For CloudHealth to collect AWS Key Management Service (KMS) Customer Master Keys (CMK), it is required that the key policies in place allow IAM access.
This is the default for new keys, but if the key policies have been modified to remove the default IAM access, CloudHealth will be unable to completely collect the key and its tag data.