The checklist we actually use

AWS cost optimisation checklist

This is the working checklist behind our audit, in the order we run it. It is ordered by expected saving rather than by AWS service, because the first four sections are where nearly all of the money is.

Work through it in order: commitments first because that is the largest single line in most accounts, then idle and oversized compute, then storage and snapshots, then network, then databases and logging. Skip any service that is not in your top five by spend. A first pass on a never-reviewed account takes a day and usually finds 20% to 35% of the monthly bill.

Before you start

  1. 1Enable Cost Explorer if it is not already on. It takes 24 hours to populate after first enabling, so do this the day before rather than the morning of.
  2. 2Opt in to Compute Optimizer. Free, and its recommendations take about 12 hours to appear. It does the rightsizing arithmetic for you.
  3. 3List every region with spend above about a dollar. Cost Explorer grouped by region. Orphans live in regions nobody opens, and an audit of only your main region misses them entirely.
  4. 4Rank services by six-month spend. The top five services are typically over 90% of the bill. Spend your time proportionally.

1. Commitments, usually the biggest line

CheckDecision ruleTypical saving
Savings Plan coverageCoverage below about 70% of a stable compute baseline is money left on the tableUp to 30% of covered compute
Existing commitment utilisationUtilisation below 95% means you are paying for capacity you do not useRecover the unused portion
Plan typeCompute Savings Plans for anything that might change; EC2 Instance plans only for a fixed familyFlexibility rather than cash
TermOne year, no upfront, for a first commitment. Three years only when the baseline has been stable for a yearAvoids committing to capacity you later remove
RDS, ElastiCache, OpenSearch, Redshift reservationsDatabases are the most stable workload in any account, so reserve them30% to 40% off those instances
Rightsize before committingAlways. Commit to the baseline that remains after cleanup, not the one you have nowPrevents a three-year mistake

2. Compute

CheckDecision ruleTypical saving
Idle instancesAverage CPU under 3% and max under 10% over 14 days, with negligible network100% of the instance
Oversized instancesCompute Optimizer says over-provisioned with risk Very Low or Low20% to 50% per instance
Previous-generation typesAny t2, m4, c4, r4 still running10% to 20%, better performance
Graviton candidatesInterpreted runtimes, managed services and containers with multi-arch images~20%
Non-production out of hoursDev, staging and QA running 168 hours a week for a team that works 45~70% of those environments
Stopped instances with attached volumesStopped for more than a month means snapshot and terminateThe volume cost
Empty and oversized EKS clusters$73 per cluster per month before a single node runs$73 per cluster
Spot for interruptible workCI runners, batch jobs, anything with a retryUp to 70% on those workloads

3. Storage

CheckDecision ruleTypical saving
gp2 volumesEvery one of them, no exceptionsFlat 20%, live, no downtime
Unattached volumesState "available" means attached to nothing100% of the volume
Over-provisioned io1/io2 IOPSProvisioned IOPS far above observedOften large
Snapshots with no source volumeSource volume gone means nothing will restore from it100%
No snapshot lifecycle policyData Lifecycle Manager is freeCaps a growing line
Deregistered AMIs with live snapshotsDeregistering an AMI does not delete its snapshots100%
S3 buckets with no lifecycle ruleEspecially log and backup bucketsVaries, often large
S3 versioning with no expiry on non-current versionsEvery overwrite kept foreverVaries
Incomplete multipart uploadsInvisible in the console, billed as storageOften surprising
EFS with no lifecycle policy$0.30 per GB-month in Standard~90% on cold data

4. Network

CheckDecision ruleTypical saving
S3 and DynamoDB gateway endpoints missingThey are free and remove that traffic from the NAT gateway$0.045 per GB of that traffic
Idle NAT gatewaysAny NAT gateway with negligible traffic$32.85 each per month
One NAT gateway per AZ in non-productionResilience nobody exercises in staging$65 per environment
Unassociated Elastic IPsCharged at $3.60 a month whether used or not$3.60 each
Public IPv4 on instances that do not need itBehind a load balancer or VPN$3.60 each
Idle load balancersNo targets, or no requests for 30 days$16 to $18 each
Unused VPN connections and Transit Gateway attachments$36 and $36.50 a month respectivelyPer resource
Cross-AZ chatter$0.01 per GB each way adds up on chatty servicesVaries
Egress without a CDNCloudFront both discounts the rate and cachesVaries

5. Databases and logging

CheckDecision ruleTypical saving
RDS Extended Support$0.10 per vCPU-hour on an out-of-support engine versionWhole fee, on upgrade
Multi-AZ on non-productionDoubles the instance cost for failover staging does not need50% of those instances
RDS gp2 storageSame 20% as EBS20%
Idle RDS instancesNear-zero connections over 14 days100%
Manual snapshots that outlived their instanceThey persist after deletion100%
Log groups set to never expireThe default on every log group ever createdStorage on the excess
VPC Flow Logs capturing ALL trafficOften the largest ingester in the accountLarge
Debug log levels in production$0.50 per GB ingestedProportional
Custom metric sprawl$0.30 per metric per monthProportional
Dashboards beyond the free three$3 each per monthSmall but free to fix

6. Account hygiene

CheckDecision ruleWhy it matters
Cost allocation tags activeAbove 30% untagged spend means you cannot attribute anythingEnables everything else
Cost Anomaly Detection configuredFree, ten minutes to set upCatches the next problem early
Budgets with alertsAt least one at your expected monthly totalTurns surprises into warnings
Support plan matched to useBusiness support is a percentage of spendWorth reviewing if tickets are rare
Resources in unexpected regionsAnything above a dollar outside your main regionsWhere orphans hide

The order matters more than the list

Every item here is real, but running them in the wrong order wastes effort. Committing before rightsizing locks in capacity you are about to delete. Migrating to Graviton before deleting idle instances means porting things you were going to throw away. Clean up, size correctly, then commit.

Put numbers on it

Frequently asked questions

How long does working through this take?

A focused day for the first four sections on a single-account estate, assuming Cost Explorer and Compute Optimizer are already enabled. The long tail, meaning every region, every log group and every snapshot chain, is where the time goes and where automation earns its keep.

Which checks are genuinely zero-risk?

Setting log retention, adding S3 and DynamoDB gateway endpoints, migrating gp2 to gp3, releasing unassociated Elastic IPs, deleting snapshots whose source volume no longer exists, and buying a one-year no-upfront Savings Plan sized below your baseline. None of those change how anything runs.

What is deliberately not on this list?

Anything that trades reliability for cost without saying so: removing Multi-AZ from production, dropping backup retention below your recovery requirement, or running production on Spot without a fallback. Those are business decisions rather than optimisations, and an audit that presents them as savings is misleading you.

Can I run these checks automatically?

Most of them. About seventy of the checks behind this list are scriptable against a read-only role, which is what our scanner does. The ones that are not, such as whether an instance at 4% CPU is idle or memory-bound, need someone to look at it, which is why the report is human-verified before it goes out.

Keep reading

Prices checked against AWS list rates on 2 August 2026. AWS changes prices; treat every figure here as a close approximation rather than a quote.

£499 fixed. Free scan first. 20%+ found or it’s free.

The scan is read-only — a role you create and delete, no keys shared — and shows your estimated monthly saving before anyone talks about money.