Why GA4 audits matter in 2026
GA4 replaced Universal Analytics in July 2023, but most setups were migrated under time pressure - copy the tag, tick the box, move on. Three years later, the same sites are running GA4 with misconfigured Consent Mode, duplicate tags from the migration period, or Enhanced Measurement events that clash with custom event tracking.
Beyond data quality, GDPR enforcement has increased. Regulators across the EU are specifically targeting pre-consent analytics tracking - GA4 firing before a user interacts with a cookie banner is now one of the most common causes of fines for small and mid-size businesses.
GA4 audit checklist - 7 checks
Verify the GA4 measurement ID is loading
Open DevTools Network tab, filter for "collect?v=2" or "analytics.js". You should see requests to www.google-analytics.com/g/collect. If missing, the GA4 tag is not firing - check GTM or your hardcoded snippet. A server-side audit can detect this without opening DevTools.
Check Consent Mode v2 defaults are set before GA4 fires
GA4 must receive gtag consent defaults before the page_view fires. In GTM, look for a Consent Initialisation trigger that sets denied defaults for analytics_storage, ad_storage, ad_user_data, and ad_personalization. Check this fires before the GA4 Configuration tag.
Confirm Enhanced Measurement is configured intentionally
GA4 Enhanced Measurement auto-tracks scrolls, outbound clicks, site search, video engagement, and file downloads. Go to Admin - Data Streams - your web stream - Enhanced Measurement. Disable any events you do not want (e.g. site search if your search URL contains query params that inflate sessions).
Audit your key events (formerly conversions)
GA4 renamed "conversions" to "key events" in 2024. Go to Admin - Events and check which events are marked as key events. Common issues: purchase event not marked, duplicate conversion events from both GA4 and GTM, or test events from development still firing.
Check for duplicate GA4 tags
If you migrated from Universal Analytics and added GA4 tags in GTM while also having a hardcoded snippet in your site template, you will see double page_views. Check by filtering Network requests - you should see exactly one /g/collect request per page load.
Verify cross-domain tracking if applicable
If your checkout or booking flow runs on a different domain (e.g. checkout.yourdomain.com), you need cross-domain measurement configured. Check Admin - Data Streams - Configure tag settings - Configure your domains. Without this, sessions break and source attribution resets at checkout.
Run a compliance scan to check GDPR and tracking status together
Manual checks cover the GTM/GA4 configuration layer but miss consent flow behaviour (what fires before a user accepts the cookie banner). A server-side audit can detect pre-consent GA4 firing, missing Consent Mode signals, and whether your CMP is wired correctly - all from a URL scan with no login required.
8 most common GA4 issues found in audits
Manual audit vs automated GA4 audit tool
The 7-step checklist above covers configuration issues you can find by reading GTM and the GA4 Admin panel. But it does not catch runtime behaviour - what actually fires in the browser during a real page load, and whether your Consent Mode signals are respected by the live CMP integration.
A server-side GA4 audit tool loads your URL in a headless browser, intercepts all network requests, and reports what is actually firing - GA4 measurement IDs, Consent Mode status, GTM container health, and any pre-consent tracking detected. No Google login or GA4 account access required. Results in under 60 seconds.
Run a free GA4 audit on your site
GetInlytics scans your URL and checks GA4 measurement ID, Consent Mode v2 signals, GTM container health, and GDPR compliance. No login, no GA4 account access needed.
Run free GA4 audit