Overview & Roles
AI Cost Governance is the module in FinOps Center that manages the full lifecycle of AI workload costs — from approving a model for use, through IAM configuration, to weekly spend review and cost allocation.
This section of the user guide covers all six pages of the AI Governance module and is organized by role. Each page describes what a specific role sees, what actions they take, and what happens next in the workflow.
Before You Start
AI Cost Governance requires three roles to be filled in your organization. The workflow will not complete unless each role acts on their step.
FinOps Lead
Model approval, scope definition, allocation policy, Allocation Gap remediation
AI Governance page → AI Models, AI Tasks, Allocation Gaps
Cloud Engineer
IAM role creation, Bedrock model access configuration, task completion
AI Governance page → AI Tasks
Product Owner
Workload registration, IAM role claiming, token estimates, weekly spend acceptance
Spaces → Add Workload wizard; weekly Spend Cards
None of these roles requires direct AWS console access to complete their part of the workflow — FinOps Center surfaces the information and generates the commands each role needs.
The End-to-End Flow
The governance workflow moves left to right. Each step produces something the next role consumes.
FinOps Lead Cloud Engineer Product Owner
───────────────── ────────────────── ──────────────────────────
1. Review model 3. Pick up task 5. Open Spaces wizard
catalog from AI Tasks 6. Select approved model
2. Approve model 4. Create IAM role 7. Claim IAM role
for account × with condition 8. Set token estimate
region scope key 9. Accept weekly spend
4b. Mark Implemented card each periodSteps 1–2 are covered in Model Governance. Steps 3–4 are covered in Cloud Engineer Tasks. Steps 5–9 are covered in Workload Setup & Estimates and Weekly Spend Cards.
Allocation Gaps — spend that falls outside the governed workflow — are covered in Allocation Gaps and are handled by the FinOps Lead.
Terminology
Use these terms consistently. Incorrect terms are noted so you can recognize them if they appear elsewhere.
FinOps Lead
Admin (this is an internal Cognito role name, not a user-facing term)
Product Owner
End User
Allocation Gap
Non-Compliance, Compliance Violation
Workload Attribution
Workload Tagging
AI Cost Governance
AI Compliance, AI Spend Governance
Availability Requirement
Inference Endpoint Type
Last updated