By · Last updated 2026-05-14

返回博客中小企业安全

DORA 法规下的 ICT 供应商管理与 ISO 27001

DORA 于 2025 年 1 月正式生效,要求金融机构对每家科技供应商进行年度审查。ISO 27001 认证可将每家供应商的审查工时从 40 至 80 小时大幅压缩至数小时以内。

May 14, 20268 分钟阅读
DORA ICT vendor managementISO 27001 DORA compliancefinancial institution vendor riskannual vendor assessmentMiFID II vendor oversight

DORA 的核心要求

DORA(《数字运营韧性法》)于 2025 年 1 月正式成为欧盟法律。银行、保险公司、投资机构和支付机构现在必须对其使用的每一家科技供应商进行风险管理。以下三项规定尤为关键。

强制合同条款(第 30 条)。 与每家科技供应商签订的合同必须涵盖四项内容:审计权限、事件通知、退出计划和绩效指标。这些条款没有任何弹性空间。

年度审查(第 28 条)。 机构必须至少每年对每一家关键供应商进行一次审查。若某家供应商发生故障会导致正常业务中断,则将其认定为「关键供应商」。用于合规业务的匿名化工具通常归入此类。

供应商名册(第 28 条第 3 款)。 机构必须维护一份涵盖所有关键第三方合同的实时清单,并为每家供应商记录安全文件。

对数十家供应商每年从头开展审查需要耗费大量时间。据估算,单次定制化审查需要约 40 至 80 小时。一家拥有 50 家关键供应商的荷兰银行,每年的审查工作量高达 4,000 小时——相当于两名全职人员全年只做审查,别无其他职责。

ISO 27001 大幅压缩审查工时

ISO 27001 认证为机构提供了满足 DORA 年度审查要求的快速通道。认证机构每年进行一次监督审计,每三年进行一次完整再认证审计。证书设有有效期,且仅在年度审计持续通过的情况下保持有效。

依据 DORA 的年度审查规则,机构每年只需调取供应商当前有效的 ISO 27001 证书,核查有效日期即可。有效日期意味着外部审计机构在过去十二个月内已对该供应商的 93 项安全控制措施完成核查。机构将此记入供应商名册,审查即告完成。

效率提升立竿见影。一家荷兰银行对经认证匿名化工具的年度审查只需数小时;从头自查则需数周。以 20 家经认证第三方供应商为例,每年可节省约 1,200 小时,这些时间可用于其他更具价值的工作。

隐私工具为何纳入 DORA 管辖范围

当金融机构使用隐私和匿名化工具处理客户数据、满足 GDPR 要求或处理 KYC 文件时,这些工具将受到 DORA 的约束。如果该工具停止服务导致机构无法生成符合 GDPR 要求的输出,则该工具即构成 DORA 定义下的关键第三方,必须接受年度审查。

关于数据最小化规则,请参阅GDPR 合规指南。关于认证如何减少合规工作量,请参阅 ISO 27001 供应链下游合规价值ISO 27001 供应商评估捷径

参考资料

准备好保护您的数据了吗?

开始使用 285 种实体类型在 48 种语言中匿名化 PII。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.