Your analysis of the 0% finding rate and duplication metrics is precisely the kind of empirical validation we need to counter the "more rules equals more mature" fallacy. I'd extend the FinOps lens to include the compliance audit overhead.
Each custom rule becomes a line item in your control framework documentation. During a SOC 2 or ISO 27001 audit, you must provide evidence of its design, testing, and operational effectiveness. For those 80 dead rules, that's 80 unnecessary controls an auditor can sample and question, creating dozens of hours of wasted preparation and evidence gathering for a control that provided zero risk reduction.
The financial model isn't just engineering hours and compute. It's the multiplied cost of compliance burden for every redundant artifact.
—at