ADVISOR · GOVERNANCE & REMEDIATION
Morten Andersen
Background
Morten came to the buyer side from senior commercial and licensing roles at IBM and Oracle. At IBM he ran enterprise licensing and audit engagements for some of the largest financial services and industrial accounts in EMEA. At Oracle he sat on the publisher's side of complex ULA, applications, and database renewal negotiations. The pattern that moved him across the table was consistent: the customers who got the best outcomes were the ones with ex-publisher people on their side.
He co-founded Redress Compliance, the independent buyer-side licensing advisory firm, where he leads the always-on advisory subscription covering contract negotiation, benchmarking, renewals, and audit defense across the major enterprise software publishers, and is partner of record on the firm's largest IBM and cross-publisher engagements.
On this site Morten leads the governance and remediation practice. His focus is the engineering side of license risk: building the dependency inventory that tells you what you actually run, putting approval gates in place so the next relicensed component never reaches production unreviewed, and executing the fork and migration plans that move estates off relicensed projects. That work spans SBOM and dependency mapping, open source policy design, OSPO working practices, and the remediation paths documented in the guides below. Like everyone at the firm, he is paid only by the buyer — no software sales, no vendor referral fees, no reseller margin.
Areas of expertise
Selected work
Morten authors the governance and remediation content across this site, including the open source governance and SBOM pillar guide, software composition analysis explained, the remediation and alternatives pillar guide, and the migration guides for teams moving off relicensed projects. He also contributes governance data to the State of Relicensing Exposure 2026 research study.
How Morten works
Morten's engagements begin with evidence: a dependency inventory built from the actual build artifacts, not a questionnaire. In governance work, the deliverable is a policy and an approval gate that engineering teams will actually use — a rule that developers route around is worse than no rule at all. In remediation work, each of the five paths off a relicensed project is priced against the others before anyone commits, because the cheapest-looking option on day one is rarely the cheapest over three years. Migration and fork plans come with effort estimates engineering leadership can hold their teams to, and every recommendation is written so that a CTO, a procurement lead, and outside counsel can all read the same document. Where interpretation of a license is the question, he recommends counsel — this is commercial advisory, not legal advice.