Financial billing and cost controls
In a cloud environment, setting up services can be as easy as providing a credit card number. Although this provides the benefit of making cloud services easy to enable and consume, this also adds risk in terms of business continuity (what if the credit card holder leaves the company?), as well as a company being financially liable for overages or the misuse of services (someone stands up a rogue server for crypto mining). Like controls in legacy environments that may check who is authorized to approve purchases at a given amount, this should be assessed within the cloud environment as well. Additionally, the IT auditor should ensure there are controls in place that allow an organization to limit potential cost overages and that proper alerting and notification are in place to monitor billing and cost status.
Depending on how the environment has been configured, some access controls may be defined around who can access billing and cost information...