Skip to main content

AWS FinOps audit

AWS FinOps audit: cut your bill with quantified savings

A read-only cost audit of your AWS account: spend breakdown, Savings Plans and Reserved Instances, rightsizing, forgotten resources. Every recommendation is quantified in euros per month, with the commands to apply it.

Why run a FinOps audit of your AWS account

An AWS bill rarely jumps overnight. It drifts, project after project:

  • instances sized for a peak that never came back;
  • detached EBS volumes, old snapshots and Elastic IP addresses nobody uses any more;
  • Savings Plans or Reserved Instances coverage that is too low, or sized on past usage;
  • VPC endpoints billed by the hour in every Availability Zone, with no traffic.

The FinOps audit makes these costs visible, ties them to specific resources and ranks the actions by return on investment.

What the FinOps audit analyses

FinOps domain analyses
AnalysisWhat you get
Cost breakdownSpend by service and region, 6-month trend and 3-month forecast (Cost Explorer).
Savings Plans and Reserved InstancesCurrent coverage, purchase recommendations and potential savings.
RightsizingOver- or under-provisioned instances, based on Compute Optimizer recommendations.
Unused resourcesUnassociated Elastic IP addresses, unattached EBS volumes, old snapshots, long-stopped instances.
VPC endpointsInterface endpoints with no traffic over 30 days, Interface endpoints used for S3 or DynamoDB where a free Gateway endpoint would do, deployments across too many zones.
Trusted AdvisorCost optimisation checks available with your AWS Support plan.

Quantified savings, not generalities

  • Each action states the expected monthly saving in euros, with the calculation assumption.
  • Actions are sorted by return on investment: most profitable first, ten at most, small levers grouped together.
  • Each action names the affected resources (IDs, ARNs) and the AWS CLI commands to apply it.
  • The remediation plan also does the reverse sum: what security or resilience fixes cost, to show a net cost and a 12-month ROI.

Cost, security and resilience in the same audit

Cutting a bill without looking at the rest can be expensive: deleting a snapshot that was your only backup, for instance. The FinOps audit is one of the ten domains analysed together:

  • the resilience domain flags the backups and Multi-AZ deployments to keep;
  • the cost optimisation pillar of the Well-Architected Framework completes the analysis;
  • the Excel action plan consolidates every domain, with a Pareto and an overall return on investment.

Data required

  • Read access to billing is part of the IAM role you deploy (job-function/Billing policy); nothing else to open.
  • Cost history comes from Cost Explorer: it must be enabled on the account.
  • Rightsizing recommendations require Compute Optimizer to be enabled; otherwise, the audit recommends enabling it as a first action.
  • From a member account of AWS Organizations, Cost Explorer only shows that account's costs; the consolidated view of shared commitments lives in the management account.

What the FinOps audit does not do

  • It buys no Savings Plan and changes no resource: it recommends, you decide.
  • It does not replace an ongoing FinOps practice (chargeback, budgets, monthly reviews): it is a snapshot at a given date, to be run again.
  • It covers one AWS account per audit.

AWS FinOps audit: frequently asked questions

How much can we save?

That depends entirely on your account: we do not promise a percentage. The report quantifies each lever found, resource by resource, in euros per month, and totals the potential savings and the cost of the actions.

Do I have to give access to my billing?

The IAM role includes read-only access to billing (job-function/Billing) and Cost Explorer. It cannot pay, change your payment methods or purchase commitments.

Compute Optimizer is not enabled on my account: is that a blocker?

No. The other analyses are produced as usual; the report notes the lack of rightsizing recommendations and suggests enabling Compute Optimizer.

Should we audit the management account or the member accounts?

An audit covers one account. Member accounts give the most accurate view of their resources; the AWS Organizations management account gives the consolidated view of commitments. Run one audit per account you want analysed.

How much does the FinOps audit cost?

299 USD per audit, billed by AWS. FinOps comes with the other nine domains (security, resilience, IAM, networking…) at no extra cost.

Ready to audit your AWS account?

Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.