Appendices
A. Glossary
| Term | Definition |
|---|---|
| FinOps | Financial Operations: a cultural practice combining finance, technology, and business for cloud cost management |
| FOCUS | FinOps Open Cost and Usage Specification: open standard for normalising billing data across providers (v1.4, Dec 2025) |
| CUR | Cost and Usage Report: AWS's detailed billing data export |
| RI | Reserved Instance: discounted pricing for committed usage (1yr or 3yr) |
| SP | Savings Plan: flexible discount model (AWS/Azure) based on committed spend per hour |
| CUD | Committed Use Discount: GCP's equivalent of Reserved Instances |
| EDP | Enterprise Discount Programme: volume-based discount agreement with a cloud provider |
| TBM | Technology Business Management: framework for IT cost allocation and reporting |
| ITAM | IT Asset Management: discipline for managing software licences and IT asset lifecycle |
| GreenOps | Applying FinOps principles to cloud carbon emissions and sustainability |
| Showback | Making cloud costs visible to teams without financial consequences |
| Chargeback | Allocating cloud costs back to teams as actual P&L charges |
| Unit Economics | Cost per unit of business output (transaction, customer, API call) |
| Rightsizing | Matching resource size to actual utilisation (targeting <40% avg CPU) |
| Tag Compliance | Percentage of cloud resources with required cost allocation tags |
| Zombie Resource | Cloud resource that exists but serves no active purpose |
| Egress | Data transfer charges for traffic leaving a cloud region or provider |
| NAT Gateway | Network Address Translation gateway (significant hidden cost in AWS) |
| Drift Detection | Comparing actual cloud state to declared infrastructure-as-code state |
| DORA | Digital Operational Resilience Act: EU regulation affecting UK banks' cloud operations |
B. AWS / Azure / GCP Service Name Mapping
| Category | AWS | Azure | GCP |
|---|---|---|---|
| Compute (VMs) | EC2 | Virtual Machines | Compute Engine |
| Containers (managed K8s) | EKS | AKS | GKE |
| Serverless compute | Lambda | Functions | Cloud Functions |
| Object storage | S3 | Blob Storage | Cloud Storage |
| Block storage | EBS | Managed Disks | Persistent Disk |
| Managed relational DB | RDS / Aurora | SQL Database | Cloud SQL / AlloyDB |
| NoSQL | DynamoDB | Cosmos DB | Firestore / Bigtable |
| Data warehouse | Redshift | Synapse Analytics | BigQuery |
| ML platform | SageMaker | Azure ML | Vertex AI |
| LLM APIs | Bedrock | Azure OpenAI | Vertex AI |
| Cost management | Cost Explorer | Cost Management | Billing Console |
| Cost advisor | Trusted Advisor / Compute Optimiser | Azure Advisor | Recommender |
| IaC native | CloudFormation | ARM / Bicep | Deployment Manager |
| CDN | CloudFront | Azure CDN | Cloud CDN |
| DNS | Route 53 | Azure DNS | Cloud DNS |
| Private connectivity | Direct Connect | ExpressRoute | Cloud Interconnect |
| Commitment pricing | RI + Savings Plans | RI + Savings Plans | Committed Use Discounts |
| Billing data export | CUR (Cost and Usage Report) | Cost Management Exports | Billing Export to BigQuery |
C. RACI Printable Matrix
The matrix below is designed for printing and posting in team areas. R = Responsible (does the work). A = Accountable (owns the outcome). C = Consulted (provides input). I = Informed (kept in the loop). Each activity has exactly one A.
| # | Activity | FinOps | Eng. | Finance | Product | Procure. | Exec. |
|---|---|---|---|---|---|---|---|
| 1 | Tagging strategy design | R/A | C | C | I | I | I |
| 2 | Tagging enforcement (code) | C | R/A | I | I | I | I |
| 3 | Anomaly detection/response | R/A | C | I | I | I | I |
| 4 | Right-sizing recommendations | C | R/A | I | I | I | I |
| 5 | RI/SP/CUD procurement | R | C | C | I | A | I |
| 6 | Budget forecasting | R/A | C | C | C | I | I |
| 7 | Showback/chargeback | R | C | A | C | I | I |
| 8 | Architecture cost review | C | R | I | C | I | A |
| 9 | Policy-as-code (Terraform) | C | R/A | I | I | I | I |
| 10 | AI/ML cost governance | R/A | C | C | C | I | I |
| 11 | SaaS rationalisation | C | I | C | C | R/A | I |
| 12 | Zombie resource cleanup | C | R/A | I | I | I | I |
| 13 | Network cost optimisation | C | R/A | I | I | I | I |
| 14 | Unit economics reporting | R | C | C | A | I | I |
| 15 | Vendor relationship mgmt | C | I | C | I | R/A | I |
D. Document Version History
This guide is a living reference. Each version records what changed and why, so a reader holding an older copy can tell what has been superseded.
Version 2.1 | September 2026
Sourcing and publication review, in three parts. First, passages that described findings as though they came from named engagements were rewritten so that every figure traces to a published benchmark, a documented industry finding, or a stated general mechanism; one unsourced figure was removed rather than reattributed, and the executive summary now attributes its headline waste range rather than asserting an outcome. Second, Section 7 was rewritten to be descriptive rather than evaluative: per-institution maturity stages and the comparative maturity ratings were removed, and commentary on outsourcing incentives is now framed structurally rather than against named suppliers. The profiles retain the public facts and drop the judgements, which no outside party is positioned to make. Third, the cover carries authorship and this version history appendix completes the appendix sequence listed in the contents.
Version 2.0 | April 2026
Eleven sections with appendices A to H: cloud cost taxonomy across AWS, Azure and GCP; the five-layer reference architecture; roles, personas and the 15-activity RACI matrix; the four-phase culture change programme; the tool landscape; Terraform as a provisioning-time control; the UK banking and financial services landscape; industry standards including FOCUS, TBM, ITAM and GreenOps; gap analysis; key players; and twelve recommendations by maturity stage.
E. Tool Comparison Matrix
The matrix below summarises the 20+ tools discussed in Section 5, mapped against the five-layer architecture. Use this to identify which tools cover which layers and where gaps exist in your current toolset.
| Tool | Layer 1 | Layer 2 | Layer 3 | Layer 4 | Layer 5 | FOCUS |
|---|---|---|---|---|---|---|
| AWS Trusted Advisor | Yes | Partial | No | Yes | No | N/A |
| Azure Advisor | Yes | No | No | Yes | No | N/A |
| GCP Recommender | Yes | No | No | Yes | No | N/A |
| Terraform + Infracost | Yes | No | No | Yes | No | N/A |
| CloudBolt | Yes | No | No | Yes | Partial | Yes |
| Nerdio | No | No | Yes | No | No | No |
| Karpenter | No | No | Yes | Partial | No | No |
| ParkMyCloud | Yes | No | Yes | No | No | No |
| CAST AI | No | No | Yes | Yes | No | No |
| Spot by NetApp | No | No | Yes | Yes | No | No |
| Kubecost | No | No | Partial | Yes | Partial | No |
| Apptio Cloudability | Partial | No | No | Partial | Yes | Yes |
| CloudHealth | Partial | No | No | Partial | Yes | Partial |
| Finout | No | No | No | Partial | Yes | Yes |
| Vantage | No | No | No | Partial | Yes | Yes |
| CoreStack | Partial | No | No | Partial | Yes | Yes |
| Cloudaware | Partial | No | No | No | Yes | Partial |
| Ternary | No | No | No | Partial | Yes | Yes |
| CloudZero | No | No | No | Partial | Yes | Partial |
| AWS Cost Explorer | No | No | No | Partial | Partial | N/A |
| Azure Cost Mgmt | No | No | No | Partial | Partial | N/A |
Key: Yes = primary capability. Partial = some coverage but not primary strength. No = not covered. N/A = not applicable (native tools). The typical enterprise deployment uses 2-4 tools spanning all five layers. No single tool covers all five.
F. FinOps Maturity Assessment Checklist
Use this checklist to assess your organisation's FinOps maturity stage. Answer each question honestly. If more than half your answers fall in a single column, that is your current stage.
| Capability | Crawl | Walk | Run |
|---|---|---|---|
| Tagging compliance | Below 70% | 70-90% | Above 90% |
| Cost attribution | Cannot attribute 30%+ of spend | Attribute 80%+ to teams | 100% attributed to products |
| Forecasting accuracy | Beyond 25% | Within 15% | Within 8% |
| Anomaly detection | Manual or none | Automated alerts | Auto-remediation |
| Engineering engagement | Finance-only reviews | Engineers attend reviews | Engineers own cost OKRs |
| Recommendation action rate | Below 30% | 30-60% | Above 70% |
| Commitment coverage | Below 40% | 40-65% | Above 65% |
| Unit economics | Not tracked | Top 5 products | All products |
| FinOps tooling | Native only | One platform + specialists | Integrated multi-tool estate |
| AI cost governance | Not tracked | Measured but not governed | Per-team budgets and tracking |
| SaaS management | Unknown licence count | Inventory exists | Quarterly rationalisation |
| Executive reporting | Ad-hoc or none | Monthly governance pack | Real-time dashboards |
G. Customer Discovery Interview Scripts
These scripts support the gap analysis in Section 9. Use them to validate whether the four identified gaps are real problems for your target organisations.
Script 1: FinOps Lead / Cloud Economist (30 minutes)
Opening: 'We are researching how financial services organisations manage cloud costs. I would like to understand your current approach, what works, and where the gaps are. There are no right answers. I am trying to learn from your experience.'
Q1. How many cloud providers does your organisation use, and roughly what is your annual cloud spend? (Establishes scale and complexity.)
Q2. Walk me through what happens when your monthly cloud bill arrives. Who sees it first? How long before engineering teams see their share? (Tests Layer 5 maturity: is there a governance process or a CSV-and-email chain?)
Q3. What percentage of your cloud resources are tagged with a cost-centre or team owner? How do you enforce that? (Tests the tagging foundation. Below 70% means significant attribution gaps.)
Q4. When a rightsizing recommendation appears in your FinOps tool, what happens next? Does it become a ticket? Who acts on it? How long does that typically take? (Tests the visibility-to-action bridge.)
Q5. How do you forecast cloud spend for next quarter? What inputs do you use? How accurate was your last forecast? (Tests Layer 4. If accuracy is beyond 15%, forecasting is broken.)
Q6. Do you manage AI/ML costs separately from cloud compute? If so, how? If not, is it becoming a concern? (Tests Gap 3: AI cost governance.)
Q7. Do you have workloads running in specific regions for regulatory reasons even though a different region would be cheaper? How do you account for that cost difference? (Tests Gap 2: regulatory-aware FinOps.)
Q8. What is the single biggest frustration in your FinOps practice today? (Open-ended. Often reveals the real gap rather than the assumed one.)
Script 2: Head of Engineering / VP Platform (20 minutes)
Q1. When your engineers provision cloud resources, what guardrails exist? Terraform modules? Instance size limits? Mandatory tags? (Tests Layer 1 preventive controls.)
Q2. How do your engineers currently learn about the cost impact of their architectural decisions? In a PR? In a sprint retro? In a monthly report? Never? (Tests shift-left maturity.)
Q3. If I said your dev environments cost $X per month and only 60% are actively used, would that surprise you? What would you do about it? (Tests zombie resource awareness.)
Q4. Do your engineers feel responsible for cloud costs, or is that someone else's problem? (Tests culture change phase.)
Script 3: CFO / Finance Director (15 minutes)
Q1. How does cloud spend appear in your P&L? As a single IT line? Allocated to business units? Per-product? (Tests chargeback maturity.)
Q2. Can you tell me the cloud cost per transaction for your top three products? (Tests unit economics maturity.)
Q3. What would you need from your FinOps function that you are not getting today? (Open-ended. Finance leaders will often name forecasting accuracy and cost attribution as gaps.)
Q4. How do you handle cloud cost variance in your quarterly forecasting? What is your typical variance? (Tests whether cloud costs are integrated into financial planning or treated as an unpredictable line item.)
Q5. If cloud spend increased 20% next quarter, how would you determine whether that increase was justified? (Tests whether the organisation has unit economics or relies on absolute numbers.)
Using the scripts effectively
Run all three scripts within the same organisation to triangulate. The FinOps Lead will describe the practice from an operational perspective. The VP Engineering will describe it from a delivery perspective. The CFO will describe it from a financial perspective. Discrepancies between the three perspectives reveal the real gaps. If the FinOps Lead says tagging compliance is 85% and the VP Engineering says 'I have no idea what our tagging compliance is,' the gap is not tagging. It is communication.
Record responses (with permission) and categorise into the four gap areas. Count how many interviewees independently mention each gap. If eight out of ten FinOps Leads mention regulatory constraints on cost optimisation, Gap 2 is validated. If two out of ten mention it, it may be a niche problem rather than a market opportunity. The threshold for gap validation: at least 40% of interviewees in the target segment should independently identify the problem without prompting.
H. Key References
State of FinOps 2026 Report, data.finops.org
FinOps Framework 2025, finops.org/framework
FOCUS Specification v1.4, focus.finops.org
Flexera 2025 State of the Cloud Report, flexera.com
Gartner Market Guide for Cloud Financial Management Tools 2025
Deloitte TMT Predictions 2025: FinOps, deloitte.com
Harness FinOps in Focus 2025, harness.io
CloudZero AI Cost Research 2025, cloudzero.com
HashiCorp State of Cloud Strategy 2024
NatWest/AWS/Accenture announcement, newsroom.accenture.com (July 2025)
Lloyds at Google Cloud Next 2025, cloud.google.com
HSBC at FinOps X 2023, finops.org/insights
Barclays AI Strategy, home.barclays (July 2025)
Barclays Global Technology Conference, microsoft.com (December 2025)
Standard Chartered/Microsoft, fintechfutures.com
Barclays/HPE GreenLake, computerweekly.com
JPMorgan Investor Day 2022 filing
End of The Complete FinOps Reference Guide, Version 2.1
This document is a living reference. Subsequent versions will refine content based on practitioner feedback, update tool assessments, and incorporate findings from the FinOps Foundation's annual State of FinOps survey.
Prefer the whole thing as one document?
The full 58-page guide, formatted, with every section and all eight appendices. We send it by email the same working day.
Request the PDF