Full AWS Practitioner Certification Question

A financial services company is migrating its internal infrastructure to AWS from an on-premises data center. Due to strict data residency regulations, the company must operate exclusively in the Asia Pacific (Osaka) Region (ap-northeast-3). Additionally, security policies prohibit any VPCs from having internet access. What are the most appropriate AWS-native solutions to enforce these regional and network restrictions while maintaining centralized governance?