Kode-1
optimise

FinOps when the regulator is watching

30 June 2026

The cloud cost conversation arrives in every enterprise, usually about eighteen months after the migration was declared a success. In a regulated enterprise it arrives with a complication the standard FinOps playbook does not address: some of your most expensive architecture exists because a regulator expects it to. Redundancy across zones and regions. Disaster recovery environments that sit idle by design. Data residency requirements that rule out the cheapest options. Retention obligations that keep storage growing on schedule. The monitoring, logging, and encryption overhead that operational resilience and information security standards effectively mandate. These are not inefficiencies — they are the cost of the obligations the organisation carries. Together they put a floor under cloud spend, and cost-cutting that breaches the floor converts a budget problem into a compliance problem. Often silently: the DR environment that was quietly downsized to hit a savings target fails no test until the day it is needed, or the day a supervisor asks for evidence it works. The floor is real. It is also, in most estates, well below current spend — because most estates carry substantial cost that has nothing to do with any obligation. Instances sized by guesswork and never revisited. Environments that outlived the project that created them. Storage that has never met a lifecycle policy. Non-production platforms running nights and weekends for no one. The discipline that matters in a regulated environment is not cutting — it is classification: knowing, line by line, which dollars are the obligation floor, which are driving value, and which are waste. Classification changes the conversation with the board. A single large cloud number invites a single blunt response. Unit economics — cost per transaction, per customer, per workload, trended over time and attributed to the platforms that generate it — invites better questions. The regulated twist is to attribute the resilience premium explicitly: when the board can see what portion of platform cost is carrying the obligations it has attested to, cost-of-obligation and cost-of-waste stop being the same line item, and the organisation stops accidentally treating one as the other. Making the discipline stick is an engineering problem, not a reporting one. Tagging enforced when resources are provisioned, not reconstructed at month end. Budgets and anomaly alerts wired into the platform, so drift is caught in days. Architecture standards that include cost in the definition of done, so efficiency is designed in rather than audited in. A monthly spreadsheet ritual produces commentary; guardrails in the platform produce behaviour. The same logic makes optimisation continuous rather than annual. Rightsizing informed by real utilisation telemetry. Commitment purchasing managed against an actual demand forecast. Storage lifecycle policies that run themselves. This is run-and-improve work — the platform keeps paying back when it is tuned, governed, and continuously improved, and cost is one of the dimensions being tuned. The annual cost crusade, by contrast, reliably produces the two failure modes worth naming: the freeze-everything mandate that stalls delivery to save a quarter's optics, and the cut that lands on resilience capacity because idle-by-design looked like waste to someone reading a report. Ownership matters as much as tooling. Cost discipline handed to procurement becomes a contract negotiation; handed to finance alone, it becomes a report. It works when it lives with the platform team — the people who can actually change the architecture — in partnership with finance, with the obligations owner in the room whenever the floor is in question. That is a small operating-model decision with outsized returns. A practical place to start: take your highest-spend platform and classify its bill into three buckets — the obligation floor, the spend that drives value, and the waste. The third bucket funds the FinOps practice several times over. The first bucket becomes a board conversation worth having: what resilience actually costs to carry. That is a number worth knowing precisely — ideally before the regulator asks how you know your obligations are funded.