The dependency you did not list
The architecture diagram shows two regions, each with app servers and a database. The running system also depends on things the diagram leaves out, such as identity, configuration, service discovery, a payment provider and the cloud's own control planes, any of which can live in one region only.
When that region goes, redundancy downstream of it stops mattering. A replacement instance must fetch its configuration, register with discovery and acquire credentials before doing useful work, and AWS counts each as a dependency on the recovery path. AWS SDKs fetch credentials from STS in us-east-1 unless told otherwise, and an identity provider on the impaired cloud can stop engineers signing in to run the failover, so AWS advises keeping break-glass users (A human in the loop adds minutes to recovery).
IAM and Route 53 keep their control planes in us-east-1, so a plan that creates roles or edits records mid-failover depends on that region, a case of control planes failing differently.
The way to find these is to take a region away and watch. Sarah Wells expects game days to expose a wrong mental model, sometimes as plainly as someone lacking access. A missing dependency is, by definition, not on the diagram.