In the context of cloud, it's cargo cult security. Something somewhere says "you must have encryption at rest." I find it very hard to believe Amazon's or Google's servers do not already have full disk encryption. So what are you protecting again? If you're storing the decryption keys in KMS in the same cloud, you're not hiding anything from the cloud provider. The only rationale I can think of for doing this is defense-in-depth, but seeing how many companies struggle to even get IAM right I doubt this would help much.
Security compliance and real world security are a universe apart. You have encryption at rest with mandated AES-GCM/SHA512? Cool story bro, some teenagers just broke into your network with a bit of social engineering and a 6 year old CVE.