Home » How Do Banks Run Backup as an Internal Service with Chargeback?

How Do Banks Run Backup as an Internal Service with Chargeback?

Large banks, insurers and other financial institutions increasingly run backup the way a service provider would: as a centrally operated internal service with a catalog, service levels and a price. Business units and application teams consume protection from that service rather than buying their own backup storage, and the cost flows back to them through showback or chargeback. Done well, an internal backup service with chargeback reduces duplicated infrastructure, makes retention decisions visible and gives the institution one consistent answer when regulators ask how data is protected and restored.

This article explains how financial institutions structure an internal backup service, how chargeback models work, what drives the cost per terabyte and how regulatory requirements shape the design. Many of the same ideas apply to any large organization running shared infrastructure.

Why banks move to an internal backup service

Backup in large financial institutions has historically grown in silos. Each division, region or acquired business bought its own software and storage, set its own retention and tested restores on its own schedule. The result is predictable: multiple backup products, inconsistent immutability, storage islands at different utilization levels and no single view of what is protected.

Moving to an internal service addresses several pressures at once:

  • Ransomware resilience. A central service can enforce immutability, isolation and restore testing everywhere, not only in the divisions that prioritized it.
  • Regulatory consistency. Regulators expect documented backup policies, defined recovery objectives and evidence of restore testing across critical services.
  • Cost transparency. Retention and copy decisions made by application owners drive storage cost, but in a silo model they rarely see the bill.
  • Scale economics. One large platform is usually cheaper per terabyte to run than many small ones.

The financial services storage landscape is covered more broadly in storage solutions for financial services.

Designing the service catalog

The catalog is what application teams see. It turns technical options into a small set of clear choices. A typical internal backup catalog defines tiers by recovery objective and retention:

  • Tier 1, critical services. Frequent backups, short recovery point objective, immutable copies, a second copy in another location and priority restore.
  • Tier 2, important services. Daily backups, immutable retention for a defined period, standard restore priority.
  • Tier 3, standard services. Daily or weekly backups with standard retention.
  • Long-term retention. Monthly or yearly copies kept for regulatory or legal reasons, rarely restored.

Each tier specifies what is included: backup frequency, retention, immutability period, number and location of copies, restore time targets and testing frequency. Application owners choose a tier for each system, often guided by a business impact assessment. Keeping the catalog short avoids endless custom requests.

Showback vs chargeback

Institutions usually move through stages.

Showback

The backup team reports consumption and an estimated cost to each business unit but does not transfer budget. Showback builds awareness and surfaces outliers, such as applications retaining far more data than policy requires, without the friction of internal billing.

Chargeback

Costs are allocated to business unit budgets based on consumption. Chargeback creates a real incentive to choose the right tier and retention, but it needs accurate metering, a rate that teams accept as fair and a dispute process.

Hybrid

Many banks fund a baseline centrally, for example the minimum protection every system must have, and charge back for anything above it, such as longer retention, extra copies or higher tiers. This keeps mandatory protection from being cut to save budget while still pricing optional extras.

Building the rate

An internal rate should be based on the full cost of running the service, divided across what is actually consumed. Components include:

  • Backup software licenses and support.
  • Backup storage hardware, protection overhead and refresh, amortized over service life.
  • Data center space, power and network.
  • Staff for operations, restore support and testing.
  • Secondary site and offline or isolated copies.
  • Headroom for growth and immutable data that cannot be reclaimed early.

Rates are commonly expressed per protected terabyte per month, per stored terabyte per month or per protected system, sometimes combined. Publish the rate before the budget cycle, hold it for the year and review it annually. The methods are similar to external provider pricing, covered in storage pricing for service providers, and the cost components are detailed in storage cost per terabyte.

Making retention costs visible

Retention is usually the largest driver of backup storage. Without chargeback, the easiest choice for an application owner is to keep everything for as long as possible. With chargeback, each extra year of retention has a visible price. The ARTESCA blog explores this in the cost of another year of retention.

Retention changes also have a lag. Shortening retention does not free capacity immediately, especially for immutable data that is locked until its retention date. backup retention changes explains why. Chargeback reports should show both current consumption and committed future consumption for locked data.

Metering and reporting

Chargeback is only credible if consumption data is accurate and attributable. Practical requirements include:

  • Tagging every protected system with a cost center and owner in the configuration management database.
  • Per-tenant or per-business-unit separation on the backup storage, such as separate accounts or buckets, so consumption can be measured directly.
  • Regular sampling of stored capacity rather than a single month-end snapshot.
  • Reports that explain the bill by system, tier and retention, so owners can act on them.
  • Exception handling for systems without an owner, which often turn out to be candidates for decommissioning.

A storage platform that supports multi-tenancy natively makes this far easier.

Regulatory drivers

Regulation shapes both the catalog and the evidence the service must produce. In the European Union, the Digital Operational Resilience Act (DORA), which has applied since 17 January 2025, requires financial entities to maintain backup policies and procedures and restoration and recovery methods as part of ICT risk management, including testing of backup and restoration. Other jurisdictions set similar expectations through supervisory guidance and examinations.

For an internal backup service, that means:

  • Documented policies that map each tier to recovery objectives.
  • Evidence of regular restore tests, with results recorded.
  • Segregation of backup copies from production systems, including logical or physical isolation.
  • Clear ownership of backup data for critical or important functions.

The scality.com blog’s guidance on ransomware recovery exercises and the Solved guide to backup verification testing cover how to run and document tests.

The storage platform behind the service

An internal service shares many requirements with an external provider: multi-tenancy, immutability, scale and efficient operations. Common platform requirements include:

  • One scalable pool that grows by adding nodes rather than adding separate arrays per division.
  • Support for multiple backup applications, since few banks consolidate to a single product overnight.
  • Object lock immutability for ransomware-resilient copies.
  • Replication to a second site and an isolated or air-gapped copy for critical data.
  • Per-business-unit accounts, quotas and reporting to support chargeback.
  • Hardware refresh without migration, since backup data for regulated firms may be kept for many years.

S3-compatible object storage is a common foundation because most enterprise backup applications can write to it directly, and it provides multi-tenancy and immutability in one platform.

Getting adoption

The hardest part is often organizational. Business units used to running their own backup may resist a central service. Approaches that help include starting with showback, offering a migration path that does not require immediate replacement of existing tools, demonstrating better restore results than the silos achieved and involving risk and audit teams early so the service becomes the default route to compliance. A visible, successful restore during an incident does more for adoption than any presentation.

Checklist: internal backup service chargeback

  • Inventory existing backup products, storage and retention across divisions.
  • Define a short catalog of tiers mapped to recovery objectives and retention.
  • Decide on showback, chargeback or a hybrid with central baseline funding.
  • Build a fully loaded rate and publish it before the budget cycle.
  • Tag every protected system with an owner and cost center.
  • Separate consumption per business unit on the storage platform.
  • Show committed future cost for immutable data in reports.
  • Map policies and test evidence to regulatory requirements such as DORA.
  • Choose a scalable, multi-tenant platform with immutability and replication.
  • Review rates, tiers and adoption annually.

Putting it together

An internal backup service with chargeback lets a financial institution treat data protection as a managed product: consistent tiers, enforced immutability, documented testing and costs that land with the teams who make retention decisions. The technology is only part of it. A clear catalog, a fair rate, accurate metering and early involvement from risk and audit teams are what make the service stick. For the external provider version of the same model, see backup as a service for providers.

Frequently asked questions

What is the difference between showback and chargeback?

Showback reports consumption and estimated cost without moving budget. Chargeback allocates actual cost to business unit budgets based on consumption.

How do banks calculate an internal backup rate?

They total software, storage, facilities, staff, secondary copies and refresh costs, then divide by consumed capacity or protected systems, and review the rate annually.

Does DORA require backup testing?

DORA requires financial entities to maintain backup and restoration policies and procedures and to test them as part of ICT risk management. Check the regulation and supervisory guidance for specifics.

Should mandatory backup be charged back?

Many institutions fund baseline protection centrally so it cannot be cut, and charge back for optional extras such as longer retention or higher tiers.

What storage suits an internal backup service?

A scalable, multi-tenant platform that supports several backup applications, immutability, replication and per-business-unit reporting. S3-compatible object storage is a common choice.

Further reading