Special topics

Cloud cost due diligence: reading the bill before the deal

Cloud cost due diligence is the part of a technical review that reads the target's cloud invoices for the last twelve months, works out what the system costs to run per unit of usage, and finds the commitments, the waste and the growth curve that the deck does not show. The bill is the one engineering artefact nobody can argue with: it is what the provider charged. Flexera's 2026 State of the Cloud survey of more than 750 cloud decision-makers estimated 29 percent of cloud spend as waste, and a target's share of that is a repair bill the buyer can price before close instead of discovering after.

Published July 27, 2026. Updated September 17, 2026. Editorial.

Key takeaways

  • Ask for twelve months of invoices by account and by service, plus every commitment contract with its end date, because the bill is the only cost record that cannot be presented.
  • Cost per unit of usage over the year is the number that matters; total spend rising is expected, and unit cost rising is a margin problem.
  • Commitments such as AWS Savings Plans and Google Cloud committed use discounts run for one or three years and transfer with the account, so their expiry dates belong in the report.
  • Flexera's 2026 survey put estimated cloud waste at 29 percent, and a target that has never looked for idle resources has that share waiting to be found.

Cloud cost due diligence reads what the target actually paid to run its software, month by month, and turns that into three findings: what the system costs per unit of usage and where that number is heading, what commitments the buyer inherits and when they expire, and how much of the bill is waste that a competent team would already have removed. Every one of those has a price, and every one is invisible in a pitch deck.

The bill is the right starting point because it is the only engineering record that the target cannot write for the reviewer. Architecture diagrams are drawn, roadmaps are planned, and test coverage is claimed. The invoice is what AWS, Google Cloud or Microsoft charged. Reveneau's diligence request asks for twelve months of invoices by account and by service, every commitment contract with its term and end date, and the target's own cost per unit of usage over the same period, and the review starts by checking whether the third reconciles with the first two.

For how the cloud bill fits the wider architecture review, read assessing architecture and scalability. For the AI-specific version of this problem, where inference spend can swallow gross margin, the AI startup guide's page on rebuilding inference gross margin from invoices does the arithmetic. The pillar guide places both.

Why does the cloud bill belong in technical due diligence?

The cloud bill belongs in technical due diligence because it is where architecture decisions become money, and because cost management has become a discipline that a target either practises or does not. The FinOps Foundation's State of FinOps 2026 survey, with 1,192 respondents representing more than $83 billion in annual cloud spend, found that 98 percent of respondents now manage AI spend, up from 63 percent in 2025 and 31 percent in 2024. A target with no one watching the bill is behind a practice the rest of the market has adopted.

The bill also measures waste directly. Flexera's 2026 State of the Cloud Report, announced 2026-03-18 from a survey of more than 750 cloud decision-makers and users, estimated wasted cloud spend at 29 percent, the first rise in that figure in five years, and 81 percent of respondents reported using generative AI. Both surveys are of practitioners across many companies, so neither says anything about a specific target; what they say is that waste is normal and that a reviewer who does not look for it is leaving a known quantity unpriced.

What should the reviewer ask for?

The reviewer should ask for three things: the invoices, the commitments, and the target's own unit cost calculation. Each is a document that already exists, or should.

  1. Twelve months of invoices by account and by service. Every provider produces these. On AWS, the Cost Explorer console shows up to 13 months of historical data and forecasts 18 months forward, and the same dataset can be exported as a cost and usage report. Ask for the export, and ask for read access to the console so the reviewer can check the export against the source.
  2. Every commitment contract. AWS Savings Plans are a commitment to a specified amount of compute per hour "for a one or three year period" in exchange for rates below on-demand, with AWS stating savings of "up to 72%" on compute. Google Cloud's committed use discounts run "one or three years" for most spend-based commitments and up to six years for Compute Engine resource-based ones. These are contracts. They transfer with the account, they expire on a date, and an expiry in month four of ownership changes the bill in month five.
  3. The target's cost per unit of usage. Per customer, per tenant, per transaction, per thousand requests, whichever unit the business sells. If the target cannot produce this, that is the first finding, because it means nobody has connected the bill to the revenue.

Ask also for the account structure: how many accounts, who owns each, and whether any production workload runs in an account owned by an individual rather than the company. The account list is where a reviewer finds the personal credit card that has been quietly paying for a critical service for three years.

How do you read twelve months of a cloud bill?

Read the bill in four passes: the trend, the mix, the commitments, and the unit cost. Each pass takes an hour with the export open in a spreadsheet, and together they produce most of the findings.

The trend. Plot monthly total spend against monthly usage (customers, requests, whatever the unit is). Spend should track usage. Spend rising while usage is flat means either waste accumulating or an architecture that scales badly. A step change in one month has a cause: a migration, a new feature, a runaway process. Ask for it.

The mix. Break the bill into compute, storage, data transfer, managed databases, and everything else, and watch the shares move. Data transfer growing faster than the rest often means a design that moves data between regions or out to the internet more than it needs to. Storage that never shrinks means nothing is ever deleted. A large "other" line means services nobody is tracking.

The commitments. Lay the commitment contracts over the compute line. A target with commitments covering most of its steady compute is buying at the discounted rate. A target with none is paying on-demand for a predictable load. A target whose commitments exceed its usage is paying for capacity it does not use, which is waste with a signature on it. Note every end date in the report.

The unit cost. Divide monthly spend by monthly units and plot it. This is the line that goes into the findings. Falling unit cost means the architecture scales. Flat is fine. Rising unit cost means every new customer costs more to serve than the last, and the gross margin in the model is wrong.

What counts as waste, and how much is normal?

Waste is any resource that costs money and serves no running workload, and Flexera's practitioner survey puts the estimated share at 29 percent of spend for 2026. The common shapes are idle compute instances, storage volumes no longer attached to anything, snapshots kept past any retention rule, development environments running around the clock, and over-provisioned databases sized for a peak that never came.

The reviewer only needs to know whether the target has looked. Ask when the last cost review happened, what it found, and what was removed. A target that answers with dates and numbers has a practice. A target that answers "we keep an eye on it" has not looked, and the 29 percent figure is the reason to assume waste is there until shown otherwise.

Turn the finding into a number the way the report template asks for: an observation with a location ("14 instances in the staging account have averaged under 3 percent utilisation for 90 days"), a verification method (read from the console), a severity, and a cost, which for waste is negative: it is money the buyer recovers. Recoverable waste is one of the few diligence findings that improves the price case rather than damaging it, so it deserves to be written up with the same care.

What does AI spend do to the cloud bill?

AI spend adds a line that grows with usage in a way traditional compute often does not, and it is the fastest-moving part of the bill in the two surveys above. FinOps Foundation respondents managing AI spend went from 31 percent in 2024 to 98 percent in 2026, which is a discipline forming in real time, and Flexera found 81 percent of respondents using generative AI.

For a target that sells AI features, model inference is a cost of goods sold, and the reviewer's job is to rebuild gross margin from the invoices rather than accept the deck's figure. Bessemer's The State of AI 2025 (2025-08-13) reported that the fastest-growing AI companies it studied had "only 25% gross margins", and ICONIQ's State of AI 2026 (July 2026, surveys of over 300 executives) put average gross margin at 45 percent in 2025 with projections of 53 percent in 2026 and 59 percent in 2027. Those are market surveys, and the target's own number comes from its own invoices. The inference gross margin page walks through the calculation, and SaaS metrics versus engineering reality covers what to do when the rebuilt margin and the presented margin disagree.

Ask separately for the model provider invoices if inference runs through a third party rather than the cloud account, and for any committed spend with that provider. A commitment to a model vendor is an inherited contract in the same way a savings plan is, and it is easier to miss.

What goes in the report?

The report carries four cloud cost findings at minimum: the unit cost trend with its direction, the inherited commitments with end dates and the change in the bill when each expires, the recoverable waste with a value, and any dependency on an individual's account or card. Each goes in the findings section with a verification method and a cost, and the High and Critical ones (a rising unit cost, a commitment expiring inside the first year, production in a personal account) go to the risk register.

For the value creation plan after close, the cloud bill is also the fastest first win. Removing idle resources and buying commitments for steady load are two changes that a new owner can make in the first quarter, and the technology workstream in a 100-day plan puts them on the schedule. The review that found them is what makes that possible.

Best for

  • Investors in any company whose product runs on a public cloud
  • Growth and buyout deals where the gross margin case depends on infrastructure cost
  • AI companies where inference is a cost of goods sold

Avoid if

  • The target runs on its own hardware, where the review is a data centre and depreciation question
  • The deal is a pre-seed cheque and the bill is a few hundred dollars a month

Verify before you commit

  • The invoice export against the provider console, with read access
  • The target's unit cost against spend divided by units from the invoices
  • Every commitment contract against its line on the bill and its end date

Common questions

What is cloud cost due diligence?

Cloud cost due diligence is the part of a technical review that reads the target's cloud invoices for twelve months, calculates cost per unit of usage and its trend, lists the commitment contracts the buyer inherits with their end dates, and estimates recoverable waste. Flexera's 2026 State of the Cloud survey of more than 750 practitioners estimated waste at 29 percent of cloud spend, so the last item is rarely zero.

What documents should an investor ask for in cloud cost due diligence?

Ask for twelve months of invoices by account and by service, every commitment contract with its term and end date, the target's own cost per unit of usage, and the list of accounts with their owners. On AWS, Cost Explorer holds up to 13 months of history and the same dataset exports as a cost and usage report, so the invoices are available to any target that asks for them.

Why is cost per unit of usage the key cloud cost metric in a deal?

Cost per unit of usage is the key metric because total spend grows with the business while unit cost should stay flat or fall. Falling unit cost means the architecture scales; rising unit cost means each new customer costs more to serve than the last and the gross margin in the model is overstated. Divide monthly spend by monthly units from the invoices and plot the twelve months.

What are cloud commitments and why do they matter to a buyer?

Cloud commitments are contracts to use a set amount of compute for a fixed term in exchange for lower rates. AWS Savings Plans run for one or three years and AWS states savings of up to 72 percent on compute; Google Cloud committed use discounts run one or three years, or up to six for Compute Engine resource-based commitments. They transfer with the account and their expiry changes the bill, so end dates belong in the report.

How much cloud waste is normal?

Flexera's 2026 State of the Cloud Report, announced 2026-03-18 from a survey of more than 750 cloud decision-makers, estimated wasted cloud spend at 29 percent, the first rise in five years. That is a market-wide practitioner estimate rather than a measurement of any one company, so the reviewer's question is whether the target has looked for waste and what it found, and 29 percent is the reason to assume waste exists until shown otherwise.

Is cloud waste a negative finding or a positive one for the buyer?

Recoverable cloud waste is one of the few diligence findings that improves the buyer's case, because it is money a new owner can stop spending in the first quarter. Write it up like any other finding, with the location, the verification method and a value, and mark the cost as recoverable. Idle instances, unattached storage and round-the-clock development environments are the usual sources.

How does AI inference spend change cloud cost due diligence?

AI inference is a cost of goods sold that grows with usage, and the reviewer rebuilds gross margin from the invoices rather than accepting the deck. Bessemer's State of AI 2025 (2025-08-13) reported 25 percent gross margins at the fastest-growing AI companies it studied, and ICONIQ's State of AI 2026 (July 2026) put the average at 45 percent for 2025. The target's number comes from its own model provider invoices.

Do most companies manage their AI cloud spend?

The FinOps Foundation's State of FinOps 2026 survey, with 1,192 respondents representing more than $83 billion in annual cloud spend, found 98 percent of respondents now manage AI spend, up from 63 percent in 2025 and 31 percent in 2024. A target with nobody watching its AI or cloud bill is behind a practice that has become standard among the companies surveyed.

What is the biggest cloud cost red flag in a deal?

Production workloads running in an account owned by an individual rather than the company, often paid on a personal card, is the finding that goes straight to the risk register, because the asset depends on a person's continued goodwill and credit limit. A rising unit cost and a commitment expiring inside the first year of ownership are the other two findings rated High or Critical.

Can cloud cost findings feed the post-close plan?

Yes. Removing idle resources and buying commitments for steady load are two changes a new owner can make in the first quarter, and the diligence review is what identifies them. Flexera's 29 percent waste estimate for 2026 suggests the first is rarely empty, and AWS's stated savings of up to 72 percent on committed compute suggests the second is worth the contract for any predictable load.

More in Special topics

Engineering artefacts for the data room: what goes in which folder

The engineering artefacts an investor should ask for in the data room are the documents and access grants that let a reviewer verify the technology instead of hearing about it: the repository inventory, the architecture as it exists, the incident log, the delivery metrics, the security reports, the open source inventory, the cloud invoices, and the engineer roster. Standard data room guidance covers none of this. a16z's guide to data rooms lists five categories to include and five to leave out, and engineering appears in neither list. This page is written for the investor requesting the room; the founder assembling it has a separate page in the preparation guide.

Open source licence due diligence

Open source licence due diligence is the part of a technical review that finds out which open source components a company's software contains, what each component's licence requires in return, and whether any of those requirements attach to the company's own code. The risk with a name is copyleft: a licence that says anyone who distributes a modified version must offer the source of the whole work under the same terms. Morgan Lewis's June 2026 note on M&A diligence lists the written policy, the inventory, the scans and the copyleft approval process as the things buyers ask about, and this page explains each in plain words for an investor who is not a lawyer.

SaaS metrics versus engineering reality: when the ARR and the codebase disagree

SaaS metrics and engineering reality disagree when the numbers in the deck describe a business the software cannot deliver: an ARR figure that includes services revenue the platform does not produce, a gross margin that leaves out the cloud bill, a churn rate that the incident log contradicts, or a roadmap the delivery metrics say will take three times as long. Technical due diligence is where those disagreements are found, because it is the only workstream that reads both the model and the system. This page lists the six places the two most often diverge, what artefact settles each one, and how to write the difference up as a finding the deal can price.