The short answer
AWS gives you a great deal of choice, which means many decisions that a hosting company would once have made for you now sit with your organization. Before deployment, you should be able to answer seven groups of questions:
- Data: what the workload stores and how sensitive it is.
- Region: where it runs, and whether any data or backups leave Canada.
- Availability: how long it may be down and how much data you can afford to lose.
- Identity: who and what can access the account, and how.
- Budget: what it should cost and how you will know when it doesn't.
- Backups: what is backed up, where, and whether restores have been tested.
- Ownership: who runs, patches, monitors and pays for it after launch.
AWS describes security as a shared responsibility: AWS protects the infrastructure that runs its services, while the customer's responsibilities depend on the services they choose. The questions below are largely about your side of that line.
1. Data
- What records will the workload hold: customer data, financial data, health information, documents, logs?
- Does it hold personal information? If so, which privacy laws apply (PIPEDA, or provincial laws such as Quebec's Law 25, Alberta or BC PIPA, or Ontario's PHIPA for health information)?
- Are there contractual requirements from customers, funders or regulators about where data is stored or who can access it?
- How much data is there today, how fast does it grow, and how long must it be kept?
- Which logs will contain personal information, and who can read them?
2. Canadian regions and data residency
AWS currently lists two regions in Canada: Canada (Central), code ca-central-1, and Canada West (Calgary), code ca-west-1. Canada West is an opt-in region that must be enabled before use (AWS Regions).
Choosing a Canadian region helps with data residency, but it does not, by itself, keep every copy of your data in the country. Ask:
- Are all the services you plan to use available in the chosen region?
- Do any services, features or third-party tools you add (monitoring, email delivery, content delivery, support tooling) process data outside Canada?
- Will backups or disaster recovery copies go to another region? A second Canadian region keeps copies in Canada; a US region does not.
- If personal information will be processed outside Canada, have you told people and put contractual protections in place? The Office of the Privacy Commissioner's guidance says organizations remain accountable for information transferred for processing and should be transparent that it may be processed in another country.
This is general information, not legal advice.
3. Availability
- What happens to the business if this workload is unavailable for an hour, a day or a week?
- What is the recovery time objective (how long until it must be back) and recovery point objective (how much recent data you could lose)?
- Is running across multiple Availability Zones within one region enough, or do you need a recovery option in a second region?
- Which parts are single points of failure: one database instance, one server, one person with the password?
- How will you know it is down before your customers tell you?
Higher availability costs more. Set the target from the business impact, not from habit.
4. Identity and access
AWS's IAM best practices are a good baseline. Ask:
- Will people sign in through federation with an identity provider (for example, your Microsoft 365 or Google Workspace accounts) using temporary credentials, rather than long-lived individual IAM users?
- Is multi-factor authentication required, ideally phishing-resistant methods such as passkeys or security keys?
- Who holds the root user credentials, how are they protected, and when are they used?
- Are permissions based on least privilege, and who reviews and removes unused access?
- Will production, testing and development live in separate accounts, with guardrails applied across them?
- When a staff member or contractor leaves, what is the offboarding step for AWS access?
5. Budget
- What is the expected monthly cost, as estimates in CAD, and what assumptions is it based on (usage, storage growth, data transfer)?
- Who receives budget alerts? AWS Budgets can notify you when actual or forecast spending passes a threshold, but AWS notes there can be a delay between incurring a charge and receiving the notification, so alerts are not a hard spending cap.
- Are resources tagged by project, environment and owner so costs can be allocated?
- Who reviews the bill monthly and has authority to switch off what is not needed?
- Have you considered commitments or reserved capacity only after usage is stable?
For ongoing cost control, see how growing companies cut cloud costs.
6. Backups and recovery
- Which resources are backed up, how often and for how long?
- Are backups managed centrally, for example with AWS Backup, which supports backup plans, cross-Region and cross-account copies, and a vault lock that prevents deletion of backups or changes to retention?
- Are backup copies kept somewhere that a compromised administrator account cannot delete?
- When was a restore last tested, and how long did it take?
- Are application configuration, infrastructure definitions and secrets recoverable too, not only data?
A backup you have never restored is an assumption. Our backup and disaster recovery service covers this in more depth.
7. Ongoing ownership
- Who owns the AWS account and the billing relationship?
- Who applies operating system, database and application updates?
- Who monitors alerts outside business hours, and what are they expected to do?
- Is the environment defined as code, so it can be rebuilt and reviewed?
- Where is the documentation: architecture, access, runbooks and recovery steps?
- When will the design be reviewed? The AWS Well-Architected Framework describes a review process for reliable, secure, efficient, cost-effective and sustainable workloads.
Pre-deployment checklist
- Data types, sensitivity and applicable privacy obligations documented.
- Region chosen, with every service and third-party tool checked for where it processes data.
- Backup and disaster recovery locations confirmed, including whether copies stay in Canada.
- Recovery time and recovery point objectives agreed with the business.
- Sign-in through federation, with MFA required; root user secured.
- Separate accounts or environments for production and non-production.
- Monthly cost estimate in CAD, budget alerts and tagging in place.
- Backup plan configured and a test restore completed.
- Monitoring and alert recipients defined, including outside business hours.
- Named owners for the account, billing, updates and incident response.
- Documentation and runbooks stored somewhere the team can reach during an outage.
Limitations
These questions apply to most business workloads but are not a full architecture review. Regulated workloads, such as those at federally regulated financial institutions or health information custodians, will have further requirements. If AWS is one option among several, the same questions help compare it with other providers and Canadian regions.
Next step
If you want help answering these questions or reviewing an existing AWS environment, see AWS deployment and cloud engineering. For broader migration planning across providers, see cloud services and migration.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- AWS Regions, Amazon Web Services documentation
- Shared Responsibility Model, Amazon Web Services
- Security best practices in IAM, Amazon Web Services documentation
- Managing your costs with AWS Budgets, Amazon Web Services documentation
- What is AWS Backup?, Amazon Web Services documentation
- AWS Well-Architected Framework, Amazon Web Services documentation
- Guidelines for processing personal data across borders, Office of the Privacy Commissioner of Canada
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.