Checklist guide

Website consent audit checklist

A website consent audit checklist should compare visible consent controls with observed tracking and cookie behavior before and after user choices. CertScore.ai helps teams structure that review with automated public website evidence.

By CertScore.ai · Updated

Start your consent review with a website scan

Enter a public page URL to gather observations for this checklist. Review visible controls, runtime activity, and available action evidence separately, then record unresolved questions in the worksheet.

Loading scan form…

Start with a free scan of one public page. This is not a full-site audit; results describe the scan’s conditions and coverage. Review the retained evidence before making changes.

See how to read a report

Scope and ownership

Record the URL, scan date, region, browser context, CMP version, tag-manager version, reviewer, and responsible implementation owner. List the public pages and templates included and the areas that remain untested.

Document expected behavior for essential services, analytics, advertising, and embedded content. Keep legal interpretation with the appropriate reviewer; the technical audit records observations.

Untouched baseline

Use a fresh session without stored consent. Record whether Accept, Reject, and Options controls were observed, and whether the inventory was complete. Unknown is different from not observed.

Review retained pre-consent requests, cookie/storage timing, vendor classifications, and policy evidence. Record a reference for each observation; do not derive tracking from a screenshot or third-party hostname alone.

Independent Accept and Reject checks

For each eligible action, record whether a unique control was actionable, whether the click completed, whether the decision was semantically verified, and whether the capture window completed. Preserve unverified and unavailable outcomes.

Review request ancestry after Reject and separate pre-click work from later requests. Treat Accept as a comparison baseline. Cookie presence alone does not establish active tracking after refusal.

Policy and runtime comparison

Confirm that the retained policy belongs to the target site. Compare a specific disclosed claim with directly comparable runtime evidence in the same scope and consent state.

Record missing or insufficient evidence as a limitation. Do not turn an inaccessible policy or an incomplete observation into a proven mismatch.

Remediation record

For each item record: observation, retained evidence reference, expected behavior, implementation owner, proposed change, status, and retest date. Keep cookie values and sensitive query parameters out of shared notes.

Inspect consent-category mappings, tag triggers, embedded scripts, and vendor settings. Preserve the original report and compare the changed behavior under matching fresh-session conditions.

Closure and monitoring

Close an item only when its evidence and retest support the expected change. If the site is blocked or the capture is incomplete, keep the item open or explicitly inconclusive.

Repeat review when CMP settings, tags, vendors, or templates change. A successful bounded observation is not certification and does not cover every region, visitor state, or future request.

Put the checklist to work on your website

Start with one page, review its evidence, then use “Scan another website” in the report to review another client, brand, or public site.

Enter a website URL
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.