The problem
Two companies became one, and with them two AWS accounts with overlapping IAM, separate bills, no shared guardrails, and no disaster recovery story that covered both sides.
What we did
We stood up AWS Organizations, imported both accounts under a master with consolidated billing, and wrote service control policies so the guardrails applied regardless of who was in which account. IAM was rebuilt around the merged org chart rather than patched. Disaster recovery and cost optimisation were folded into the same piece of work, since both had to be re-derived from the combined footprint anyway.