Is this a clause-by-clause standards crosswalk?
This is a topic-level preparation map using public standards metadata. It contains no claim to reproduce or fully assess the draft normative requirements.
Map agent authority, access, policy, validation, oversight and evidence to prEN 18228, prEN 18282 and prEN 18229-1 preparation work.
For financial-services platform architects, AI risk leads and security teams.
Last updated: Sep 7, 2026 · Version v1.0 · Not legal advice.
Short answer
Use a control-to-evidence register to prepare agent systems for risk management, cybersecurity and logging assessment. The matrix below is KLA’s topic-level engineering interpretation. Clause-level conformity needs the applicable standard text and a system-specific assessment.
The JTC 21 catalogue entries updated 4 September show the following status. The Commission portal reports EN 18286 assessment as ongoing. Earlier enquiry dates are historical.
| Reference | Subject | Catalogue stage | OJEU citation recorded |
|---|---|---|---|
| EN 18286:2026 | Quality management | Published | No |
| prEN 18228 | Risk management | Approval | No |
| prEN 18282 | Cybersecurity | Approval | No |
| prEN 18229-1 | Logging | Approval | No |
Treat each row as an engineering work package. The draft identifiers indicate relevant topics; they establish no exhaustive clause coverage or required implementation technology.
| Agent control | Relevant topic | Evidence to prepare |
|---|---|---|
| Authority and pre-action policy | prEN 18228: risk management | Risk scenario; delegated scope; policy version; denied-action test |
| Tool and data scope | prEN 18282: cybersecurity | Threat model; credential and network boundaries; unauthorized-access tests |
| Validation | prEN 18228 / prEN 18282 | Test set; known failure modes; results; reviewer and residual-risk decision |
| Human escalation | prEN 18228; assess applicable human-oversight requirements separately | Reviewer authority; context shown; rejection, expiry and escalation tests |
| Monitoring | prEN 18228 / prEN 18282 | Control-effectiveness review; incident triage; remediation and re-test |
| Evidence | prEN 18229-1: logging | Event schema; decision/execution linkage; access and retention rules; reconstruction test |
Assign an owner for the register, approve changes, retain review results and define revalidation triggers. Record the intended use, system boundary and applicable provider or deployer role before assessing obligations.
For each control, add the exact edition and clause when an authorized reviewer has assessed the standard text. Record gaps and compensating measures explicitly. Keep procurement statements consistent with the completed assessment.
For an illustrative AML alert-closure request, retain the tenant and agent identity, case identifier, authorized action, policy version and decision, approval identity where required, execution result, timestamps and correlation identifiers. Define redaction and access rules so the record does not unnecessarily replicate sensitive case data.
Test whether a reviewer can follow a rejected request and an executed request from start to finish. Check missing records, retries and partial failures. Cryptographic sealing is a separate implementation choice to assess; this guide makes no claim that the logging draft mandates it.
An Official Journal reference and conformity with the provisions covering the relevant legal requirements determine the presumption available. Publication, a product mapping or a completed demonstration alone cannot establish it.
KLA Control Plane can contribute policy and approval records, execution lineage and evidence artifacts from integrated paths. Organizational governance, system classification, validation and the applicable conformity assessment remain part of the wider work.
Use the architecture guide to assign implementation boundaries before turning this matrix into a procurement checklist.
This is a topic-level preparation map using public standards metadata. It contains no claim to reproduce or fully assess the draft normative requirements.
A mapping identifies candidate controls and evidence. Conformity requires assessment of the system against applicable requirements and the relevant standard provisions, with any presumption limited by the Official Journal reference.
Regulated Agent Harness Architecture
/guides/regulated-agent-harness-architecture
Bank of England harness engineering analysis
/blog/bank-of-england-ai-harness-engineering
Preparing agent controls for EU AI Act standards
/blog/eu-ai-act-standards-agent-controls
SAFR runtime framework
/blog/safr-mas-framework-explained
Discuss your agent control architecture
/book-demo