Newer AWS providers allow for default tags in the provider. The policy should check tags, and tags_all for compliance.