What a cloud cost review actually looks like
A working agenda, not a maturity model.
Most published FinOps material describes an operating model. This describes a meeting — the one that has to happen monthly for any of the operating model to matter.
Before the meeting: three numbers
Total spend against last month. Total spend against forecast. And the largest single delta by service. If you cannot produce those three in advance, the meeting becomes a data-gathering exercise and nothing gets decided.
The delta is the agenda
Not the total. The total is context; the change is the thing that needs a name attached. Every significant delta should end the meeting with one of three outcomes: it was intended and the forecast was wrong, it was unintended and someone owns fixing it, or nobody knows and someone owns finding out before next month.
"Nobody knows" is a legitimate outcome once. Twice on the same line item means the ownership is wrong.
Untagged spend is a standing item
Whatever proportion of spend is untagged is the proportion you cannot attribute, and it only grows if it is not on the agenda. Report it as a percentage every month and treat a rising number as a process failure rather than a tooling one.
What not to do in the meeting
Do not optimise in the room. The temptation is to spot a large number and start redesigning something. The meeting exists to assign ownership; the work happens afterwards, by the people who own the service.
Cadence
Monthly for the review, quarterly for commitments and the audit checklist. More often than monthly and there is not enough signal above the noise; less often and a bad month compounds before anyone names it.