67 checks across six layers.
This is the checklist we run on every audit. It is public on purpose: if you want to run it yourself, go ahead. If you would rather we do it against your live data and hand you the findings, that is what the free audit is.
Meta Pixel + CAPI
Browser pixel and Conversions API, judged together.
Meta's algorithm is only as good as the events it receives. We check that every event arrives, arrives once, and arrives with enough identity attached to be matched to a real person.
Audit my Meta setup- Base pixel present on every page template, including checkout and thank-you pages
- Standard events (ViewContent, AddToCart, InitiateCheckout, Purchase, Lead) fire on the right action, once
- Purchase value and currency populated and matching the order total
- Conversions API live and covering the same events as the pixel
- Shared event_id between pixel and CAPI so Events Manager deduplicates instead of double-counting
- Event match quality per event, and which parameters are missing (email, phone, fbp, fbc, external_id, IP, user agent)
- Customer information parameters hashed correctly (SHA-256, normalized)
- Domain verified and Aggregated Event Measurement priorities configured
- Test Events tool shows both browser and server hits with matching ids
- No stray or legacy pixels from old agencies or apps still firing
- Advanced matching and automatic events enabled or disabled deliberately
- Consent state honoured: nothing fires before the visitor agrees where the law requires it
Google Ads
Conversion actions, click ids and Enhanced Conversions.
Smart Bidding needs a clean conversion signal with the right value. We check what Google Ads counts, whether it counts it once, and whether it can still match conversions after cookies expire.
Audit my Google setup- Conversion actions mapped to real business outcomes, with primary and secondary set correctly
- No conversion counted twice via both a Google Ads tag and a GA4 import
- gclid, wbraid and gbraid captured and stored across the session and into the CRM
- Enhanced Conversions for web enabled with hashed first-party data
- Enhanced Conversions for leads configured for offline conversion uploads
- Conversion value and currency passed dynamically, not hard-coded
- Transaction id passed so duplicate orders and refresh reloads are deduplicated
- Counting settings (one vs every) match the conversion type
- Conversion window and attribution model set deliberately
- Consent Mode signals reaching Google Ads, with modeled conversions active where relevant
- Auto-tagging on, and no manual UTMs overriding gclid-based attribution
- Google Ads and GA4 linked, with the right property and audiences shared
GA4 + Tag Manager
Property setup, events, ecommerce schema and container hygiene.
GA4 is the source everything else reads from. We check whether the numbers in it can be trusted, and whether the dataLayer underneath is structured so tags stay correct when the site changes.
Audit my GA4 setup- Data streams, time zone, currency and data retention set correctly
- Key events (conversions) marked, and only the ones that matter
- Ecommerce events use the recommended schema with items arrays, value, currency and transaction_id
- Purchase fires once per order, and does not fire again on thank-you page refresh
- Cross-domain measurement configured for checkout, payment gateway and subdomains
- Referral exclusions for payment gateways (Razorpay, Stripe, PayPal, PayU) so sessions are not broken
- Internal traffic and developer traffic filtered
- Session and user attribution settings, plus Google Signals, set deliberately
- BigQuery export enabled where raw data or attribution modeling is needed
- GTM container: no unused tags, no duplicate triggers, versions named and published cleanly
- dataLayer pushes are consistent, typed correctly and available before the tag fires
- Server-side GTM present where needed, with correct client and transport URL
- Consent Mode defaults and updates wired into GTM, with tags gated correctly
- No PII (emails, phone numbers) leaking into page URLs or event parameters
CRM + offline conversions
The feedback loop from lead to revenue.
For lead-gen businesses the sale happens in the CRM, so the ad platforms never see it unless you send it. We check whether the loop is closed, and how much attribution is lost along the way.
Audit my CRM setup- Every lead record stores the click ids and UTMs it came in with (gclid, fbclid, fbp, fbc, session id)
- Form submissions reach the CRM with a stable lead id shared with the website event
- Pipeline stages (Lead, MQL, SQL, Won) exist and are populated consistently
- Stage changes are sent back to Meta CAPI, Google Ads offline conversions and GA4 with original attribution
- Deal value and currency sent with the Won event so the platforms optimize for revenue
- Offline uploads scheduled and healthy, with match rates reviewed
- Meta Lead Ads and other native lead forms synced into the CRM with source intact
- Phone and WhatsApp leads captured, not just web forms
- Duplicate leads merged rather than double-counted as conversions
- Reporting reconciles: leads in the ads platforms vs leads in the CRM vs revenue in the bank
Consent Mode v2 + CMP
Compliant, and still measurable.
Done wrong, consent either blinds your measurement or exposes you to compliance risk. We check the configuration against the regions you sell in and confirm modeled conversions are actually being recovered.
Audit my Consent setup- A consent management platform is installed (Usercentrics, Cookiebot, CookieYes, Didomi, Termly, Shopify consent) and loads first
- Consent Mode v2 default state set before any tag fires, including ad_user_data and ad_personalization
- Update command fires on user choice and tags react to it
- Regional rules: EEA and UK defaults denied, other regions configured deliberately
- Nothing sets cookies or sends data before consent where required
- Google Ads and GA4 show consent signals present and modeling active
- Meta pixel respects consent via the CMP integration or the consent API
- Consent banner does not block essential functionality or break checkout
- Privacy policy and cookie policy reflect the tags actually in use
Ecommerce platform layer
Shopify, WooCommerce, Magento and custom builds.
Every platform has its own way of breaking tracking. We check the events at the platform level, where most agencies never look, and follow the order from cart to confirmation.
Audit my store setup- Shopify: Custom Pixels on Checkout Extensibility replace anything that relied on checkout.liquid
- Shopify: native Google and Meta channel apps do not duplicate GTM or pixel events
- Shopify: cart attributes carry UTMs and click ids onto the order
- WooCommerce and Magento: purchase fires on the real order confirmation, not on a cached template
- Payment gateway redirects (Razorpay, Stripe, PayU, PayPal) do not break the session or lose the click id
- Headless and app-based checkouts (GoKwik, Shiprocket Checkout) send events with the right ids
- Product, category and cart events include item ids that match the catalog feeds
- Refunds and cancellations handled so reported revenue matches the books
- Subscription renewals and upsells attributed correctly or excluded deliberately
- Mobile app events (if any) reconciled with web events
Tested against your data, not a screenshot of your settings.
A settings review tells you what is configured. Only real sessions and real orders tell you what actually happens.
01
Live session tests
We walk the funnel as a visitor with debug tooling open: Tag Assistant, GA4 DebugView, Meta Test Events, network logs.
02
Real order reconciliation
Orders or deals from a recent period, compared line by line against GA4, Google Ads, Meta and the CRM.
03
Configuration review
Every container, property, pixel and conversion action inspected for settings that silently distort the numbers.
04
Severity and spend impact
Each finding scored by how many conversions it touches and how much of your budget is being optimized on it.
Want us to run all 67 checks for you?
Free, personal, and done by the senior team. You get the findings, the score and the roadmap in 3 to 5 business days.
Free. No obligation. You keep the report either way.