>

Analytics Audit Checklist

Analytics failures are usually silent. Data keeps flowing and reports keep rendering while the numbers quietly stop meaning what everyone assumes they mean.

Why Audit Analytics

Tracking breaks during site changes, template updates, consent tool deployments and tag manager edits. Nobody receives an alert. The first symptom is typically a report that looks slightly wrong, weeks later.

An audit establishes whether the data supporting your decisions is sound. It is worth doing when inheriting an account, after any significant site change, and on a fixed annual cadence regardless.

Configuration Checks

  • Is the measurement tag present on every page, and exactly once? Duplicate tags inflate sessions and halve bounce figures
  • Is internal traffic filtered, and is the filter actually working?
  • Are cross-domain journeys configured where the site spans multiple domains?
  • Is the data retention period set deliberately rather than left at default?
  • Are conversion events defined, and do they correspond to real business outcomes?
  • Is the site search configured if the site has a search function?

Data Quality Checks

Self-referral traffic. Your own domain appearing as a referral source indicates broken session continuity, usually at a payment gateway or subdomain boundary.

Unexpected direct traffic. Direct exceeding roughly a third of sessions often means untagged campaigns or lost referrer data on redirects.

Conversion count sanity. Compare analytics conversions against the source of truth — the CRM, the payment processor, the booking system. A consistent gap of more than 10 to 15 percent needs explaining.

Sudden step changes. Plot key metrics over a long window. Vertical jumps usually mark a tracking change, not a business change.

Consent and Privacy Checks

With consent management in place, verify what happens in each state: consent granted, consent denied, no choice made. Test each path and confirm the data behaves as expected.

Check that consent mode is correctly configured rather than simply blocking tags outright, and that modelled conversions — if relied upon — are actually being generated.

Documenting the Setup

The audit output should include a measurement plan document: what is tracked, why, how each event fires, and who owns it. Most accounts have none, which is why the same problems recur after every staff change.

The Checks That Find the Most Damage

Some analytics faults distort everything downstream and are invisible in a dashboard. These are the ones worth checking first.

  • Duplicate tags. The same tag firing twice halves bounce and doubles pageviews. Check the network requests on a few pages rather than trusting the container.
  • Internal traffic not excluded. Your own team, your agency, your office. On a low-traffic site this is a large share of everything.
  • Self-referrals. Your own domain appearing as a traffic source means session continuity is breaking, usually across a subdomain or a payment redirect — which also means conversions are being credited to the wrong source.
  • Data retention set to the minimum, silently limiting historical analysis. Check it; the default is not what most people want.
  • Conversions counting the wrong event, or counting one event multiple times per session.
  • Filters applied to the only data view, with no unfiltered copy. Filtered data is not recoverable.

Consent, and Why the Numbers Moved

The most common analytics mystery — traffic dropped and nothing changed — is usually consent, and it is worth checking before investigating anything else.

Confirm what happens before a user consents. Whether tags fire, in what mode, and whether that behaviour changed when the banner was last updated. A consent tool updated by a compliance team frequently moves analytics numbers, and nobody connects the two.

Understand what modelled data is. Where consent mode is active, some of what you see is estimated rather than observed, and the modelled share varies by region and by traffic volume. That is not wrong, but it means a year-on-year comparison spanning a consent change is comparing two different things.

Check region-specific behaviour if you have European or other regulated traffic, where the default should be more restrictive.

And document the consent configuration alongside the analytics configuration. They are usually owned by different people, changed independently, and together they determine every number the business runs on — which is precisely why nobody notices when one moves.

Sources

What each claim on this page rests on. Entries are typed so you can see which are primary.

  1. officialGoogle Analytics 4 documentation — data retention settings, internal traffic filters, conversion configuration and consent mode behaviour support.google.com

Ask an AI about this page

Opens your assistant with this page as the source, and a question rather than a summary. It will ask what you are building before it answers.

ChatGPTClaudeGeminiPerplexityGrok

Nothing is sent from here. The link carries only this page’s title and address.