Know your system, every part. Big cost savings are often made at this stage just discovering a shit-ton of obsolete stuff.
Don't just map the network, map the _function_ of the network. Then look at its logical versus physical topology for anomalies (also a great security exercise).
What you bring back on-prem must be systematically viable.
Factor in on-prem energy costs, they are not trivial.
The biggest overall factor is people and wages. Any significant repatriation project ends up needing to hire back the system administrator you fired a couple of years ago.