within DoH’s regulatory perimeter, ADHICS applies.

ISO 27001 is a general-purpose management system standard. ISO 27001 certification is voluntary, pursued for commercial reasons — customer assurance, contractual obligations, governance maturity, market access.

This is the practical consequence: for an Abu Dhabi healthcare entity, there is no framework selection decision. There is a mandatory baseline and an optional layer above it.

2. Sector and geography

ADHICS is written for one sector in one Emirate, and it shows in the content — medical device security, clinical system availability, patient data confidentiality, health information exchange participation. It is harmonized with UAE federal law, including Law No. (2) of 2019 on ICT in healthcare and Law No. (45) of 2021 on data privacy.

ISO 27001 is sector-agnostic and geographically portable, adopted across finance, manufacturing, technology, government and healthcare alike. For organizations serving international partners or operating across multiple jurisdictions, that portability is the point.

3. How risk drives control selection

This is where the two standards are most often mischaracterized, including in comparisons that describe ADHICS as purely prescriptive.

ADHICS does incorporate risk management, and Section A sets out a risk management framework. Controls are explicitly split between Always Applicable and Risk-Based, and applicability tiers adjust the requirement set to entity profile.

The difference is what risk assessment is permitted to decide. Under ISO 27001, risk assessment determines your control baseline — you can justify excluding an Annex A control entirely, provided the reasoning is documented and accepted. Under ADHICS, risk assessment operates above a mandated floor. Always Applicable controls are not available for exclusion regardless of your risk appetite.

An ISO 27001 practitioner accustomed to scoping decisions being defensible needs to recalibrate here. In ADHICS, some decisions are not yours to make.

4. What ADHICS requires that ISO 27001 does not

Several ADHICS requirements have no equivalent anywhere in ISO 27001. These are where mapping exercises consistently overstate readiness.

Data localization. Protected Health Information and PII must not be stored, processed or transferred outside the UAE without an explicit exemption issued by DoH. ISO 27001 has no comparable constraint — a certified ISMS can run on offshore infrastructure without issue.

Residency-based access restriction. Access to systems holding sensitive health data is restricted to individuals physically present in the UAE, or those holding a valid DoH professional licence. This is the requirement with the sharpest operational consequence: offshore managed service, remote administration and follow-the-sun support models that satisfy ISO 27001 comfortably may not survive an ADHICS assessment in their current form.

Prescribed governance structure. ADHICS mandates a three-tier structure an Information Security Governance Committee for executive oversight, a HIIP Workgroup for tactical planning, and named Implementation Stakeholders for operational delivery. ISO 27001 requires demonstrated leadership commitment; ADHICS specifies the committees.

Prescribed classification scheme. A defined colour-coded scheme applies — Red (Secret), Orange (Confidential), Blue (Restricted), Green (Public). ISO 27001 requires that you classify information; ADHICS tells you what the labels are.

How the two audits actually differ?

The scope differences above are visible on paper. The assessment differences are where organizations are caught out, and they are rarely written about.

ISO 27001 certification follows a two-stage sequence with an accredited certification body: Stage 1 reviews documentation and readiness, Stage 2 tests implementation and effectiveness. Findings are raised as major or minor non-conformities and closed through corrective action.

ADHICS assessment by DoH also runs in two parts, but they are two different lenses rather than two stages of one review: a process audit and a technological audit.

In the DoH process audits we have supported, the domains where organizations most consistently score poorly or fail outright are Access Control and Communications and Operations Management. Not the exotic domains — the two that touch daily operations most heavily.

In technological audits, findings cluster around a recognizable set: critical patches not applied, high-risk misconfigurations, and inadequate compensating controls around legacy systems that cannot be patched or replaced without disrupting clinical service.

ADHICS assessment
ADHICS assessment

Read together, these point to a single root cause. In most cases the policies and procedures exist and are adequate. What fails is adherence — operations drifting from the documented process, patch cycles slipping, configuration standards not enforced, exceptions granted informally and never revisited. Which is why the same non-conformities reappear audit after audit at the same organizations.

This is the substantive reason an ISO 27001 certificate does not predict an ADHICS outcome. A certification audit samples for evidence that your management system functions. A DoH technological audit inspects your estate.

Why ADHICS scoring is unforgiving?

The scoring model differs in a way that should change how you prioritize remediation.

ISO 27001 conformity is a judgment on the management system as a whole. Weakness in one area surfaces as a non-conformity, is corrected, and certification proceeds. There is no numerical pass mark.

ADHICS is scored, and the threshold is a dual gate: an organization must achieve 86% or above overall, and at least 70% in every individual domain. Category weighting across Basic, Transitional and Advanced controls applies on top of that.

The consequence is straightforward but frequently missed. You cannot average your way to ADHICS compliance. An organization scoring 92% overall with one domain sitting at 64% has failed, and its headline number gives no warning. Strength across ten domains does not rescue the eleventh.

For remediation planning this inverts the usual instinct. The efficient move under most frameworks is to lift broad, shallow weaknesses — it moves the aggregate number fastest. Under ADHICS the aggregate is the easier gate to clear. Effort belongs on your weakest domain first, depth before breadth, until every domain clears the floor.

Combined with the audit findings above, that has a clear implication for where to look: Access Control and Communications and Operations Management are both the domains that carry the heaviest operational load and the ones where entities most often sit closest to the floor.

Where the frameworks converge?

The overlap is real. Both standards are built on confidentiality, integrity and availability. Both require documented policy, governance ownership, risk assessment, incident response, business continuity, awareness training and continual improvement. An organization with a mature ISO 27001 implementation has genuinely useful groundwork in place.

That overlap is exactly why mapping exercises are seductive and why they mislead. High control-level correspondence produces a readiness percentage that feels reassuring, while the requirements with no ISO analogue — residency, localization, mandated governance bodies, prescribed classification — sit outside the mapping entirely, and the adherence gaps that drive audit findings do not appear in a mapping at all.

Which should come first?

If you are a healthcare service provider operating in the Abu Dhabi market, ADHICS is your de facto baseline. Build to it first.

The reasoning is practical. It is mandatory, the DoH audit is coming regardless of what else you hold, and its control set is the more prescriptive of the two. Once ADHICS is in place, mapping upward to ISO 27001 is comparatively straightforward — you are taking a defined control set and wrapping a management system around it, and much of the evidence base already exists.

The reverse order creates avoidable rework. You scope an ISMS to your own risk appetite, document your exclusions, certify, and then discover that ADHICS does not accept those exclusions and that several requirements were never in your scope to begin with. The residency and localization requirements are the expensive examples — architectural decisions that are cheap to make correctly at the start and costly to unwind afterwards.

There is a legitimate counterargument worth stating plainly: Annex A is a reference set, so why not scope the ISMS to cover ADHICS from the outset? You can, and if you are certifying anyway it is the sensible approach. But it does not change the order of operations. The ADHICS requirement set still defines the floor. You are letting the regulation determine your scope either way — better to acknowledge that at the design stage than to discover it at Stage 2.

On timelines, our own delivery experience is roughly six months for an ISO 27001 implementation starting from scratch, and three to four months where the organization already has an established security programme and evidence is readily available. Scope, organizational size and existing control maturity move that figure more than anything else.

Conclusion

ADHICS and ISO 27001 are not competing frameworks and the choice between them is largely illusory for Abu Dhabi healthcare entities. One is a regulatory obligation with a defined scope, a two-part audit and a numerical pass mark. The other is a voluntary management system standard that demonstrates governance maturity to a global audience. They answer different questions and both are worth holding.

What is worth abandoning is the assumption that one substantially delivers the other. ADHICS compliance is not ISO 27001 with healthcare vocabulary. It carries requirements ISO does not contain, it is assessed through an infrastructure-level technological audit rather than a management-system sample, and it is scored against a floor in every domain rather than an average.

The organizations that pass are not the ones with the best documentation. They are the ones whose daily operations match it.

If you want a useful indication of where you stand before DoH provides one, start with a narrow test: take your Access Control and Communications and Operations Management procedures, and check whether current practice matches what is written — privileged access reviews actually performed on schedule, patch cycles meeting their defined windows, configuration baselines enforced rather than documented, exceptions formally approved and time-bound. That comparison, done honestly, predicts your audit outcome better than any control mapping will.

If the gap is wider than you expected, ValueMentor’s team supports healthcare entities through DoH process and technological audits, and through ADHICS-to-ISO 27001 mapping where certification is also a requirement. We are happy to look at where you stand.

FAQs

1. Is ADHICS the same as ISO 27001?

No. ADHICS V2 is a mandatory healthcare-specific regulation issued by the Department of Health – Abu Dhabi, comprising 11 domains and 131 controls. ISO/IEC 27001:2022 is a voluntary international management system standard with 93 Annex A reference controls. The overlap is real but partial, and their audit and scoring models are entirely different.


2. Is ADHICS compliance mandatory?

Yes, for healthcare entities operating under DoH regulation in Abu Dhabi. This includes providers, payers, laboratories, pharmacies and service providers to the sector, with requirements tiered by entity type across Basic, Transitional, Advanced and Service Provider categories.


3. Who should get ISO 27001 certified?

Any organization seeking to demonstrate information security maturity to customers, partners or regulators. For Abu Dhabi healthcare entities it is typically pursued alongside ADHICS rather than instead of it, most often driven by international partners or group-level requirements.


4. Can a healthcare organization implement both ADHICS and ISO 27001?

Yes, and many do. The recommended sequence is ADHICS first as the mandatory baseline, then mapping upward to ISO 27001, since building to the more prescriptive standard first avoids rework on scope and architecture.


5. Does ISO 27001 focus only on cybersecurity?

No. It covers information security management as a whole — people, process and technology — including governance, risk management, supplier relationships, physical security and business continuity.


6. Which standard is recognized internationally?

ISO 27001 is recognized globally across all industries. ADHICS is a regional regulation specific to the Abu Dhabi healthcare sector and is not intended for use outside that context.


7. Does ADHICS include risk management requirements?

Yes. ADHICS V2 sets out a risk management framework and classifies controls as Always Applicable or Risk-Based. The distinction from ISO 27001 is that risk assessment operates above a mandated floor — Always Applicable controls cannot be excluded on the basis of risk appetite, unlike Annex A controls under a Statement of Applicability.


8. How long does ISO 27001 certification take?

Based on our delivery experience, roughly six months for an organization starting from scratch, and three to four months where an established security programme is already in place and evidence is readily available. Scope, organizational size and existing control maturity are the main variables.


9. Does ISO 27001 help with regulatory compliance?

It provides useful groundwork — governance structures, risk processes, documentation discipline and evidence practices all transfer. It does not satisfy ADHICS on its own, particularly for requirements such as data localization, residency-based access restriction, the mandated governance structure and the prescribed classification scheme, none of which have ISO 27001 equivalents.


10. Which is better: ADHICS or ISO 27001?

The question does not apply cleanly. If you operate in Abu Dhabi healthcare, ADHICS is an obligation rather than an option, and ISO 27001 is a commercial decision layered on top of it. Outside that sector and jurisdiction, ISO 27001 is the relevant standard.

Author

Ronald Mathew

Ronald Mathew is a cybersecurity governance and risk professional specializing in security strategy, program management, and security operations oversight. His work focuses on building sustainable security capabilities, strengthening organizational resilience, and enabling informed decision‑making at the leadership level. Ronald reviews and validates security content through a strategic and risk‑based lens shaped by enterprise‑scale experience.

Table of Contents

Protect Your Business from Cyber Threats Today!

Safeguard your business with tailored cybersecurity solutions. Contact us now for a free consultation and ensure a secure digital future!

Ready to Secure Your Future?

We partner with ambitious leaders who shape the future, not just react to it. Let’s achieve extraordinary outcomes together.

I want to talk to your experts in:

Related Blogs

3D countdown display showing 90 days for ADHICS audit preparation and DoH Abu Dhabi compliance.
Small healthcare startup evaluating HITRUST certification costs through a digital healthcare compliance dashboard