TL
The short answer

Shared costs on AWS are untangled by starting from the Cost and Usage Report, switching from blended to amortized cost, and allocating each non attributable line with a written rule. The usual culprits are data transfer between availability zones and regions, NAT gateway processing, shared services and security accounts, support fees, and the discount from Savings Plans and Reserved Instances bought centrally. Each has a natural driver you can allocate against, and once you do, the unallocated bucket shrinks from a large unexplained number to a small disclosed overhead everyone accepts.

The reason this matters: you cannot hold a team accountable for spend it cannot see, and you cannot make a sound commitment decision while a quarter of the bill is floating. Here is the order of operations that works.

Where do shared costs come from on AWS?

The Cost and Usage Report is the source of truth, and it makes the problem visible the moment you group by tag and find a large untagged remainder. That remainder is mostly five things. Data transfer is the quiet leader: traffic between availability zones, between regions, and out to the internet rarely carries a team tag, and NAT gateway processing charges ride alongside it. Shared services accounts holding logging, security tooling, and networking are billed centrally. Support fees scale with the estate but land in one place. And the discount from centrally purchased Savings Plans and Reserved Instances is spread across accounts in a way that hides who triggered it.

Tagging fixes part of this but never all of it, because some costs are genuinely shared. The goal is not to tag the untaggable, it is to allocate it with a key you can defend.

Use amortized cost, not blended cost

AWS gives you three cost measures in consolidated billing, and the choice changes every team's number. Blended cost averages the discounted rate across all accounts in the Organization, which is convenient and misleading, because it makes a heavy committer look the same as a team that bought nothing. Unblended cost shows each account the rate it actually paid. Amortized cost spreads the up front and recurring portions of commitments across the periods they cover.

For allocation, use amortized cost. It is the only measure that charges a team the effective rate for what it ran rather than the accident of when finance purchased a commitment. Blended cost is the single most common reason a shared cost allocation does not survive scrutiny: a team disputes its number, you trace it, and discover the figure was an Organization wide average that never described their usage.

The rule

Allocate on amortized, unblended cost. Reserve blended cost for nothing in showback. The day you switch, expect some teams' numbers to move sharply, which is the distortion you were carrying all along becoming visible.

Allocate each shared line with a documented key

Once you are on amortized cost, attack the remainder line by line. The principle is the same as anywhere in FinOps: pick a key that tracks the real driver of the cost and apply it identically every month.

Shared costDriverAllocation key
Inter AZ and inter region transferTraffic volumeProportional to each team's measured data movement
NAT gateway processingOutbound traffic through the gatewayBy the workloads routed through each NAT
Shared services and security accountsEstate footprint protectedProportional to each team's compute and storage
Support feesSize of estate consumedProportional to each team's amortized spend
Central Savings Plan and RI discountResources running under the commitmentAmortized cost attributes it automatically

Note that the commitment discount mostly allocates itself once you use amortized cost, because the Cost and Usage Report attributes the covered usage to the account that ran it. That removes the largest and most contentious piece of the puzzle before you start hand allocating anything.

Reduce shared cost, do not just allocate it

Allocation makes the cost visible and owned, but the bigger prize is shrinking it. Data transfer and NAT gateways are classic quiet budget eaters, and once a team sees its true network share it usually finds architecture changes worth making, such as VPC endpoints, regional consolidation, or moving chatty services into the same availability zone. Logging volume often turns out to be the driver behind both transfer and storage. The point of untangling is to turn an unowned number into a number a team can act on this week.

Worked example

A Fortune 500 retailer ran roughly a fifth of its AWS bill as unallocated shared cost. Moving to amortized cost attributed the bulk of the commitment discount automatically. Allocating transfer by measured egress exposed two data heavy teams that had assumed network was free, and they cut their share materially within a quarter by adding VPC endpoints and consolidating cross region replication. The unallocated bucket fell to a small, disclosed central overhead. Figures are verified against billing data and anonymized.

Where this fits in the AWS estate

Untangling shared costs is the foundation for accountable budgets and sound commitment decisions across AWS. It pairs directly with disciplined tagging and a clean account structure. Read tagging for cost allocation on AWS to get the inputs clean, and multi account strategy and cost control for the structure that makes allocation tractable. The whole estate picture lives in the AWS cost optimization guide.

Frequently asked questions

What counts as a shared cost on AWS?
Any cost that does not attach cleanly to one team: data transfer between availability zones and regions, NAT gateway processing, shared services accounts, security and logging tooling, support fees, and the discount from centrally purchased Savings Plans and Reserved Instances.
What is the difference between blended and unblended cost?
Blended cost averages the discounted rate across all accounts in an Organization and hides who triggered a commitment. Unblended cost shows each account the rate it actually paid. For allocation, use unblended or amortized cost so commitment benefit follows the account that consumed it.
How do you allocate shared Savings Plan discounts fairly?
Use amortized cost from the Cost and Usage Report, which spreads each commitment across its term and attributes the discount to the resources that ran under it, so a team is charged the effective rate for what it used.

Untangle your AWS bill with us

We help enterprises turn an unowned shared cost bucket into accountable, defensible numbers and then cut the spend underneath it. Our guarantee: we reduce your cloud spend or we reimburse our service fee. Pricing is either a Fixed Fee scoped up front or Gainshare, a share of verified savings with no retainer and no risk.

Independent · buyer-side

Put a defensible number on your cloud spend.

No provider in the room, no published price list. Tell us your footprint and we will scope the savings against your billing data — we reduce your cloud spend or we reimburse our service fee.

Buyer-side intelligence, monthly.

The Cloud Spend Navigator: what changed in cloud pricing, commitments, and FinOps — no vendor spin.