Back to Blog

Web Analytics Audit Checklist for Small Businesses

Most analytics audit checklists are written for companies with a data team. Here's the one that fits a business with one website and no analyst.
Insights
September 18, 2026

You already know that conducting an audit of your website analytics set-up is critically important to accurately measuring the traffic on your website. However, if you are like many small business owners, you may put this seemingly arduous task off indefinitely. To make the audit a less daunting endeavor, I've created a stripped down 6-questions checklist for those whose job it is to prepare the shop, run the shop and clean up afterwards. Now you can get this chore out of the way with minimal effort.

1. Is the measurement installed correctly?

What to check

  • One analytics tracking code appears once on every page of your site, including pages added after launch.
  • Whether the tracking starts before or after your cookie banner asks the visitor for permission.

Common problems

Double-installed tags. You have the same tracking code installed twice on one or more pages. When that happens, your sessions, users and events are all reported at roughly double their real count. It usually happens one of two ways: the code was pasted both into your site's settings and into the page template, or you moved platforms or redesigned, the old code survived the move, and a new one was added on top of it. What to do: remove one of them, and keep the one you can see and control.

More than one tracking code. Here you have different tracking codes on different pages — some pages reported under one code, the rest under another. This commonly happens when analytics was set up early in the life of the website and then left alone. Later, new pages were added and a new tracking code went onto those, on the same website. Your numbers are now split between two codes and neither one accounts for all of your visitors. What to do: decide which code you're keeping, put it on every page, and remove the other. Be aware that the history recorded under the old code stays where it is — it doesn't move across.

How to check whether you have more than one tag installed

Go to tagassistant.google.com, enter your web address, and read two numbers: how many Google tags it found, and how many Page Views it lists under "Hits Sent." One tag and one page view is what you want. Check two or three other pages of your site the same way, and confirm the tracking code is the same every time.

Common problems, continued

Your site builder pre-empts your consent banner. Most site builders — often called Content Management Systems, or CMS — offer a settings box where you paste your Google Analytics ID and they install it on your website for you. It's the easy route, and if you don't use a cookie consent banner it's fine. But that box loads the tracking code before your banner can tell it whether the visitor agreed, which means tracking starts before permission is given. What to do: if consent matters to you, paste the code into your site's head code yourself, or use a tag manager, so that the consent instructions can sit above it.

How to check whether your tracking waits for consent

In Tag Assistant, open the page view it recorded and look at the consent state attached to it. If tracking is firing before the banner has been answered, the banner and the analytics aren't connected to each other.

2. Are the actions that matter being counted?

What to check

  • Write down the three to five things a visitor can do on your site that are worth money to you. Confirm each one is being recorded.
  • Confirm each one is recorded at the moment it actually happens, and only once.
  • Where money is involved, confirm an amount is recorded alongside it.

Common problems

Only visits are being counted. The site records traffic in detail and outcomes not at all. It's the most common gap I see in small-business setups, and it's the difference between counting everyone who walks past the shop and counting the ones who come in and buy something. What to do: pick your three most valuable actions — a purchase, a booking, a completed contact form, a tapped phone number — and set each one up to be recorded as a key event.

The action is recorded at the wrong moment. A form that records a conversion when the page opens, rather than when the form is submitted, will tell you almost everyone converts. What to do: submit your own form and confirm the count goes up once, at the point of submitting.

Things that happen off the website aren't counted at all. The phone call, the walk-in, the reply to your email. What to do: you don't need to automate this. Counting them by hand once a month is enough to keep the website's numbers in proportion.

How to check whether your key actions are being recorded

In Google Analytics, open the Realtime report on one screen and your website on another. Complete the action yourself — submit the form, make the booking — and watch for it to appear. If it doesn't show up within a minute or two, it isn't being recorded.

3. Are users being miscounted due to visiting your site from different starting points?

What to check

  • If your booking or payment happens at a different web address than your main site, confirm one visitor isn't being counted as two.
  • Check whether your own website appears in your list of traffic sources.

Common problems

Booking or checkout sits at a different web address. Say someone finds you through a Google search, lands on your site, and clicks "Book Now" — and that button sends them to a scheduling or payment service at a different web address, such as a Square, Calendly or Shopify page. Analytics treats those two addresses as two separate websites, so it records two separate visitors: one who arrived from Google, looked around and left without booking, and another who appeared from nowhere, arrived from your own website, and booked. The booking gets credited to your own site, and the Google search that actually brought the customer in looks like it produced nothing. The same thing happens to a link in an email or a social post. What to do: the fix is a one-time setup called cross-domain tracking, which tells analytics those two addresses belong to one business so the visit stays in one piece. It's worth asking for help with if you're not sure.

Your own website appears as a source of its own traffic. This is what the problem above looks like in your reports — the second half of that split visit, arriving from your own address. What to do: add your own addresses to the referral exclusion list so a hop between them doesn't start a new visit.

User switches devices or browsers. Someone finds you on a phone and comes back on a laptop; someone browses privately. Those are two visitors in your reports and there's no setting that repairs it. What to do: nothing, other than knowing it. It's the reason a number like "new visitors" is always somewhat higher than the number of new people.

How to check whether your visits are splitting off

Open the report that lists where your traffic comes from. If your own web address is in that list, visits are splitting off somewhere in the middle.

4. Do you know where your traffic actually comes from?

What to check

  • Confirm the links you send out — in email, on social media, in ads — are tagged so analytics knows where they came from.
  • Check that the tags you use are spelled the same way every time.
  • Check whether "Direct" traffic is implausibly large.

Common problems

Untagged links. A link you post without tagging arrives in your reports as "Direct" or as something unhelpful, so the campaign that brought the visitor in gets no credit. What to do: use Google's Campaign URL Builder to add the tags. It's a form — you paste your link in and it hands you a tagged version to use.

Inconsistent spelling. Facebook, facebook and FB are three separate sources in your reports, permanently. What to do: choose one convention, write it down somewhere you'll find it again, and use lower case for everything.

"Direct" is much bigger than it should be. Direct means someone typed your address in or used a bookmark. On a small site, a very large Direct number is almost always untagged links rather than a devoted audience. What to do: tag the links and watch the number redistribute over the following weeks.

5. Is the data clean?

What to check

  • Confirm your own visits — and your web developer's — are excluded.
  • Confirm no personal information is landing in your reports.
  • Check how long your data is set to be kept.

Common problems

You're counted as one of your own customers. On a small site, your own visits can be a meaningful share of the traffic, and they'll cluster on exactly the pages you're trying to evaluate. What to do: set up an internal traffic filter so your own visits are excluded.

Personal information is landing in your reports. This happens by accident. A form that puts an email address into the page's web address will send that address straight into your page reports, where it isn't supposed to be and where you're not permitted to keep it. What to do: open the report listing your most-viewed pages and look for an @ symbol or anything resembling a name, an address or a phone number. If you find any, the form needs changing — and the data collected so far needs removing.

Your history disappears sooner than you expect. Data retention is set to two months by default in Google Analytics, which means the detailed reports you'll want for a year-on-year comparison won't be there. What to do: change it to 14 months, the longest available on the free version. This only affects data from the point you change it, so it's worth doing early.

6. Does your cookie banner actually control the tracking?

What to check

  • Confirm the banner appears in a fresh private window, on more pages than just the homepage.
  • Confirm that declining genuinely stops the tracking.
  • Confirm the visitor's choice is remembered as they move between pages.

Common problems

The banner appears but controls nothing. The banner shows, the visitor declines, and the tracking carries on regardless. Nothing looks wrong from the outside. I'll say plainly that this happened on my own site: the banner looked correct and governed nothing for three weeks, and the only way I found out was by checking whether the tracking still fired after I declined. What to do: run the check below. If declining doesn't stop the tracking, the banner and the analytics aren't connected, and that's a setup problem rather than a settings problem.

The banner only appears on the homepage. Visitors arriving from search usually land somewhere else. What to do: check two or three interior pages, including a blog post.

The choice isn't remembered. If the banner reappears on every page, the visitor's decision isn't being stored, and the tracking is likely making its own decision each time. What to do: click through three pages after answering it once.

How to check whether declining actually stops the tracking

Open your site in a private window and decline the banner. Then open your browser's developer tools (Command + Option + I on a Mac, Control + Shift + I or F12 on Windows), click the Network tab, type collect in the filter box, and reload the page. After a decline, there should be no lines at all.

What to do with what you find

Fix the collection before you change the site. If you correct a double-installed tag and redesign your homepage in the same week, you won't be able to tell which one moved the numbers. Fix the measurement, let it run clean for two weeks, and treat that as your starting line.

Rank the rest by effort. Most of what an audit turns up takes an afternoon — a filter, a key event, an exclusion, a consent setting. The items that need real budget are usually few, and they're easier to justify once the quick ones are done.

Expect to learn something about the business. An audit usually surfaces something nobody was looking for: a traffic source you didn't know you had, a page doing most of the persuading, a path nobody designed but everyone follows. That isn't the purpose of the audit. It's what becomes available once the numbers are believable.

How often to do this

Twice a year for most small sites, plus once after anything structural — a redesign, a platform move, a new booking or payment system, a change of web address. Those are the moments when measurement tends to break without anyone noticing, and also the moments you most want to know whether the change worked.

If you want the reasoning behind all of this — why an audit is a map rather than a report card — I've written about what a web analytics audit actually tells you.

If you'd rather not work through this alone, that's what the GA4 Health Audit is for — I go through this list properly and hand you a plain-language map of which numbers you can trust, what to fix, and in what order. Get in touch and let's take a look together.

Get Started

Ready to Strategize 
Your Next Move?

Let’s talk about your next milestone—and how to reach it
Consulting & strategist Webflow template
Alex Tran
Founder & CEO