INTERVIEW

João Miranda de Sousa, of Garrigues: “Today, it is no longer enough simply to master specific areas of law”

INTERVIEW

Mafalda Barreto, of Gómez-Acebo & Pombo: “Clients no longer look only for lawyers; they look for strategic partners”

Nexure Advisory is born, a new benchmark in software compliance and contractual licensing risk management

By Heidi Maldonado

Software is no longer a peripheral technological asset. Today, it is the operational core of organizations and, at the same time, one of their main vectors of contractual, regulatory, and economic exposure. Audits by manufacturers with retroactive adjustments of millions of euros, clauses for unilateral modification of licensing metrics, and structural dependencies that prevent the execution of exit plans within the timeframes stipulated by the contracts themselves—usually between 15 and 30 days—these are everyday realities for any organization that operates with mission-critical software.

It is in this context that Nexure Advisory is born: a boutique consulting firm specializing in software contractual risk governance, which arises from the natural evolution of CSV Consulting – a consulting firm founded more than a decade ago by Carlos Garmendia, Tania Martínez and Javier Garmendia – and which is integrated this year into the Acatia Group; forming the largest ecosystem of TechCompliance solutions.

This change is not a cosmetic rebranding. It is an identity transformation that reflects the maturity of a working model, the expansion of its international reach, and the consolidation of its own methodology—the SLR Framework (Software Licensing Risk Management Framework)—which allows organizations to measure, quantify, and manage their exposure to contractual risk arising from software licensing in a structured way.

“Software has become one of the areas with the greatest regulatory and contractual exposure for organizations. With Nexure Advisory, we want to better reflect our mission: to help companies proactively manage this risk by integrating technology, legality, and strategy,” said Carlos Garmendia, managing partner of Nexure Advisory.

The name Nexure is not arbitrary. It refers to the concept of a nexus or structural connection and accurately reflects the essence of the firm’s work: integrating the various dimensions of software-related risk—technological, contractual, legal, and operational—into a coherent system of control and governance.

The core of this proposal is the SLR Framework, a proprietary methodological model structured around three quantifiable indicators: the ECA (Adjusted Contractual Exposure), which measures the specific contractual risk of each license; the SLRMI (Software Licensing Risk Maturity Index), which assesses organizational maturity in risk management; and the IEC (Contractual Exposure Index), which integrates both into an aggregated view of the organization’s software portfolio. This objective, traceable, and independent model transforms a traditionally invisible risk into a strategic indicator for decision-making.

The launch of Nexure Advisory is not unrelated to the current regulatory climate. The DORA Regulation (Regulation (EU) 2022/2554, Digital Operational Resilience Act) imposes precise obligations on financial institutions and their critical ICT providers regarding ICT risk management, operational resilience, third-party control, and exit plans in the face of technological dependencies. Furthermore, Guidelines EBA/GL/2019/02 and EBA/GL/2019/04—on ICT risk management and outsourcing agreements, respectively—establish a technology governance standard that serves as an exemplary benchmark even for organizations not subject to financial supervision.

In this context, software contracts from major technology manufacturers—SAP, Oracle, Microsoft, and others—have ceased to be mere commercial agreements and have become private regulatory instruments that decisively condition the operational continuity, strategic autonomy, and financial exposure of the organizations that subscribe to them. The contractual asymmetry characteristic of these agreements, combined with practices the firm calls legal marketing—unilateral modifications of terms through links to websites—creates a risky scenario that demands an integrated legal, technical, and strategic approach.

“Our goal is to transform the traditional software management model. For years it has been treated as a simple technological asset, when in reality it is an asset with critical contractual and regulatory implications,” said Javier Garmendia, managing partner responsible for projects and processes.

Nexure Advisory’s activity is structured around three main lines of practice, conceived as an integrated risk governance system: firstly, software compliance consulting, consisting of controlling the contractual risk associated with licenses and designing risk-based management models aligned with the DORA, EBA, and ENS standards. Secondly, software compliance audits and penetration tests, which allow organizations to anticipate contractual and technical vulnerabilities before the manufacturers themselves activate them through review processes initiated by their own initiative.

Finally, technological solutions for the automation of contract control, which allow continuous visibility over the obligations and risks arising from the use of the software, integrated into the PDCA cycles of corporate risk management.

CSV Consulting’s transformation into Nexure Advisory coincides with its integration into the Acatia Group, strengthening the firm’s capacity to undertake larger-scale projects and expand its presence in international markets. This integration aligns with Nexure Advisory’s commitment to serving as a leading consultancy for regulated entities, large organizations, and any company for which software is a critical component of its operations.

Related Articles

Editar Imagenes de Higthligths

You are not permitted to submit this form!







    Editar Imagenes de Higthligths

    You are not permitted to submit this form!

    Editar reconocimientos - Latin Lawyer

    Contenido Reconocimiento Latin Lawyer*

    Editar reconocimientos - Leaders League

    Contenido Reconocimiento Leaders League*

    Editar link equipo

    Editar Oficinas

    Editar de highlight

    Editar reconocimientos - Legal 500

    Contenido Reconocimiento Chambers*

    Editar Reconocimientos - Chamber

    Contenido Reconocimiento Chambers*

    Editar Banner

    Selecciona un Banner*

    Editar reconocimientos

    Editar reconocimientos

    Contenido Reconocimiento Interno*

    Editar resumen

    Editar sectores de actividad

    Sectores de Actividad*

    Editar áreas de practica

    Areas de practica*

    Editar tag

    Tags*

    Edita otros datos de interés

    You are not permitted to submit this form!

    Editar logo

    You are not permitted to submit this form!

    Editar datos de firma