Banking Corporate Governance: Agreement 005-2011 in Panama

When a financial institution receives an observation on corporate governance, the typical reaction is to look for the missing document. It almost never is a document: it is that the decision structure cannot withstand being asked who answers for what.
Agreement 005-2011 of the Superintendency of Banks, dated 20 September 2011, "issues a new Agreement updating the provisions on Corporate Governance". It is a rule that reads quickly and gets implemented badly, because its content is not documentary but organizational.
What it actually regulates
Corporate governance sounds like committees and minutes. In practice it defines three things: who decides, who executes and who verifies that what was decided gets done. When those three functions concentrate in the same people, the framework collapses on its own, however well the manual is drafted.
The rule puts the focus on the board. Not as a ceremonial body approving whatever is brought to it, but as the ultimate owner of the institution's control environment. That responsibility is not delegated: execution can be delegated, accountability never.
How it translates into operations
Board composition and functioning
What an inspector reviews is not whether a board exists, but whether it works. Specifically: how often it meets, what information it receives beforehand, whether that information arrives in time to be read, and whether the minutes record deliberation or only approval.
Minutes reading "approved unanimously" with no trace of what was discussed is a finding waiting to happen.
Committees with a written mandate
Committees need three things: a mandate stating what they decide and what they merely recommend, a composition consistent with that mandate, and a reporting channel to the board.
The frequent mistake is creating committees in response to a previous observation, without defining their authority. They end up being meetings that produce minutes rather than decisions.
Reporting lines that do not cross
This is where most institutions stumble. If whoever executes a process also controls its compliance and then reports the result, there is no internal control: there is one person saying everything is fine.
The independence of control functions is not an organizational luxury. It is the condition for the rest of the framework to mean anything.
What evidence holds all this up
A governance framework is demonstrated with three types of record, and it is worth knowing before they are requested.
The first is the convening notice: what was sent, to whom and when. It evidences that there was real time for analysis. The second is the minutes, which must capture positions and not only the outcome; a recorded disagreement is a sign the body works. The third is follow-up: what was agreed, who took it on, with what date and what happened afterwards.
Without the third, the first two are theatre. It is the record fewest institutions maintain and the one that most quickly reveals whether governance operates or merely exists on paper.
Its relationship with operational risk
Agreement 005-2011 does not live alone. Agreement 011-2018, dated 11 September 2018, establishes that operational risk management must include identification, measurement, mitigation, monitoring and control.
The connection is direct: operational risk is identified and measured in operations, but what to do about it is decided in governance. A risk matrix that never reaches a committee able to allocate resources is a documentary exercise.
I have seen it many times: the institution has an impeccable matrix, up to date, with assigned owners. And the mitigation actions have been open for months because nobody with a budget has seen them. The finding there is not about operational risk; it is about governance.
The findings that repeat most
In the banks where I have worked, corporate governance observations concentrate in a handful of patterns. These are the ones that appear again and again:
Minutes without traceability of the decision. They record the outcome, not the analysis. When the inspector asks why something was decided, there is no documented answer.
Committees without a mandate. They exist, they meet and they take minutes, but nobody can say what that committee is empowered to decide and what it must escalate.
Information arriving late. The board pack is sent the day before. Formally there was information; materially there was no time to analyse it.
Control functions without independence. The head of an area reports on the performance of their own area with no contrast.
Follow-up that never closes. Corrective actions are approved and nobody verifies they were executed. Agreement 011-2018 is explicit about monitoring, and this is the point where most institutions fail.
A structure designed for the org chart, not for operations. Committees that mirror the map of departments instead of grouping decisions that belong together. The result is that every relevant decision has to pass through three separate forums, and none of them feels like the owner.
Self-assessment checklist
- Is there a written mandate for each committee, stating what it decides and what it escalates?
- Does the information pack reach the board with enough time to be read?
- Do the minutes record deliberation, not only approval?
- Do control functions report to a level independent from whoever executes?
- Is there a risk matrix that effectively reaches a committee able to decide?
- Is it verified, with evidence, that approved corrective actions were executed?
- Are process owners named, and do they know it?
- Does the board receive information on operational risk, not only on financial results?
If you fail on 4 or on 6, those are the two an inspector finds first.
Common mistakes when remediating
Answering with documents. A governance observation is rarely closed by writing a new policy. It is closed by changing who decides what.
Creating a committee for every finding. It multiplies meetings and dilutes responsibility. Sometimes the right answer is giving real authority to an existing committee.
Copying another institution's structure. A committee org chart that works in a thousand-person bank does not work in an eighty-person credit union.
Leaving the design for last. Documenting procedures before defining who is accountable produces manuals nobody recognizes as their own.
Treating the board as a recipient of reports. If it only receives, it does not govern. The rule places it as accountable, not as audience.
Where to start
If your institution has open corporate governance observations, order matters: first define the decision structure, then document it. The other way round produces paper that changes nothing.
You can see how we approach regulatory work in SBP regulatory compliance, and the structure design itself in organizational design. The full sector picture is in banking and financial services.
Do you have an open observation and no clear way in? Book a free 15-minute assessment.

CEO, Grupo Alternative
Katherine González
PMP® | ISO 9001 Lead Auditor | MBA
I've spent 15 years helping companies in Latin America optimize their processes. I've seen how BPM transforms companies from within—reducing costs, accelerating growth, and improving the quality of life for teams.
Share this article