Website Analytics Audit: GA4 Events, Consent and Data Quality
Audit GA4 measurement definitions, event delivery, consent states and reporting limits. Reconcile differences before using analytics to make decisions.
Published by AuditWeb
A website analytics audit checks whether tracking records the intended actions and whether reports can support the decisions made from them. It documents collection gaps, duplicate events, reporting limits and the definitions used in each comparison.
What does an analytics audit cover?
Cover the agreed properties, streams, domains, events and customer journeys. Record implementation versions, access permissions and the audit date. Mark unavailable server or transaction evidence as a limitation.
A discrepancy is a finding to investigate, not automatic proof that GA4 is wrong. Browser restrictions, consent, timezones, event definitions and reporting methods can all produce different totals.
How should GA4 configuration be reviewed?
Start with the property and stream receiving data, then check the intended event configuration and access controls.
- Match production pages to the correct measurement destination.
- Identify CMS, hardcoded and tag-manager installations that might emit the same event twice.
- Review enhanced measurement against custom events and single-page navigation.
- Test internal-traffic filters before activating them; exclusions can permanently affect incoming data.
- Choose retention for the actual analysis and privacy requirements rather than maximising it by default.
Google documents configuration limits separately from how reports store and display data. Do not assume a retention setting controls every report in the same way.
How do you check tracking accuracy?
Reproduce a known action and trace it from the browser request to the event report. Use the same test conditions when comparing implementations.
- Record the URL, consent choice, browser, timestamp and action.
- Inspect the destination and payload in browser network tools.
- Use DebugView to inspect debug events where available.
- Check whether navigation, retries or duplicate listeners emit extra events.
- Compare the corresponding business record when access is authorised.
For journeys spanning domains, verify identity and attribution continuity instead of assuming every subdomain needs the same configuration. Investigate unwanted payment referrals without excluding legitimate acquisition sources.
How should important actions be defined?
Choose key events that represent meaningful outcomes. Name the trigger and distinguish intent from completion: clicking a contact button is different from a successfully delivered enquiry.
Google's conversion explanation distinguishes Analytics key events from Google Ads conversions. Record the platform and counting method when comparing them.
Use actual transaction values where verified. Label lead values as estimates and preserve their assumptions. Exclude private customer text, credentials and unnecessary personal data from event payloads.
What should an event review record?
Record the event name, trigger, permitted parameters, destination, consent behaviour and owner. A consistent specification makes duplicates and missing actions easier to diagnose.
Test success, validation error, network failure, repeated click and direct access to the confirmation URL. A success-page view alone can fire without a genuine submission. Coordinate tests so they do not create real orders or misleading leads.
The tag audit covers the scripts and triggers that send events; this analytics audit covers whether the resulting data answers the business question.
How should data-quality limits be reported?
Report consent coverage, blockers, thresholding, sampling, identity settings and processing delays where they affect the result. Missing observations are not zero activity.
Google's Consent Mode documentation distinguishes basic blocking from advanced behaviour that can send measurements without cookies. Consent Mode is not itself a legal-compliance determination or a guarantee of complete data.
Reconcile totals only after aligning definitions, scope and dates. There is no universal ten-percent tolerance. Modelled or attributed data should be labelled, not presented as a complete raw transaction ledger.
What is the final analytics audit checklist?
- Property, stream, domains and access are documented.
- Test actions reach the intended destination without unintended duplicates.
- Key-event definitions distinguish clicks from completed outcomes.
- Consent choices and applicable restrictions are respected.
- Parameters exclude unnecessary personal or confidential data.
- Filters, retention and reporting limitations are explained.
- Reconciliation differences have an owner, evidence and retest.
Use the audit working files to record issues before relying on the data in a CRO experiment plan.
Check Your Page HTML
Review titles, canonical links and other on-page signals from pasted HTML. Download your findings for follow-up.
Open HTML CheckerNo signup required • Pasted HTML stays in your browser