Measurement / audit

GA4, tracking and Consent Mode audit

A fixed-scope technical audit of your GA4, Google Ads, tag manager and consent setup. Nine checks, each recorded with the evidence behind it, returned as a severity-rated findings log.

Access we need

  • GA4, read-only
  • Google Tag Manager, read-only
  • Google Ads, read-only
  • Consent platform, read-only

No admin rights, no billing access and no ability to publish. Access is read-only throughout and revoked on delivery.

The nine checks

ad_storage
Whether ad_storage is operating as the sole control for advertising data across your linked GA4 and Google Ads accounts, against the change of 15 June 2026.
Consent Mode
The four Consent Mode parameters, and whether they pass before your tags fire or after.
Tag order
Tag firing order, recorded per tag against each consent state.
Server-side
Server-side tagging readiness, and what is running client-side that should not be.
Conversions API
Conversions API coverage and event deduplication across your platforms.
Imports
Conversion imports between Google Ads and GA4, including offline imports.
DUAA
GA4 configuration against the DUAA exemptions in force from 5 February 2026, where analytics also feeds advertising or profiling.
Third-party scripts
Third-party scripts your site instigates, mapped against the ICO's storage and access guidance of 29 April 2026.
Continuity
Cross-domain and subdomain continuity, and whether session identity survives the checkout hop.

Checks that do not apply to your setup are listed in the report as not applicable, with the reason. A short report is a scoped report.

What you get

A written report, dated and signed. Every finding carries the evidence that produced it: a screenshot, a timestamp and a request trace, so your own team or your agency can re-run it and get the same answer.

Findings are assigned to a role, never to a person: your tag manager administrator, your consent platform vendor, your media agency, or us. No individual at your company is named in the document.

Fixes are costed from a fixed band table and published in the report as a range. If you disagree with a finding we re-run that check once at no charge and either uphold it or withdraw it in writing.

The report describes how your tags and consent signals behave. It is a technical record written so your solicitor can use it, and it does not give legal advice. If you would rather the work sat under privilege, your solicitor engages us instead of you. Same audit, same report.

How findings are graded

Severity 1Advertising or conversion data is being lost or misattributed now. The affected volume is estimated in the finding.

Severity 2A control you believe is operating is not, including consent signals that do not pass before tags fire.

Severity 3Configuration that will fail at a known future date, with the date stated.

Severity 4Observation. No action needed.

The audit is one way into our measurement and tracking work. If what you need is the build rather than the audit, say so and we will skip it.

Ask about the audit

One email starts it. No form, no queue, no account to create, and no discovery call before anyone has told you anything useful.

Email us

That opens a message to info@mktg-consulting.com with the four things we need already listed. Answer what you can and we will ask for the rest.

What to include

  • Which of the four areas you are asking about, or that you are not sure
  • What is already in place, and roughly how long it has been there
  • What is driving the timing, because that usually decides the shape of the work

We reply to every enquiry within one working day, including the ones we are not right for. If it is not work we should be doing we will say so and, where we can, say who should. A site promising a reply and never saying when is a promise nobody can hold us to.