WHO Global Strategy on Digital Health 2020-2025
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Implementation Enablers
Each major digital health programme should maintain a risk register covering technical, clinical safety, privacy, sustainability, and political risks, with documented mitigations and ownership.
- Programme-level risk registers
- Risk treatment plans
- Quarterly risk review minutes
- Clinical safety case for clinical decision support tools
- Risks captured only at project start
- Clinical safety treated as IT issue
- No escalation path to governance body
Digital health programmes should demonstrate financial and operational sustainability beyond initial donor or pilot funding, with total cost of ownership models covering at least five years.
- Five-year total cost of ownership model
- Transition plan from donor to government funding
- Operations and maintenance contracts
- Service level agreements with vendors
- Pilots end at funding cliff without transition
- Operations costs underestimated
- No service level agreement for production systems
Public procurement for digital health products and services should require open standards, interoperability conformance, and clear exit provisions to avoid vendor lock-in.
- Standard procurement clauses mandating open standards
- Conformance testing requirements in tender documents
- Exit and data portability clauses in contracts
- Vendor risk assessments
- Procurement template references standards without conformance test
- No exit clause for source code and data
- Sole-source awards without market test
Data captured through digital health systems should be subject to defined data quality standards, with routine audit, validation, and feedback loops to source facilities.
- Data quality framework
- Routine data quality audit reports
- Feedback reports to facilities and providers
- Data dictionary aligned to national standards
- Data dashboards published without quality validation
- No feedback loop to data submitters
- Data dictionary missing or out of date
National digital health infrastructure should be designed to support surveillance, contact tracing, vaccination records, and supply chain visibility during health emergencies, with scenario tests.
- Emergency preparedness annex to digital health strategy
- Stress test reports for surveillance and reporting systems
- Continuity of operations plan
- After-action reviews from past emergency activations
- Emergency systems separate from routine systems
- No stress test under load
- After-action lessons not implemented
Monitoring and Evaluation
A monitoring and evaluation framework with baseline indicators, targets, and reporting cadence should be established for the national digital health strategy, with results published.
- M&E framework with indicators and targets
- Baseline assessment report
- Annual progress reports against indicators
- Published dashboard or open data feed
- Indicators defined but no data source
- No baseline established
- Results not published or shared with stakeholders
Member States should register significant digital health investments in the WHO Digital Health Atlas to support coordination, prevent duplication, and contribute to global learning.
- Digital Health Atlas registrations for active programmes
- Annual review of Atlas entries for currency
- Cross-reference register linking Atlas entries to national strategy
- Programmes not registered at all
- Atlas entries stale
- No internal owner for Atlas curation
SO1
Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 1: Promote Global Collaboration. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WHODIGH-1
- see authoritative source for detailed gap analysis
SO2
Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 2: Advance Country Implementation. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WHODIGH-2
- see authoritative source for detailed gap analysis
SO3
Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 3: Strengthen Governance. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WHODIGH-3
- see authoritative source for detailed gap analysis
SO4
Per WHO Global Strategy on Digital Health 2020-2025: Strategic Objective 4: Person-Centred Digital Health. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WHODIGH-4
- see authoritative source for detailed gap analysis
Strategic Objective 1: Global Collaboration
Member States and partners should actively participate in global digital health knowledge exchange, contribute to open repositories, and support cross-border learning on digital health interventions, standards, and lessons learned.
- Participation log for WHO digital health forums and working groups
- Contributions to WHO digital health knowledge repository
- Country case study submissions
- MoUs with peer Ministries of Health on digital health cooperation
- Engagement limited to attendance without substantive knowledge contribution
- No formal mechanism to translate WHO guidance into national practice
- Case studies not maintained or refreshed annually
Strategic Objective 1: Promote Global Collaboration
Member States share knowledge and investments in digital health to align strategies across countries.
- Knowledge platform
- Community of practice
- Sharing log
- No platform
- Inactive CoP
- Siloed knowledge
Promote networks and partnerships for digital health innovation and knowledge exchange.
- Network membership
- Network governance
- Activity reports
- No network membership
- Passive participation
- No outputs
Establish a repository of digital health implementations, evidence, and best practices.
- Repository design
- Submission SOP
- Curation process
- No repository
- Submission unclear
- No curation
Build capacity in low- and middle-income countries for adopting digital health technologies.
- Capacity plan
- Training curriculum
- Certification records
- No capacity plan
- Limited training
- No certification
Strategic Objective 2: Advance Country Digital Health Implementation
Every country should adopt, review, and strengthen its national digital health strategy.
- National strategy document
- Roadmap
- Governance structure
- No strategy
- Strategy unimplemented
- No governance
Define a national digital health architecture blueprint or roadmap for implementation.
- Reference architecture
- Blueprint
- Implementation guide
- No blueprint
- Architecture fragmented
- Stale guide
Adopt open-source health data standards and interoperability frameworks.
- Standards register
- Open-source toolkit
- Conformance tests
- No standards adoption
- Proprietary lock-in
- No conformance
Mobilise resources and investment for sustainable digital health infrastructure.
- Infrastructure plan
- Connectivity assessment
- Investment case
- No investment case
- Connectivity gaps
- No power resilience
Strengthen health information systems as part of national digital health strategies.
- HIS strategy
- Indicator framework
- Data quality assessment
- Fragmented HIS
- Poor data quality
- No interoperability
Strategic Objective 2: Country Implementation
Each Member State should establish, publish, and operationalise a national digital health strategy that is aligned with WHO guidance, includes a costed implementation roadmap, and is reviewed on a defined cadence.
- Approved National Digital Health Strategy document
- Costed implementation roadmap with milestones
- Annual progress report against strategy KPIs
- Ministry-level governance committee minutes
- Alignment matrix mapping national strategy to WHO four strategic objectives
- Strategy published but not costed or resourced
- No defined review cycle or owner
- Alignment with WHO objectives not documented
- Strategy stale beyond stated review date
The national digital health strategy should be developed and reviewed with structured input from public sector entities, civil society, patient representatives, private sector providers, academia, and frontline health workers.
- Stakeholder mapping and engagement plan
- Consultation workshop reports
- Public comment register with dispositions
- Patient and civil society representation roster
- Engagement limited to government departments
- No patient or civil society voice on the steering committee
- Consultation outputs not reflected in final strategy
Implementation of the national strategy should be supported by a costed action plan covering capital and recurrent expenditure, with identified financing sources across multiple budget cycles.
- Multi-year costed action plan
- Budget approval letters from Ministry of Finance
- Donor and partner financing matrix
- Total cost of ownership models for major platforms
- Capital costs identified but recurrent operating costs ignored
- Financing assumed without confirmed source
- No total cost of ownership for major platforms
Strategic Objective 3: Governance
A formal governance body should be established at national level with authority over digital health policy, standards, investment prioritisation, and oversight of the national strategy implementation.
- Terms of reference for national digital health governance body
- Appointment letters for members
- Meeting minutes with attendance records
- Annual report to legislature or Cabinet
- Governance body exists on paper but does not meet on cadence
- No decision authority over budget or standards
- Conflict of interest disclosures missing
National digital health activities should be supported by an enacted legal and regulatory framework covering data protection, electronic records, telemedicine, cross-border data flows, and patient rights.
- Enacted data protection legislation
- Electronic health records regulation
- Telemedicine practice guidelines
- Cross-border data transfer policy
- Patient digital rights charter
- Data protection law enacted but no implementing regulations
- Telemedicine practiced without regulatory framework
- No published patient digital rights
National digital health programmes should adopt published interoperability standards for health data exchange, terminology, identifiers, and security, with a published standards roadmap.
- Published national interoperability standards roadmap
- Adoption mandate for HL7 FHIR, ICD, SNOMED CT, LOINC as applicable
- Master patient index policy
- Health facility registry and provider registry policies
- Conformance testing reports
- Standards mandated but no conformance testing capability
- Master patient index policy absent
- Vendor lock-in due to lack of open standards in procurement
National strategies should include workforce planning for digital health competencies covering clinicians, public health workers, informaticians, data scientists, and managers, with published curricula and capacity targets.
- Digital health workforce plan
- Competency framework for digital health roles
- Curricula for in-service and pre-service training
- Annual training delivery statistics
- Workforce plan absent or not aligned to strategy targets
- Training delivered in pilots only
- Competency framework not adopted by professional councils
Strategic Objective 3: Strengthen Governance
Create sustainable and robust governance structures for digital health at all levels.
- Governance charter
- Steering committee minutes
- RACI matrix
- No governance
- Unclear roles
- Inactive committee
Develop regulatory frameworks addressing data privacy, security, and ethical use of digital health.
- Regulatory framework
- Approval process
- Compliance register
- No framework
- Slow approvals
- Weak enforcement
Establish data governance frameworks ensuring privacy, consent, and security of health data.
- Data protection policy
- DPIA register
- Consent management
- Weak data protection
- No DPIA
- Missing consent
Promote adoption of international standards and interoperability for digital health systems.
- Interop standards register
- Terminology services
- Profile catalogue
- No interop standards
- Terminology gaps
- No profiles
Develop governance mechanisms for responsible use of AI and emerging technologies in health.
- AI governance policy
- Algorithm register
- Bias audit
- No AI governance
- Unaudited algorithms
- Bias unaddressed
Strategic Objective 4: Person Centred Health Systems
Digital health investments should be assessed against contribution to person-centred care outcomes, including individual access to records, informed consent for data use, and language and accessibility inclusion.
- Patient access to health records policy
- Informed consent templates for health data use
- Accessibility conformance statements (WCAG 2.1 AA)
- Multilingual interface coverage report
- Patient access exists but limited to summary records
- Consent templates absent or not language-appropriate
- Accessibility not tested with users with disabilities
Digital health programmes should be designed to advance equity across geography, gender, age, disability, language, and socio-economic status, with monitoring of differential access and outcomes.
- Equity impact assessment for each major digital health programme
- Disaggregated access and outcome statistics
- Digital inclusion strategy
- Connectivity coverage maps
- No disaggregation by gender, age, or disability
- Equity assessments performed retrospectively only
- Connectivity gaps treated as out of scope
Personal health data should be protected through enforced privacy, confidentiality, and security controls aligned with national law and international good practice, including breach notification obligations.
- Information security policy for health data
- Encryption at rest and in transit standards
- Access control logs for clinical systems
- Breach notification procedure and register
- Independent security assessment reports
- Encryption applied to backups only
- Breach notification window not defined
- No independent assessment of national platforms
- Access logs not reviewed
Digital health programmes should be governed by published ethical principles, including responsible use of artificial intelligence in health, with mechanisms for redress and complaints.
- National ethics framework for digital health and AI in health
- Ethics review process for digital health pilots
- Patient complaint and redress mechanism
- AI model validation and bias assessment reports
- AI pilots launched without ethics review
- Redress mechanism not publicised
- No bias assessment for AI tools serving diverse populations
Strategic Objective 4: Person-Centred Digital Health
Place people at the centre of digital health through appropriate health data ownership.
- UX design system
- User research
- Usability tests
- No user research
- Provider-centric design
- No testing
Promote digital health literacy among health workers and the general population.
- Digital literacy curriculum
- Patient education
- Assessment tools
- Low literacy unaddressed
- No curriculum
- No assessment
Ensure digital health technologies reduce rather than exacerbate health inequities.
- Equity assessment
- Access plan
- Disparities report
- No equity lens
- Digital divide
- No targeted access
Use digital tools to enhance patient engagement, self-management, and shared decision-making.
- Patient portal
- Engagement metrics
- Co-design records
- No patient portal
- Low engagement
- No co-design
Equip community health workers with appropriate digital tools and training.
- CHW digital toolkit
- Training records
- Supervision data
- No CHW digital tools
- Limited training
- No supervision data
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the WHO Global Strategy on Digital Health 2020-2025 framework page.