The challenge
A cloud programme had stalled twice on the regulator’s data-residency and evidence requirements.
Our approach
The programme had stalled twice, both times at the regulator, and both times because data residency and evidence had been treated as a compliance review at the end rather than a design input at the start.
We restarted from the landing zone: accounts, networking, identity, tagging, and guardrails, with the control mapping written for the auditor to read before a single workload moved.
“The third attempt worked because the regulator was in the room during design, not at the end.”
What we built
Workloads moved in five waves, each proving a class of problem — stateless first, then stateful, then the regulated data stores, then the batch estate, then the last two legacy systems that needed a connectivity plan rather than a migration.
Evidence collection was automated into the platform. The audit pack is now generated rather than assembled, which removed roughly three weeks of effort per cycle.
- AWS
- Terraform
- HashiCorp Vault
- Datadog
- GitHub Actions
Results
Zero findings at the first post-migration review — the outcome the previous two attempts had failed to reach. Infrastructure cost fell 38% in year one, driven by rightsizing during migration rather than after it.
The bank now runs the landing zone with its own team. We provide a quarterly architecture review and nothing else.
What’s next
Two remaining legacy systems have a lifecycle plan through 2028. Neither should be migrated, and we said so.
Figures are taken from the client’s own reporting and published with their permission. We will introduce you to them on request.