The auth policy here should be updated so its scoped to the exact COS bucket. This will reduce the chance of having a clashing auth policy in an account, as well as comply with the concept of "least privileges".
We actually already do this in the main landing zone DA code -> https://github.com/terraform-ibm-modules/terraform-ibm-landing-zone/blob/d6d992c77b1a6fd9cb35c5b7798312fd3da64ddb/service_authorizations.tf#L97-L162