Cloud file

May 23, 2026

NAT Gateway Line Separate from the Virtual Machine Line

Document note only. Field Ledger is not a tax firm, cloud reseller, dental office, or insurer. Read your own form and confirm it with the preparer, billing desk, carrier, or another licensed professional.

This printable NAT gateway and virtual machine line comparison table standardizes network configuration tracking for U.S. cloud admin official records. It is designed for use in enterprise cloud invoice reconciliation and audit documentation folders, to eliminate misclassification of network egress costs that are often conflated with virtual machine runtime charges. Before completing any entries, confirm that all source data is pulled directly from dated cloud provider usage logs, not rough internal estimates, to ensure consistency for third-party review. You may reference Field Ledger’s general recordkeeping guidance for folder labeling standards if you do not have existing internal protocols for cloud expense filing.

Table Column Labeling for NAT Gateway Throughput Metric Entries

Each column in the included table is designed to eliminate ambiguity between NAT gateway and virtual machine line items, which are often grouped together in unformatted cloud invoice exports. The Log Entry Date (UTC) column must be populated with the exact date the usage occurred, not the date the invoice was generated, to align with time-stamped network configuration logs that are required for audit validation. The Resource ID Prefix column is a shorthand check for resource type: all NAT gateway resource IDs begin with a provider-standard prefix (e.g., nat- for AWS, nat-gateway- for GCP) while virtual machine IDs carry distinct prefixes (e.g., i- for AWS EC2, vm- for GCP Compute Engine) that make immediate classification possible without cross-referencing additional records. The Usage Metric Type column lists the specific billed activity for the resource: NAT gateway entries will only ever include runtime hours and data processing charges for traffic routed through the gateway, while virtual machine entries include compute runtime, attached storage costs, and direct egress traffic that does not pass through the NAT gateway. The Billed Amount column reflects the raw, unadjusted charge listed on the provider invoice, with no manual adjustments added at the time of entry; any corrections should be noted in the discrepancy annotation section instead. The Cross-Reference ID column links each line item to an internal change management ticket, support request, or configuration log entry that confirms the resource was authorized for use during the billing cycle. The Discrepancy Flag column uses a simple Y/N indicator to mark lines where the billed amount, usage volume, or runtime duration differs from pre-configured usage limits or expected charges for the resource.

Crop of nat gateway line separate folder on office nook
office nook: nat gateway line separate folder, no writing visible.
Log Entry Date (UTC) Resource ID Prefix Usage Metric Type Billed Amount (USD) Cross-Reference ID Discrepancy Flag
2024-04-01 nat-0a1b2c3d NAT Gateway Hourly Runtime Illustrative example: 27.90 CHG-2024-0312 N
2024-04-01 i-9z8y7x6w Compute Runtime (c5.xlarge) Illustrative example: 123.45 CHG-2024-0305 N
2024-04-15 nat-0a1b2c3d Data Processing (Egress 12TB) Illustrative example: 1021.78 SRV-2024-0416 Y
2024-04-15 vm-4d3c2b1a VM Egress Data (2.1TB) Illustrative example: 178.23 CHG-2024-0402 N
2024-04-30 nat-0e5f6g7h NAT Gateway Hourly Runtime (redundant instance) Illustrative example: 27.90 CHG-2024-0410 N
2024-04-30 i-3f2e1d0c Compute Runtime (t3.medium) Illustrative example: 32.10 CHG-2024-0409 Y

Header Box Markings for Cross-Reference Line Item Matching

Every printed copy of the completed table must include four standard markings in the 2×3 inch header box located in the top right corner of the form, to ensure it can be matched to corresponding invoice and log records in seconds during review. First, print the 7-digit internal invoice batch number assigned by your finance team to the relevant cloud billing cycle, in the top line of the header box. Second, add the 4-digit billing cycle date code, formatted as two digits for the month followed by two digits for the year (e.g., 0424 for April 2024), directly below the batch number. Third, add the full initials of the cloud admin who verified and completed the table entries, plus the date they completed the verification, in the third line of the header box. If the table is being filed as part of tax records for deductible cloud business expenses, add a fourth marking in all capital letters: TAX YEAR [YYYY], to make it easy to sort for tax filing purposes. All markings must be made in black permanent ink, no pencil, to prevent accidental alteration of cross-reference details. If you are completing this form as part of a formal audit request, confirm all header markings align with your audit team’s required documentation standards before submission, and consult your finance lead if you have questions about batch number or date code formatting. This page cannot be used to validate tax deductions, so always consult a licensed tax preparer before including these records in a tax filing.

Print Form Filing Instructions for Archived Network Configuration Logs

Once you have completed and verified all table entries and header markings, follow these steps to file the physical copy for long-term retention. First, print the table on standard 8.5×11 inch white paper, single-sided, with no scaling or resizing, to ensure all columns and annotations are fully legible for future review. Next, attach two supporting documents to the back of the printed table using a single staple in the top left corner: the first page of the official cloud provider invoice for the billing cycle, and a 1-page extract of the network configuration log showing all active NAT gateway and virtual machine resource IDs for the cycle, with matching resource ID prefixes to the ones listed in the table. File the stapled packet in your dedicated enterprise cloud expense records folder, sorted first by billing year, then by billing month, then by cloud provider. If your organization maintains both physical and digital copies of all billing records, stamp the bottom left corner of the physical copy with a permanent “DIGITAL COPY ON FILE” stamp, and write the full digital folder path for the corresponding digital records on the back of the printed table, to make cross-referencing easy. Never file adjusted or corrected versions of the table without attaching a signed addendum that explains the reason for the change, the date the change was made, and the full name and title of the person who authorized the adjustment. Standard record retention periods for cloud billing records range from 3 to 7 years for U.S. tax and audit purposes, but confirm the exact retention requirement with your legal or finance team before discarding any old records.

Side Note Annotations for Unusual Line Discrepancy Documentation

Any line item marked with a Y in the Discrepancy Flag column requires a formal annotation to document the issue, which must be added either in the right margin of the printed form or in the dedicated annotation field of the digital version of the table. Annotations must be specific, with no vague language, and should include four core details: the identified root cause of the discrepancy (if known at the time of entry), the date you notified your cloud provider’s billing desk of the issue, the expected adjusted charge for the line item if you are disputing the listed amount, and the unique support ticket number assigned by the provider for the dispute. Illustrative example: a NAT gateway line item showing 12TB of egress processing when your configured throughput limit for the gateway is set to 5TB for the billing cycle would have an annotation reading “Misconfigured security group allowed unapproved egress traffic, notified provider billing desk 2024-04-16, expected adjustment $425.75, ticket #CLOUD-24-78912”. All annotations must be dated and initialed by the person documenting the discrepancy, to create a clear audit trail for future review. Do not use internal jargon or undefined abbreviations in annotations, as external auditors or tax preparers who are not familiar with your team’s internal terminology will need to understand the note without additional context. This document cannot resolve billing disputes or secure adjustments on your behalf; all disputes must be submitted directly to your cloud provider’s billing support team per their published processes.

Illustrative field card for NAT Gateway Line Separate
Illustrative card for NAT Gateway Line Separate.

Digital Folder Organization for Completed Table Submission Records

Storing digital copies of the completed table and supporting records in a standardized folder structure ensures you can locate records quickly for audits, tax filing, or invoice dispute resolution. Start with a root folder titled “Enterprise Cloud Billing Records”, with subfolders for each calendar year, then nested subfolders for each billing month within the year. Create a dedicated subfolder titled “NAT vs VM Line Reconciliation” inside each billing month folder, to separate these reconciliation records from general invoice and payment records. Save three core files in this subfolder for each billing cycle: first, a non-editable PDF version of the completed reconciliation table, named using the convention [Provider Name]_[Billing Cycle Start Date]_NAT_VM_Reconciliation.pdf (e.g., AWS_2024-04-01_NAT_VM_Reconciliation.pdf). Second, the unmodified raw CSV invoice export downloaded directly from your cloud provider’s admin console, with no edits, deletions, or adjustments to the original line items. Third, a full export of the network configuration logs for the billing cycle, in CSV or JSON format, showing all resource IDs, usage volumes, and time stamps matching the entries in the reconciliation table. Set folder permissions to view-only for all users except authorized cloud admin and finance team members, to prevent accidental modification or deletion of source records. If you share the folder with external auditors or tax preparers, create a separate view-only share link that expires after 30 days to limit access to sensitive billing data. You may reference Field Ledger’s general digital recordkeeping guidance for additional folder labeling best practices if you do not have existing internal protocols.

Before completing your next monthly cloud invoice reconciliation, pull three random line items from your most recent unprocessed billing export to practice categorizing them as NAT gateway or virtual machine entries using the table structure outlined above.

Filed by Field Ledger.