Home/Case Studies/Cost recovery
$1.9M of annual AWS waste, found and structurally removed.
Financial services platform · ~$6M annual AWS spend · 40+ accounts
The situation
AWS spend had grown 90% year on year while revenue grew 20%. Some of that growth was real — two acquisitions and a genuine increase in platform usage. Most of it was not, and nobody could say which was which.
More than half the bill could not be attributed to a team, a product or a business unit. Finance had asked for a breakdown three times and received three different answers, because each was assembled by hand from a different starting point.
A previous optimisation effort had produced a spreadsheet of recommendations. About a third were implemented; the spreadsheet went stale within a month and nobody re-generated it. This is the single most common pattern we inherit.
Cost forensics first
Before touching anything we reconstructed what changed and when, using the Cost and Usage Report joined against CloudTrail. Not "what is expensive" — that is easy and mostly tells you where your production workloads are. The question is what got more expensive, starting when, and what happened that day.
That isolated three clusters of runaway spend within nine days:
- A non-production environment cloned for an integration test in the previous November and never torn down, running production-sized instances. $34k/month.
- A document and event archive writing to S3 Standard with no lifecycle policy, accumulating since the platform launched. $19k/month and growing.
- A logging configuration change that had increased CloudWatch ingestion elevenfold — made deliberately during an incident eight months earlier and never reverted. $22k/month.
None of the three required an architecture decision or a change advisory board. All three were fixed within a fortnight, which bought the credibility for the harder work that followed.
Then the part that makes it stick
Quick wins are not a FinOps programme. If attribution does not change, the same categories of waste reappear within two quarters — usually created by different people for equally sensible-sounding reasons.
Tag policy with teeth
A tag policy existed as a wiki page, which is to say it did not exist. We implemented required tags enforced through service control policies and AWS Config, with a deliberately short exemption list and a named owner for each exemption.
Untagged spend went from 41% to 12% in six weeks, and to 3% by month four. The last nine percent was the hard part — mostly shared infrastructure that genuinely needed an allocation key agreed with finance rather than a tag.
Account structure aligned to the business
Forty accounts had accumulated with no consistent pattern. We restructured into organisational units by product line, so the account boundary does the attribution work that tags struggle with. New workloads land in the right place by default, which is worth more than any amount of reporting.
Showback to the people who can act
Spend dashboards went to engineering leads, not only to finance. A monthly number a finance business partner cannot influence is a report. The same number in front of the engineer who provisioned the resource is a decision.
Commitments, in the right order
The existing Savings Plan coverage was 34%, purchased two years earlier against a pre-growth baseline and with an awkward expiry cliff — three quarters of it maturing in the same month.
We deliberately waited until rightsizing was complete before repurchasing. Buying commitments against an un-rightsized baseline locks in the waste for one to three years, and it is the most expensive mistake available in cloud cost management.
Coverage was rebuilt to 86% and laddered across quarters so no future month carries a disproportionate renewal.
Where it landed
$1.9M identified, $1.4M realised in six months. The remaining $500k sits behind a modernisation project the customer owns and has scheduled for next financial year — we have not counted it as achieved, and we would encourage scepticism about any provider who would.
More durably: untagged spend at 3%, showback in front of the teams who create the cost, and anomaly detection routed to the owning team the same day rather than surfacing at month end.
“They found $190k of annual waste in the first fortnight and then refused to bill us a percentage of it. That told me everything.”
Chief Financial Officer, financial services platform
A note on how we charge
We were asked, twice, to move to a percentage-of-savings model. We declined both times.
A share-of-savings provider is paid more for finding waste slowly, is rewarded for leaving some behind, and has no incentive at all to do the attribution work that prevents recurrence — because prevention reduces next year's fee. The model is attractive because it looks risk-free. It is not; the risk is just deferred and structural.
Related case studies
Find out what is actually in your bill
A first findings session in two weeks, from read-only access. No production changes needed to get the answer.