All resources

ADHICS Training Requirements for UAE Healthcare Providers: What Auditors Ask For

Published: 2026-07-17

When an ADHICS audit reaches the security awareness domain, the conversation quickly turns to documents: can you show who was trained, that they were tested, and that training is renewed on schedule? This article walks through the specific evidence auditors ask UAE healthcare providers for, and how to prepare it.

The training mandate in brief

ADHICS domain SA-1 requires every licensed healthcare organization in Abu Dhabi to deliver security awareness training to all staff and to keep verifiable records. The mandate covers clinical and administrative staff alike — anyone with access to health information systems.

Evidence item 1: the training attendance report (SA-1.2)

This is the first document most auditors request. It must list each employee, their department and job title, the course they attended, and their completion date and status. Gaps here — employees with no training record, or records without dates — are among the most common SA-1 findings.

Evidence item 2: assessment scores (SA-1.3)

Attendance alone does not satisfy ADHICS. Auditors want proof that staff knowledge was assessed: a report of assessment scores per attendee, the passing threshold applied, and pass/fail outcomes. If your training has no assessment component, this control cannot be evidenced.

Evidence item 3: the renewal schedule (SA-1.4)

Because ADHICS requires annual renewal of security awareness training, auditors ask how you track expiry. A certificate expiry schedule — listing each employee's certificate date and when re-training is due — demonstrates that renewal is managed proactively rather than reactively.

Presenting evidence during the audit

Auditors expect evidence in a reviewable format: dated PDF reports, consistent employee identifiers, and certificates that can be independently verified. Some audits also ask to see the actual training experience; a controlled, time-limited auditor preview of the course content can answer that without exposing learner data.

Preparing with Cisoshare Training

Cisoshare Training generates each of these documents automatically: the Training Attendance Report (SA-1.2), the Assessment Scores Report (SA-1.3), and the Certificate Expiry Schedule (SA-1.4) are downloadable as audit-ready PDFs, and every certificate carries a publicly verifiable number. Auditor preview sessions provide a scoped, watermarked view of the course itself when requested.

Generate ADHICS SA-1 evidence reports automatically — enroll your organization today.