Cloud Strategy17 July 20267 min read

Cloud Cost Audits: The 10 Things We Check Before Recommending Any Migration

Cloud waste is rarely one bad server. It's weak governance, unclear ownership, poor tagging and the absence of cost accountability, compounding quietly every month. Here's the 10-point checklist we run before any migration or optimisation recommendation.

Cloud bills grow quietly. Nobody wakes up to a sudden spike caused by one obvious mistake — usually it's the opposite. A dev environment left running over a long weekend. A storage bucket nobody remembers creating. A reserved instance that made sense eighteen months ago and hasn't been reviewed since. None of these individually explain a runaway bill. Together, month after month, they do.

We've written before about why South African businesses are still overpaying for cloud and the governance framework needed to fix it structurally. This article is the practical companion: the specific ten-point checklist we run before recommending any migration, re-architecture, or optimisation programme — because you can't fix what you haven't measured, and most organisations haven't measured it properly.

Why cloud cost problems happen

Cloud cost overruns are almost never a technology failure. They're a governance failure. Nobody owns the decision to provision a resource and nobody owns the decision to decommission it, so resources accumulate faster than they get cleaned up. Tagging is inconsistent or absent, so nobody can attribute spend to a team, project or business unit — which means nobody feels the cost of their own decisions. And because nobody has clear ownership or visibility, monitoring tends to focus on uptime and performance, not spend, until someone in finance asks why the bill doubled.

The fix isn't a single tool. It's a disciplined audit that surfaces exactly where the waste is, followed by a governance model that prevents it from re-accumulating.

The 10-point audit checklist

1. Resource inventory. Before anything else: a complete, current list of every resource running across every account, subscription or project. This sounds basic, but in most organisations we engage with, nobody has this in one place — it's scattered across consoles, and shadow resources provisioned outside the standard process are common.

2. Tagging. Every resource should carry consistent tags for owner, environment, project and cost centre. Without this, cost data can't be attributed to anyone, which means nobody is accountable for it. Inconsistent or missing tagging is the single most common finding in our audits.

3. Idle resources. Compute instances, databases and load balancers running with near-zero utilisation, kept alive because decommissioning them is nobody's job. Dev and test environments are the worst offenders — provisioned for a sprint, still running a year later.

4. Rightsizing. Resources provisioned for peak load that never approaches that peak, or sized based on a guess rather than actual utilisation data. Rightsizing based on real usage patterns, rather than the instance size that felt safe at launch, is often the single largest saving available.

5. Storage costs. Old snapshots, orphaned volumes, and data sitting in a storage tier priced for frequent access when it hasn't been touched in months. Storage costs accumulate silently because nobody notices a slowly growing bill the way they'd notice a slowly growing compute bill.

6. Data transfer costs. Egress and cross-region transfer charges are one of the least understood line items on a cloud bill, and one of the easiest to reduce through better architecture — co-locating services that talk to each other frequently, and caching to avoid repeated transfers.

7. Reserved capacity. Committed-use discounts and reserved instances only save money if they match actual, sustained usage. We regularly find reservations purchased for a workload that has since changed shape, sitting alongside on-demand instances covering the load the reservation no longer fits.

8. Monitoring and alerts. Without budget alerts and anomaly detection, cost overruns are discovered when the invoice arrives, not when the spend happens. Real-time visibility is what turns cost management from a monthly post-mortem into an ongoing discipline.

9. Security exposure. Cost and security audits overlap more than people expect — publicly exposed storage, overly permissive access, and unused accounts with standing access are both a security risk and, often, a sign of the same underlying governance gap that's driving cost waste.

10. Ownership and governance. The audit's most important output isn't a savings number — it's a clear answer to "who owns this decision going forward?" Without assigned ownership for provisioning, review and decommissioning, every other fix on this list erodes again within a year.

What to fix first

Not every finding deserves equal urgency. We generally sequence remediation in this order: idle resources and rightsizing first, because they're the fastest wins with the lowest risk of disruption; tagging and ownership second, because without them the savings won't hold; then reserved capacity and storage tiering, which take more analysis to get right; and security exposure addressed in parallel throughout, since it's rarely safe to defer.

The goal isn't a one-time cleanup. It's establishing the governance and visibility that stops the same waste from re-accumulating six months later — which is why the audit output should always include an ownership model, not just a list of things to switch off.

How CloudNala can help

CloudNala runs structured cloud cost and architecture audits across Azure, AWS and GCP — covering all ten checks above, prioritised by impact and effort, with a clear remediation plan and governance model so the savings hold. This is the same discipline we bring to every migration and modernisation engagement, because a migration built on ungoverned cost habits just relocates the problem to a new provider.


Work with CloudNala

CloudNala helps organisations move from technology ambition to practical execution across cloud, AI, data, platform engineering and digital services.

Whether you are exploring AI, modernising your cloud environment, building a public-sector digital service, or turning an idea into a working MVP, we can help you shape the roadmap and deliver the next step.

Request a Cloud Cost and Architecture Review or write to us at consult@cloudnala.co.za