Cloud Cost Audit: Is Your Target Burning Cash on Inefficient Infrastructure?
In the world of SaaS M&A, the income statement often hides a silent EBITDA killer: unoptimized cloud infrastructure. For Private Equity (PE) and Venture Capital (VC) firms, "the cloud" is frequently treated as a utility—like electricity or water. You pay the bill, and the lights stay on.
But in a high-growth SaaS target, the cloud bill isn't just an expense; it's a window into the soul of the engineering organization. At Bad Cop, we’ve seen multi-million dollar deals where the target's AWS bill was growing 2x faster than their ARR. That isn't "scaling"; that's a structural failure in architecture.
If you aren't performing a rigorous cloud cost due diligence before signing the term sheet, you aren't just buying a company—you're inheriting a financial leak. Here is how to audit cloud infrastructure like a pro.
1. The "Unit Economics" of the Cloud
Most PE associates look at the total AWS or Azure spend. A "Bad Cop" looks at the Cost to Serve (CTS).
The Red Flag: A target that cannot tell you exactly how much it costs in infrastructure to support a single customer or a single transaction.
The Test: Ask the CTO: "What is your cloud cost per active user, and how has that trended over the last four quarters?"
What to look for: In a healthy SaaS business, cloud costs should benefit from economies of scale. If the cost per user is flat or increasing as they grow, the architecture is inefficient, and your margins will never expand post-acquisition.
2. The "Orphaned Resources" Audit
Startups move fast and break things. Usually, what they break is the "delete" button on expensive cloud resources.
The Red Flag: A massive "Other" or "Uncategorized" section in the AWS Cost Explorer.
The Test: Request a "Tagging Compliance Report."
What to look for: Every dollar spent should be tagged to a specific product, environment (Dev/Staging/Prod), or department. If 30% of the bill is untagged, you are paying for "zombie" servers, abandoned databases, and snapshots from 2022 that no one remembers creating. This is low-hanging fruit for immediate post-close EBITDA improvement.
3. Reserved Instances vs. On-Demand: The Commitment Gap
How a company buys its cloud capacity tells you everything about its financial maturity.
The Red Flag: A target paying 100% "On-Demand" rates for steady-state workloads.
The Test: Check the ratio of Reserved Instances (RIs) or Savings Plans to On-Demand spend.
What to look for: On-Demand is for testing; RIs are for business. If a target is purely On-Demand, they are effectively throwing 30-60% of their infrastructure budget out the window. While this represents a "quick win" for you post-close, it also signals a lack of operational discipline in the engineering leadership.
4. Architecture as a Cost Driver
Sometimes, high cloud costs aren't a billing issue; they are a code issue.
The Red Flag: Excessive data transfer (egress) fees or massive "Managed Service" costs (like RDS or Managed Kafka) that dwarf the actual compute spend.
The Test: "Walk me through your data retention policy and how it impacts your S3/Storage costs."
What to look for: We often find companies storing petabytes of logs "just in case," paying thousands a month to store data they will never read. A "Bad Cop" audit identifies these architectural bottlenecks where code is literally burning cash.
5. The "Exit-Ready" Infrastructure
If your goal is to flip the company in 3-5 years, you need to ensure the infrastructure isn't a proprietary mess that will scare off the next buyer.
The Red Flag: "Cloud-native" features that create extreme vendor lock-in without a clear performance benefit.
The Test: "How long would it take to migrate this workload to a different cloud provider or a private cloud environment?"
What to look for: You want to see Infrastructure as Code (IaC) like Terraform or Pulumi. If the infrastructure was built manually in the AWS Console, it's a "black box" that increases your technical risk and decreases your eventual exit valuation.
Summary: The Bad Cop Verdict
Cloud infrastructure is the largest line item in a SaaS COGS for a reason. During SaaS infrastructure audit, don't settle for "it's just the cost of doing business."
If the target's cloud spend is a mystery, your ROI will be too. You need to know if you're buying a streamlined engine or a gas-guzzler.
Is your target's AWS bill spiraling out of control?
We play the "Bad Cop" so you don't have to. We've audited hundreds of cloud environments for PE/VC firms, uncovering millions in hidden costs and architectural risks.
Book a free 15-minute screening at badcop.tech and let’s audit their infrastructure before you sign the check.