# Website consent audit worksheet

Published by CertScore.ai, September 14, 2026. This blank worksheet is a review aid, not a scan result or compliance certificate. You may reuse it with attribution to https://certscore.ai/guides/reject-consent-tracking-test.

## Scope

- Reviewer and implementation owner:
- Exact public URL and page/template:
- Date, time and time zone:
- Region and browser context:
- CMP and tag-manager versions, if known:
- Report/evidence reference:
- Pages, regions and visitor states not covered:

## Baseline — a fresh session without a stored choice

- First-layer inventory complete? Yes / No / Unknown:
- Accept / Reject / Options: Observed / Not observed / Unknown:
- Classified tracking requests before any choice:
- Cookie/storage identities and timing:
- Retained evidence references:
- Coverage limitations:

## Action — an independent fresh session for each choice

- Action: Accept / Reject:
- Exact target retained during the action? Yes / No / Unknown:
- Control and click time:
- Click: Completed / Failed / Not attempted / Unknown:
- Semantic decision: Granted / Denied / Mixed / Unknown:
- Registration: Verified / Unverified:
- Capture window: Complete / Limited:
- Activity dropped or missing? Yes / No / Unknown:
- Relevant request chain began: Before click / After click / Unknown:
- Vendor and purpose classification:
- Direct request/write evidence reference:
- Storage identity and unchanged-value evidence reference, if available:

Never paste raw cookie values, credentials, personal information or sensitive query values into this worksheet. An unchanged cookie alone does not prove active use. A completed click or hidden banner alone does not confirm a decision. Incomplete capture is a limitation, not a pass or observed gap.

## Review and remediation

| Observation | Evidence reference | Expected behavior | Owner | Proposed change | Retest result |
| --- | --- | --- | --- | --- | --- |
| | | | | | |

## Retest

- Original and new report references:
- Matching target, region, fresh state and scope:
- Configuration change and time:
- Specific request/storage behavior that changed:
- Remaining limitations:
- Outcome: Expected behavior observed in tested scope / Further review / Inconclusive:

Walkthrough: https://certscore.ai/guides/reject-consent-tracking-test
Full checklist: https://certscore.ai/guides/website-consent-audit-checklist
Sample report format: https://certscore.ai/sample-report
