Status: IN
The FIS EC2 access policy includes `kms:CreateGrant` conditioned on `kms:ViaService` and `kms:GrantIsForAWSResource` to handle stop/start of instances with encrypted EBS volumes.
Source: entries/2026/03/12/aws-managed-policy-latest-reference-AWSFaultInjectionSimulatorEC2Accesshtml.md