Audit checklist
Website Analytics Audit Checklist: 40 Checks for Reliable Data
Audit website analytics across tracking coverage, data quality, privacy, conversions, attribution, funnels, reporting, and governance.
An analytics dashboard can look precise while being directionally wrong. A useful audit tests the entire chain—from the browser action to the business decision—not just whether a tag fires.
Score each check as pass, fail, not applicable, or unknown. Treat unknown as a risk that needs an owner.
Tracking coverage (1–7)
- All indexable routes record a page view
- SPA route changes record exactly one page view
- Primary and supporting conversions are tracked
- Server-confirmed outcomes are captured where appropriate
- Cross-domain journeys preserve necessary context
- 404 and error states are measurable
- Internal, preview, and automated traffic can be filtered
Data quality (8–15)
- Event names follow one documented convention
- Required properties are present and typed consistently
- Duplicate events are below the accepted threshold
- Timestamps, time zone, and currency are correct
- Bots and spam referrals are handled
- Backend conversion totals are reconciled
- Release changes have not broken historical comparisons
- Known limitations are visible to report users
Privacy and security (16–23)
- Collection purpose and legal basis are documented
- No personal data leaks through URLs
- Free-form properties cannot collect secrets or sensitive data
- Identifiers and IP handling are documented
- Retention and deletion are configured
- Access follows least privilege
- Vendors and subprocessors are reviewed
- Privacy notices accurately describe the implementation
Conversion and funnel analysis (24–29)
- The primary conversion has one unambiguous definition
- Funnel steps reflect real user actions
- Unexpected paths can be discovered
- Drop-offs have enough volume to act on
- Experiment exposure connects to outcomes
- Guardrail metrics prevent local optimization from harming the whole journey
Acquisition and attribution (30–34)
- UTM naming is documented
- Campaign links are tested before launch
- Self-referrals and payment-provider referrals are excluded
- Direct traffic changes are investigated
- Analytics attribution is not presented as causal proof
Reporting and governance (35–40)
- Every recurring report has an audience and decision
- Metric definitions are available beside reports
- Owners receive alerts for broken critical events
- New events require a business purpose and owner
- Access and unused dashboards are reviewed quarterly
- The audit has a remediation owner and due date
How to prioritize audit findings
Fix issues that can reverse a business decision first: missing purchases, duplicate conversions, personal-data leakage, broken campaign attribution, and undocumented definition changes. Next fix friction that slows routine analysis. Cosmetic dashboard cleanup comes last.
| Priority | Example | Response |
|---|---|---|
| Critical | Personal data in event payloads | Stop collection and remediate immediately |
| High | Purchases duplicated | Fix before using conversion reports |
| Medium | Inconsistent campaign naming | Standardize before next campaign |
| Low | Unused dashboard clutter | Clean during scheduled maintenance |
Recommended audit cadence
Run a lightweight conversion and privacy check after meaningful releases, a monthly data-quality review, and a full quarterly audit. Repeat the full audit after migrations, checkout changes, domain changes, or a new consent-management setup.
Put the guide into practice
TrailPixel combines cookieless tracking, automatic funnel detection, and A/B testing in one workflow.
Start free