Multi-cloudNetworking4 min read

Avoid double-counting cloud network charges

Sources checked September 10, 2026Varies by scope
On this page

This check is due for a source refresh. Confirm the current documentation before you rely on provider-specific details.

THE SHORT ANSWER

Reconcile one closed invoice period and remove only confirmed repeated imports, or your network subtotal can understate valid spend. Keep distinct service charges on the same traffic path because matching bytes do not prove duplication.

What you need first

Tool
Use a read-only file or table viewer for existing AWS Cost and Usage Reports, Azure cost-details files and Google Cloud Billing exports. For Google Cloud, the standard export is a BigQuery table.
Access
Ask an authorized billing colleague for read-only billing records and invoice documents covering the agreed accounts and closed period. Ask a network engineer for the corresponding traffic-path map.
If you do not use that tool
Give your billing colleague the provider accounts, closed invoice period, currency and tax scope. Ask for the completed reconciliation, network subtotal and unresolved lines, with a network engineer mapping each unexplained service charge.

Why this is worth a look

Deleting lines with matching traffic volumes can hide valid costs. Google Cloud Armor Enterprise data processing is billed per GiB transferred to the internet, separately from Cloud Load Balancing data processing and in addition to other data transfer fees. AWS inter-Region and inter-Availability Zone transfer costs are metered per Gigabyte. Azure says every cost-details record should be considered unique, so these records and units cannot be treated as interchangeable charges.

Run this check

CHECKLIST

Use existing billing records and invoice documents in a read-only file or table viewer. Review one closed invoice period per provider, keeping reported units and currencies separate.

Read-only network charge reconciliation
NETWORK CHARGE RECONCILIATION

SCOPE AND INPUTS
[ ] Record the provider, account scope, closed invoice period, currency and tax treatment. Keep a separate review for each provider and currency.
[ ] Obtain read-only billing records and invoice documents from an authorized billing colleague, plus a traffic-path map from a network engineer. Do not change exports or resources.
[ ] Record each input file or table and the period it covers. Preserve original records so review notes can be traced to their source.

1. VERIFY COVERAGE
[ ] Confirm that inputs cover the full selected invoice period. If they do not, label the subtotal partial and request complete records before reconciling it.
[ ] For Google Cloud regional exports, check when export began and whether it was disabled. Data is available from enablement, and disabled intervals might be missing.
[ ] Use the invoice period, not only usage dates. Google Cloud invoice month can differ from usage month.

2. KEEP DOCUMENTED DETAILS INTACT
[ ] AWS: keep product/dataTransfer, product/fromRegionCode and product/usagetype when present. Product columns are dynamic, so an absent column is not proof of zero cost.
[ ] Azure: use CostInBillingCurrency for the charge in the billing currency when that field applies to the account type. Treat every cost-details record as unique.
[ ] Google Cloud: retain sku.id, sku.description, cost, currency and adjustment_info when present. Do not assume a missing field means zero cost.
[ ] Record usage units exactly as reported. Do not treat GB and GiB as equal or add unlike units.

3. SEPARATE IMPORT DUPLICATION FROM SERVICE CHARGES
[ ] Check whether the same source records were included more than once in the working report. Exclude only confirmed repeated imports from the report, not from source data.
[ ] For each network line, record the charged service or function, traffic direction, locations, project or account, reported units and what traffic is measured. Mark unknowns for engineering review.
[ ] Keep distinct service fees even when their traffic volumes match. Google Cloud Armor Enterprise processing and Cloud Load Balancing processing are separate fees.
[ ] Ask the engineer to confirm which charges belong to the same path. Do not infer a duplicate from matching bytes, cost or descriptions alone.

4. RECONCILE WITHOUT HIDING CHANGES
[ ] Keep charges, credits, taxes, corrections and rounding adjustments visible as separate reconciliation components.
[ ] For Google Cloud corrections, retain both the negating line and the replacement line, and retain their adjustment_info values when present. Corrections can appear on a later invoice for earlier usage.
[ ] For Azure, include applicable invoice-level rounding adjustments when reconciling the complete invoice scope. Do not assign the whole adjustment to a network subset.
[ ] Reconcile complete-scope totals to the invoice with credits, taxes and adjustments accounted for. Show the network subtotal separately; do not compare it directly with the whole invoice total.
[ ] Record each unresolved difference, its source records and the colleague responsible for resolving it. Do not force a match by deleting unexplained lines.

How to confirm it

  1. 01

    Choose a reconcilable scope

    Choose one closed invoice period and account scope per provider. Keep currencies separate and record tax treatment. If you only have network lines, request the complete invoice-scope reconciliation instead of comparing the network subtotal with the whole invoice.

  2. 02

    Confirm export coverage

    Ask the billing colleague to confirm that records cover the selected period. For Google Cloud regional exports, record the enablement date and any disabled interval because data can be missing there. Mark incomplete results as partial, not zero spend.

  3. 03

    Map charges to the path

    Ask a network engineer to map each unexplained line to its service, direction and project or account. For Google Cloud cross-project service referencing, load-balancer and internet transfer charges are attributed to the forwarding-rule project, while cacheable Cloud CDN charges are attributed to the project containing the CDN-enabled backend service. Include both projects when in scope.

  4. 04

    Reconcile without deleting evidence

    Compare complete-scope totals with the invoice and leave unexplained lines visible with an owner. Remove only confirmed repeated imports from the working report. Keep Google Cloud correction lines and Azure invoice-level rounding adjustments in the reconciliation.

Before making changes

Assume one closed invoice period, a defined account scope, one currency per reconciliation and explicit tax treatment. A closed period does not prevent later Google Cloud corrections. Azure rounding adjustments are aggregated at Billing Profile or Enrollment scope, with no lower-scope information. This review identifies reporting differences, not proof of provider overbilling.

Skip this if no network charges are in scope, or if one already-explained line is present and you have confirmed there are no repeated imports, related service charges or unresolved corrections or adjustments.

Primary sources