Skip to content

Evidence request lists

WHO Global Strategy on Digital Health 2020-2025

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Implementation Enablers

WHO-DH-IMP.1
Risk management for digital health programmes

Each major digital health programme should maintain a risk register covering technical, clinical safety, privacy, sustainability, and political risks, with documented mitigations and ownership.

Artefacts an auditor will ask for
  • Programme-level risk registers
  • Risk treatment plans
  • Quarterly risk review minutes
  • Clinical safety case for clinical decision support tools
Where this commonly fails
  • Risks captured only at project start
  • Clinical safety treated as IT issue
  • No escalation path to governance body
WHO-DH-IMP.2
Sustainability and total cost of ownership

Digital health programmes should demonstrate financial and operational sustainability beyond initial donor or pilot funding, with total cost of ownership models covering at least five years.

Artefacts an auditor will ask for
  • Five-year total cost of ownership model
  • Transition plan from donor to government funding
  • Operations and maintenance contracts
  • Service level agreements with vendors
Where this commonly fails
  • Pilots end at funding cliff without transition
  • Operations costs underestimated
  • No service level agreement for production systems
WHO-DH-IMP.3
Procurement aligned to open standards

Public procurement for digital health products and services should require open standards, interoperability conformance, and clear exit provisions to avoid vendor lock-in.

Artefacts an auditor will ask for
  • Standard procurement clauses mandating open standards
  • Conformance testing requirements in tender documents
  • Exit and data portability clauses in contracts
  • Vendor risk assessments
Where this commonly fails
  • Procurement template references standards without conformance test
  • No exit clause for source code and data
  • Sole-source awards without market test
WHO-DH-IMP.4
Health data quality and integrity

Data captured through digital health systems should be subject to defined data quality standards, with routine audit, validation, and feedback loops to source facilities.

Artefacts an auditor will ask for
  • Data quality framework
  • Routine data quality audit reports
  • Feedback reports to facilities and providers
  • Data dictionary aligned to national standards
Where this commonly fails
  • Data dashboards published without quality validation
  • No feedback loop to data submitters
  • Data dictionary missing or out of date
WHO-DH-IMP.5
Pandemic and emergency preparedness use of digital tools

National digital health infrastructure should be designed to support surveillance, contact tracing, vaccination records, and supply chain visibility during health emergencies, with scenario tests.

Artefacts an auditor will ask for
  • Emergency preparedness annex to digital health strategy
  • Stress test reports for surveillance and reporting systems
  • Continuity of operations plan
  • After-action reviews from past emergency activations
Where this commonly fails
  • Emergency systems separate from routine systems
  • No stress test under load
  • After-action lessons not implemented

Monitoring and Evaluation

WHO-DH-MON.1
Monitoring and evaluation of digital health strategy

A monitoring and evaluation framework with baseline indicators, targets, and reporting cadence should be established for the national digital health strategy, with results published.

Artefacts an auditor will ask for
  • M&E framework with indicators and targets
  • Baseline assessment report
  • Annual progress reports against indicators
  • Published dashboard or open data feed
Where this commonly fails
  • Indicators defined but no data source
  • No baseline established
  • Results not published or shared with stakeholders
WHO-DH-MON.2
Digital Health Atlas registration of investments

Member States should register significant digital health investments in the WHO Digital Health Atlas to support coordination, prevent duplication, and contribute to global learning.

Artefacts an auditor will ask for
  • Digital Health Atlas registrations for active programmes
  • Annual review of Atlas entries for currency
  • Cross-reference register linking Atlas entries to national strategy
Where this commonly fails
  • Programmes not registered at all
  • Atlas entries stale
  • No internal owner for Atlas curation

SO1

WHODIGH-1
Strategic Objective 1: Promote Global Collaboration

Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 1: Promote Global Collaboration. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WHODIGH-1
Where this commonly fails
  • see authoritative source for detailed gap analysis

SO2

WHODIGH-2
Strategic Objective 2: Advance Country Implementation

Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 2: Advance Country Implementation. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WHODIGH-2
Where this commonly fails
  • see authoritative source for detailed gap analysis

SO3

WHODIGH-3
Strategic Objective 3: Strengthen Governance

Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 3: Strengthen Governance. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WHODIGH-3
Where this commonly fails
  • see authoritative source for detailed gap analysis

SO4

WHODIGH-4
Strategic Objective 4: Person-Centred Digital Health

Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 4: Person-Centred Digital Health. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WHODIGH-4
Where this commonly fails
  • see authoritative source for detailed gap analysis

Strategic Objective 1: Global Collaboration

WHO-DH-SO1.1
Strategic Objective 1: Promote global collaboration and advance the transfer of knowledge on digital health

Member States and partners should actively participate in global digital health knowledge exchange, contribute to open repositories, and support cross-border learning on digital health interventions, standards, and lessons learned.

Artefacts an auditor will ask for
  • Participation log for WHO digital health forums and working groups
  • Contributions to WHO digital health knowledge repository
  • Country case study submissions
  • MoUs with peer Ministries of Health on digital health cooperation
Where this commonly fails
  • Engagement limited to attendance without substantive knowledge contribution
  • No formal mechanism to translate WHO guidance into national practice
  • Case studies not maintained or refreshed annually

Strategic Objective 1: Promote Global Collaboration

SO1.1
Share digital health knowledge

Member States share knowledge and investments in digital health to align strategies across countries.

Artefacts an auditor will ask for
  • Knowledge platform
  • Community of practice
  • Sharing log
Where this commonly fails
  • No platform
  • Inactive CoP
  • Siloed knowledge
SO1.2
Support digital health networks

Promote networks and partnerships for digital health innovation and knowledge exchange.

Artefacts an auditor will ask for
  • Network membership
  • Network governance
  • Activity reports
Where this commonly fails
  • No network membership
  • Passive participation
  • No outputs
SO1.3
Global digital health repository

Establish a repository of digital health implementations, evidence, and best practices.

Artefacts an auditor will ask for
  • Repository design
  • Submission SOP
  • Curation process
Where this commonly fails
  • No repository
  • Submission unclear
  • No curation
SO1.4
Digital health capacity building

Build capacity in low- and middle-income countries for adopting digital health technologies.

Artefacts an auditor will ask for
  • Capacity plan
  • Training curriculum
  • Certification records
Where this commonly fails
  • No capacity plan
  • Limited training
  • No certification

Strategic Objective 2: Advance Country Digital Health Implementation

SO2.1
National digital health strategy adoption

Every country should adopt, review, and strengthen its national digital health strategy.

Artefacts an auditor will ask for
  • National strategy document
  • Roadmap
  • Governance structure
Where this commonly fails
  • No strategy
  • Strategy unimplemented
  • No governance
SO2.2
Digital health architecture blueprint

Define a national digital health architecture blueprint or roadmap for implementation.

Artefacts an auditor will ask for
  • Reference architecture
  • Blueprint
  • Implementation guide
Where this commonly fails
  • No blueprint
  • Architecture fragmented
  • Stale guide
SO2.3
Open-source health data standards

Adopt open-source health data standards and interoperability frameworks.

Artefacts an auditor will ask for
  • Standards register
  • Open-source toolkit
  • Conformance tests
Where this commonly fails
  • No standards adoption
  • Proprietary lock-in
  • No conformance
SO2.4
Investment in digital health infrastructure

Mobilise resources and investment for sustainable digital health infrastructure.

Artefacts an auditor will ask for
  • Infrastructure plan
  • Connectivity assessment
  • Investment case
Where this commonly fails
  • No investment case
  • Connectivity gaps
  • No power resilience
SO2.5
Health information systems strengthening

Strengthen health information systems as part of national digital health strategies.

Artefacts an auditor will ask for
  • HIS strategy
  • Indicator framework
  • Data quality assessment
Where this commonly fails
  • Fragmented HIS
  • Poor data quality
  • No interoperability

Strategic Objective 2: Country Implementation

WHO-DH-SO2.1
Strategic Objective 2: Advance the implementation of national digital health strategies

Each Member State should establish, publish, and operationalise a national digital health strategy that is aligned with WHO guidance, includes a costed implementation roadmap, and is reviewed on a defined cadence.

Artefacts an auditor will ask for
  • Approved National Digital Health Strategy document
  • Costed implementation roadmap with milestones
  • Annual progress report against strategy KPIs
  • Ministry-level governance committee minutes
  • Alignment matrix mapping national strategy to WHO four strategic objectives
Where this commonly fails
  • Strategy published but not costed or resourced
  • No defined review cycle or owner
  • Alignment with WHO objectives not documented
  • Strategy stale beyond stated review date
WHO-DH-SO2.2
Stakeholder engagement and multi-sector coordination

The national digital health strategy should be developed and reviewed with structured input from public sector entities, civil society, patient representatives, private sector providers, academia, and frontline health workers.

Artefacts an auditor will ask for
  • Stakeholder mapping and engagement plan
  • Consultation workshop reports
  • Public comment register with dispositions
  • Patient and civil society representation roster
Where this commonly fails
  • Engagement limited to government departments
  • No patient or civil society voice on the steering committee
  • Consultation outputs not reflected in final strategy
WHO-DH-SO2.3
Costed action plan and financing

Implementation of the national strategy should be supported by a costed action plan covering capital and recurrent expenditure, with identified financing sources across multiple budget cycles.

Artefacts an auditor will ask for
  • Multi-year costed action plan
  • Budget approval letters from Ministry of Finance
  • Donor and partner financing matrix
  • Total cost of ownership models for major platforms
Where this commonly fails
  • Capital costs identified but recurrent operating costs ignored
  • Financing assumed without confirmed source
  • No total cost of ownership for major platforms

Strategic Objective 3: Governance

WHO-DH-SO3.1
Strategic Objective 3: Strengthen governance for digital health at global, regional and national levels

A formal governance body should be established at national level with authority over digital health policy, standards, investment prioritisation, and oversight of the national strategy implementation.

Artefacts an auditor will ask for
  • Terms of reference for national digital health governance body
  • Appointment letters for members
  • Meeting minutes with attendance records
  • Annual report to legislature or Cabinet
Where this commonly fails
  • Governance body exists on paper but does not meet on cadence
  • No decision authority over budget or standards
  • Conflict of interest disclosures missing
WHO-DH-SO3.2
Legal and regulatory framework

National digital health activities should be supported by an enacted legal and regulatory framework covering data protection, electronic records, telemedicine, cross-border data flows, and patient rights.

Artefacts an auditor will ask for
  • Enacted data protection legislation
  • Electronic health records regulation
  • Telemedicine practice guidelines
  • Cross-border data transfer policy
  • Patient digital rights charter
Where this commonly fails
  • Data protection law enacted but no implementing regulations
  • Telemedicine practiced without regulatory framework
  • No published patient digital rights
WHO-DH-SO3.3
Standards and interoperability

National digital health programmes should adopt published interoperability standards for health data exchange, terminology, identifiers, and security, with a published standards roadmap.

Artefacts an auditor will ask for
  • Published national interoperability standards roadmap
  • Adoption mandate for HL7 FHIR, ICD, SNOMED CT, LOINC as applicable
  • Master patient index policy
  • Health facility registry and provider registry policies
  • Conformance testing reports
Where this commonly fails
  • Standards mandated but no conformance testing capability
  • Master patient index policy absent
  • Vendor lock-in due to lack of open standards in procurement
WHO-DH-SO3.4
Workforce capacity for digital health

National strategies should include workforce planning for digital health competencies covering clinicians, public health workers, informaticians, data scientists, and managers, with published curricula and capacity targets.

Artefacts an auditor will ask for
  • Digital health workforce plan
  • Competency framework for digital health roles
  • Curricula for in-service and pre-service training
  • Annual training delivery statistics
Where this commonly fails
  • Workforce plan absent or not aligned to strategy targets
  • Training delivered in pilots only
  • Competency framework not adopted by professional councils

Strategic Objective 3: Strengthen Governance

SO3.1
Sustainable governance structures

Create sustainable and robust governance structures for digital health at all levels.

Artefacts an auditor will ask for
  • Governance charter
  • Steering committee minutes
  • RACI matrix
Where this commonly fails
  • No governance
  • Unclear roles
  • Inactive committee
SO3.2
Regulatory frameworks for digital health

Develop regulatory frameworks addressing data privacy, security, and ethical use of digital health.

Artefacts an auditor will ask for
  • Regulatory framework
  • Approval process
  • Compliance register
Where this commonly fails
  • No framework
  • Slow approvals
  • Weak enforcement
SO3.3
Data governance and protection

Establish data governance frameworks ensuring privacy, consent, and security of health data.

Artefacts an auditor will ask for
  • Data protection policy
  • DPIA register
  • Consent management
Where this commonly fails
  • Weak data protection
  • No DPIA
  • Missing consent
SO3.4
Standards and interoperability governance

Promote adoption of international standards and interoperability for digital health systems.

Artefacts an auditor will ask for
  • Interop standards register
  • Terminology services
  • Profile catalogue
Where this commonly fails
  • No interop standards
  • Terminology gaps
  • No profiles
SO3.5
Artificial intelligence governance in health

Develop governance mechanisms for responsible use of AI and emerging technologies in health.

Artefacts an auditor will ask for
  • AI governance policy
  • Algorithm register
  • Bias audit
Where this commonly fails
  • No AI governance
  • Unaudited algorithms
  • Bias unaddressed

Strategic Objective 4: Person Centred Health Systems

WHO-DH-SO4.1
Strategic Objective 4: Advocate person-centred health systems enabled by digital health

Digital health investments should be assessed against contribution to person-centred care outcomes, including individual access to records, informed consent for data use, and language and accessibility inclusion.

Artefacts an auditor will ask for
  • Patient access to health records policy
  • Informed consent templates for health data use
  • Accessibility conformance statements (WCAG 2.1 AA)
  • Multilingual interface coverage report
Where this commonly fails
  • Patient access exists but limited to summary records
  • Consent templates absent or not language-appropriate
  • Accessibility not tested with users with disabilities
WHO-DH-SO4.2
Equity in access to digital health services

Digital health programmes should be designed to advance equity across geography, gender, age, disability, language, and socio-economic status, with monitoring of differential access and outcomes.

Artefacts an auditor will ask for
  • Equity impact assessment for each major digital health programme
  • Disaggregated access and outcome statistics
  • Digital inclusion strategy
  • Connectivity coverage maps
Where this commonly fails
  • No disaggregation by gender, age, or disability
  • Equity assessments performed retrospectively only
  • Connectivity gaps treated as out of scope
WHO-DH-SO4.3
Privacy, confidentiality and security of health data

Personal health data should be protected through enforced privacy, confidentiality, and security controls aligned with national law and international good practice, including breach notification obligations.

Artefacts an auditor will ask for
  • Information security policy for health data
  • Encryption at rest and in transit standards
  • Access control logs for clinical systems
  • Breach notification procedure and register
  • Independent security assessment reports
Where this commonly fails
  • Encryption applied to backups only
  • Breach notification window not defined
  • No independent assessment of national platforms
  • Access logs not reviewed
WHO-DH-SO4.4
Ethics and trust in digital health

Digital health programmes should be governed by published ethical principles, including responsible use of artificial intelligence in health, with mechanisms for redress and complaints.

Artefacts an auditor will ask for
  • National ethics framework for digital health and AI in health
  • Ethics review process for digital health pilots
  • Patient complaint and redress mechanism
  • AI model validation and bias assessment reports
Where this commonly fails
  • AI pilots launched without ethics review
  • Redress mechanism not publicised
  • No bias assessment for AI tools serving diverse populations

Strategic Objective 4: Person-Centred Digital Health

SO4.1
People-centred design principles

Place people at the centre of digital health through appropriate health data ownership.

Artefacts an auditor will ask for
  • UX design system
  • User research
  • Usability tests
Where this commonly fails
  • No user research
  • Provider-centric design
  • No testing
SO4.2
Digital health literacy

Promote digital health literacy among health workers and the general population.

Artefacts an auditor will ask for
  • Digital literacy curriculum
  • Patient education
  • Assessment tools
Where this commonly fails
  • Low literacy unaddressed
  • No curriculum
  • No assessment
SO4.3
Equity and inclusion in digital health

Ensure digital health technologies reduce rather than exacerbate health inequities.

Artefacts an auditor will ask for
  • Equity assessment
  • Access plan
  • Disparities report
Where this commonly fails
  • No equity lens
  • Digital divide
  • No targeted access
SO4.4
Patient engagement and empowerment

Use digital tools to enhance patient engagement, self-management, and shared decision-making.

Artefacts an auditor will ask for
  • Patient portal
  • Engagement metrics
  • Co-design records
Where this commonly fails
  • No patient portal
  • Low engagement
  • No co-design
SO4.5
Community health worker digital support

Equip community health workers with appropriate digital tools and training.

Artefacts an auditor will ask for
  • CHW digital toolkit
  • Training records
  • Supervision data
Where this commonly fails
  • No CHW digital tools
  • Limited training
  • No supervision data
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the WHO Global Strategy on Digital Health 2020-2025 framework page.