Analytics & CRM
GA4 audit checklist: 18 checks before you trust your reports
A hands-on GA4 audit for website owners and marketing teams: verify what is collected, trace real customer actions and separate tracking faults from reporting differences.
Vladlens Kecko · · 7 min read

A GA4 audit checklist should verify the journey from a real customer action to the report used to make a decision. Seeing visitors in Realtime only proves that some data is arriving. It does not prove that purchases, enquiries or campaign sources are recorded correctly.
This guide covers a website implementation. Start with read access to GA4, access to your tag setup and test access to the website. Compare analytics with order or CRM records, and agree who can publish tracking changes. Record the property, stream, test device, consent choice and time of each test.
For a focused comparison, follow the GA4 and Google Ads reconciliation guide. Use the UTM naming template to standardise incoming campaign links.
The 18-point GA4 audit checklist
Use pass, fail or investigate for each row. Keep a screenshot or test log, an owner and a next action. An audit should leave a reproducible explanation, not just a list of settings.
| Check | What to verify |
|---|---|
| 1. Ownership | The business retains appropriate access and former partners no longer have unnecessary access |
| 2. Property and stream | Production traffic goes to the intended property and web stream |
| 3. Currency and time zone | Reporting settings match the business context used for comparison |
| 4. Tag coverage | Important landing, product, checkout and confirmation pages send expected events |
| 5. Duplicate installation | A CMS plugin, hard-coded tag and GTM do not send the same event twice |
| 6. Page views | Initial loads and client-side navigation produce the intended page-view sequence |
| 7. Event definitions | Each event has a clear business meaning and a documented trigger |
| 8. Successful actions | A completed form or purchase triggers the intended outcome, not just a button click |
| 9. Repeat actions | Refreshing, going back or retrying does not inflate successful outcomes |
| 10. Key events | Important business outcomes are marked intentionally; engagement events are distinguishable |
| 11. Ecommerce parameters | Purchase IDs, value, currency and items match the test order |
| 12. Consent states | Default and updated consent states behave as designed for accept and reject choices |
| 13. Personal data | URLs, titles and ordinary event parameters do not expose emails, names or phone numbers |
| 14. Cross-domain journeys | Moving to a controlled checkout or booking domain preserves the intended measurement |
| 15. Unwanted referrals | Payment or operational domains do not incorrectly claim acquisition credit |
| 16. Internal traffic filters | Exclusions identify the intended traffic without removing customers |
| 17. Campaign attribution | Campaign naming, redirects and linked advertising accounts preserve usable source data |
| 18. Reconciliation | Differences from CRM and order records have an explained scope, delay and definition |
Test one journey at a time
Enable debug mode for your test device with Tag Assistant or Tag Manager preview, then inspect the event sequence and parameters in GA4 DebugView. Use acquisition reports for attribution analysis; DebugView is primarily an implementation diagnostic.
Run these scenarios on desktop and mobile:
- Visit a landing page, follow an internal link and confirm the expected page sequence.
- Attempt an invalid form submission; confirm it is not recorded as a successful enquiry.
- Submit a valid form and match the event with the received CRM or inbox record.
- Reload the confirmation screen and check whether the success event repeats.
- For a shop, complete a test purchase, inspect its parameters and compare it with the order system.
Avoid concluding that an event is missing solely because the debug panel is empty. Check the selected device, debug setup, consent state and network requests. A blocked or unconsented journey can behave differently from your accepted-consent test.
Diagnose duplicates before changing reports
List every route by which an event can be sent: site code, a CMS plugin, GTM or a server integration. Look for two senders or a trigger that fires on both a click and a success callback. Fix the sender or trigger rather than trying to hide duplicate activity in a report.
For ecommerce, validate recommended event names and required fields against Google’s ecommerce implementation guide. Use a unique transaction ID for each order and test refresh behaviour. Google’s validation guide explains transaction-ID handling; do not assume the same protection applies to every custom lead event.
A GA4 audit discussion on Reddit highlights checking event firing against real user actions before trusting reports. This is anecdotal advice; the reproducible journey and official implementation reference are what establish whether your setup works.
Check consent and personal-data exposure
Test a new visitor who accepts, one who rejects and a returning visitor who changes their choice. Use Google’s consent debugging procedure to inspect defaults, updates and tag behaviour. A visible banner alone does not establish correct consent signalling.
Inspect URLs and payloads after form submissions. Keep email addresses, phone numbers and names out of ordinary analytics parameters, page titles and URLs. See Google’s PII guidance. Treat purpose-built user-data features as a separate implementation, rather than putting customer details in arbitrary fields.
Repair source attribution without hiding the problem
If you control multiple domains in one customer journey, check the cross-domain configuration and whether redirects preserve the linker parameter. For a payment-provider return, inspect unwanted referral settings. These settings solve different problems; excluding a referral is not a substitute for a correctly connected journey.
Check campaign links from the actual email or advertisement, including any redirect. Use consistent campaign naming on incoming marketing links. Avoid adding campaign tags to ordinary internal navigation, which can make interpretation harder.
Test internal and developer filters before activating them. Google notes that excluded data is permanently unavailable, and filters do not repair historical data. Document the activation date so later report changes have an explanation.
Reconcile a sample, then prioritise fixes
Compare a clearly defined period after data has had time to process. Align time zones, currency, event definitions and attribution scope. GA4, Google Ads and your CRM answer different questions; identical totals are not automatically the correct target.
An illustrative finding might be 10 accepted test enquiries in the CRM but 20 success events because both a click handler and a confirmation-page trigger fire. That gives you a specific implementation fix. A difference caused by consent choices or attribution windows needs an explanation, not an invented balancing event.
Prioritise exposed personal data, missing or duplicate business outcomes and broken customer-source continuity. Then improve naming and report usability. If these events feed advertising decisions, also check the Google Ads audit checklist and your CRM integration.
Common questions
Is Realtime enough for an audit?
No. Combine a controlled journey, event parameters, debug tools and processed reporting. Confirm business outcomes against the system that actually receives the order or enquiry.
Should every event be a key event?
Choose events that represent important business outcomes. Keep supporting engagement actions separately interpretable. Check Google Ads conversion goals independently before using imported events for bidding.
Will fixing tracking repair old reports?
Most implementation fixes change future collection. Annotate the correction date and avoid comparing before and after as if the measurement method had always been identical.
Find the tracking issues that affect your decisions
Request a free performance audit and mention GA4 tracking in your enquiry. We can review your measurement priorities and discuss the next steps. For implementation support, explore tracking, attribution and CRM.
About the author
Continue reading
Google Ads conversion tracking for B2B: from click to revenue
Connect campaign identifiers, lead stages and sales outcomes so advertising decisions reflect qualified pipeline and closed revenue.
Why do GA4 and Google Ads show different conversions?
GA4 and Google Ads disagree? Compare conversion actions, dates, attribution and duplicate tracking with a practical reconciliation checklist.
Google Ads CRM integration: connect leads and offline conversions
Return qualified opportunities and won business to Google Ads so campaign decisions learn from real commercial outcomes rather than raw forms.