ORCHA Domain Master OBR v6 · DHAF · DTAC · OBR Silver · MHCC · ISO 82304-2
v4
?
Add your name
🛠 Builder mode — use the + inserters to add criteria & sub-domains. This is the internal master; export it to share or branch a client version.
Consolidated Master Criteria Library · 2026 Review

One canonical library for every assessment criterion.

The Domain Master is ORCHA's single, consolidated criteria library — every question laid out side-by-side as one reviewable surface. Each question appears once and carries a badge for every scheme it belongs to, so you can see at a glance where a criterion is shared and where it is unique. Per-client schemes are simply enable, disable and scoring configurations layered over this master set.

How the review works

Add your name (saved locally in your browser), then enter the dashboard to work through the four OBR v6 domains. Every action is stamped with your name and timestamp, and exportable as JSON.

👤

Set your reviewer name first

Stamped on every action and comment you make. Stored locally — no server.

Three actions per question

  • Keep — the question stays in OBR v6 as worded today.
  • Disable — the question should be removed from the active question set.
  • Discuss — needs a conversation before a decision; add a comment to explain.

How OBR v6, DHAF, DTAC, OBR Silver, MHCC and ISO 82304-2 are merged

  • Where a question code exists in more than one scheme it appears once, tagged with one badge per scheme. The expanded card shows the most-canonical scheme's guidance as primary (OBR > DHAF > DTAC); any materially different scheme-specific guidance is shown alongside in its own section.
  • Where a code is unique to one scheme — UK CQC registration in OBR, HIPAA in DHAF, DCB0129 Clinical Safety in DTAC — it appears once with just that scheme's badge.
  • Data-scoping questions stay consolidated under Data & Privacy → Data Scope (Scene Setters); Scene Setters remain genuine functionality only.
  • Clinical Safety is its own top-level domain (a request from the team) — DCB0129-aligned questions about the CSO, Hazard Log, Safety Case and clinical risk evaluation live here rather than buried under Clinical Assurance.
  • Technical Security & Stability houses the DHAF Enhanced Review Component and DTAC's Cyber Essentials, Interoperability and Tech Sec scene setters together.
  • DTAC NHS Service Standard usability questions appear as ten new sub-domains under Usability and Accessibility, prefixed NHS SS: so they sort together below the existing UA sub-domains.
  • OBR uses NICE ESF tiers (1, 2a, 2b, 3a, 3b); DHAF uses ORCHA-Adapted ESF tiers (A, Bi, Bii, Ci, Cii). Codes differ, so both sets appear under ESF Compliance side-by-side.
  • OBR Silver (Enhanced Technical Security) questions are distributed into the existing Technical Security & Stability sub-domains where they fit naturally — accreditation under Cyber Essentials & Certifications, penetration testing / vulnerability / MFA under Security Assessment, and product lifecycle items under Product Stability & Lifecycle. Each Silver question carries an SRL tier (Security Requirement Level 1–4) shown alongside its guidance, and an OBR Silver badge so they're filterable from the SRL workflow.
  • MHCC (Mental Health Commission of Canada Assessment Framework for Mental Health Apps) was matched code-by-code against the existing dataset. Where an MHCC question is sourced from ORCHA/US DHAF (per its origin tag) and the wording matches an existing code, that code gains the MHCC badge. Where MHCC introduces new criteria — for mental-health-specific scoping, suicidal ideation, Cultural Safety / Equity and Enhanced Data Sovereignty (EGAP / OCAP®) — they appear as new MHCC-only questions, with the latter two themes promoted to their own top-level domains.
  • Codes, question wording and guidance are taken verbatim from SOP v6.1 (OBR), DHAF SOP V1, DTAC SOP, the OBR Silver — Enhanced Technical Security spreadsheet and the MHCC Assessment Framework for Mental Health Apps PDF; OBR scoring (Value / Risk / Question Type) is from the Long Summary Document.

Comment conventions

  • Codes and question wording are locked, but you can request changes to domain mapping, sub-category, ordering and guidance via comments.
  • Prefix your comment with a tag and the change you want applied:
  • MOVE → Data & Privacy / Privacy Policy — remap to a different domain / sub-category.
  • SUBCAT → Privacy Policy — change the sub-category only.
  • ORDER → 3 — set ordering rank within its sub-category (lower = earlier).
  • GUIDANCE → <notes> — add or replace guidance text.
  • Plain text without a tag is treated as a free-form review note.

Domain Master dashboard

0 domains, 0 questions in the master library. Pick a tile to start reviewing — your progress is tracked locally in this browser.

Overall review progress
0% reviewed
0 of 0 questions
0 keep 0 disable 0 discuss · 0 comments
0Reviewed
0Total