Are you leveraging modules? For example, if you create a new product in your account, can you just have the product call your own module to create its IAM roles to your own standards and specification? Or are you repeating IAM code over and over?
Basically all of your terraform code should be modularized because you’ll likely repeat it for different environments like staging vs. production. So, for example, when I want to build another product VPC in another environment, it’s just another deployment of the same child module with different input variables.
Are you trying to manage multiple products with the same terraform code? I see this a lot and while it’s not a catastrophe, I try to separate terraform repositories by their product or logical function.
I also wonder if you’re overusing AWS sub-accounts. I only use a separate account when the business needs to separate the business unit entirely, or to separate production from other environments. Everything else should be able to be kept separate via roles and policies.