GA4 Audit: A 25-Point Checklist to Check Whether Google Analytics Measures What It Should

October 1, 2026 9 min readKarol Majewski
GA4 Audit: A 25-Point Checklist to Check Whether Google Analytics Measures What It Should

A GA4 audit is a systematic check of whether Google Analytics 4 collects data correctly: whether every pageview and every event is counted once, whether property settings distort the reports, and whether measurement respects user consent. It is worth doing because GA4 does not report its own errors — a misconfigured property looks as credible in reports as a correct one, and you base ad budgets on those numbers. Below is the checklist we use at our marketing agency when reviewing measurement.

What a GA4 audit is and when to run one

A GA4 audit checks three things: whether data is complete (nothing gets lost), clean (nothing is counted twice or comes from your own team) and compliant with the law. Run it after an implementation or migration, after every site redesign and cookie banner change, after launching a new campaign with a sales goal, and on a regular quarterly rhythm. The first full review usually takes 2–3 hours.

Layer 1: does the tag fire once per pageview and in the right place

A correct GA4 tag sends one page_view event per pageview, from one measurement ID (G-XXXXXXXX), to Google's collection endpoint. The most common mistake is a double implementation: code pasted by hand into the template plus the same tag fired from Google Tag Manager, which produces two page_views per pageview, inflated sessions and a deflated bounce rate.

  • Open the site with GTM preview (Tag Assistant) on and count page_view events per pageview in GA4 DebugView — there should be one.
  • In the browser's Network tab filter requests by “collect”: check how many G- IDs the site uses and whether each is intended (old properties left by previous agencies are common).
  • Watch for UA- IDs: Universal Analytics has not collected data since July 2023, so such a tag is dead code that only slows the page down.
  • Hits from Europe usually go to a regional Google address (e.g. region1.analytics.google.com) — that is normal and does not mean a custom server. A server-side setup is recognized by a first-party domain, which we cover in server-side tracking: is it worth it.
  • Check pages after navigation without a reload (SPA stores): page_view must fire on a view change too, not only on the first visit.
  • Open a non-existent URL: the 404 page should carry the same tag, so you can see where you lose users.

Layer 2: do funnel events send complete data

E-commerce funnel events are the path view_item_list, view_item, add_to_cart, view_cart, begin_checkout and purchase, and each one must carry parameters: a product list (items), currency and value. Without them the Monetization report is empty or incomplete, and Google Ads and Meta campaigns have nothing to learn from.

EventWhen it should fireWhat is most often wrong
view_itemOpening a product pageMissing items, or it also fires on category pages
add_to_cartAdding to cart (also from a listing and a cart drawer)Measured only on the product page, not in the drawer
begin_checkoutEntering checkoutMissing when checkout sits on a separate domain or an external payment page
purchaseA confirmed order, onceNo transaction_id; refreshing the thank-you page counts the purchase again
generate_lead (service sites)After the form is submitted, not on button clickFires on the click itself, including on validation errors
Funnel events and what to check in each

The costliest mistake in this layer concerns the purchase event. Without a unique transaction ID (transaction_id), the same transaction is counted every time a customer refreshes the confirmation page or returns to it from an email, and revenue in reports grows artificially. Check in DebugView that transaction_id is filled in and that one test order produces exactly one purchase event. If you set budgets from ROAS, also read Break-even ROAS and maximum CPC, because inflated revenue inflates ROAS too.

While you are there, check that the currency in events is set by the store and not by GA4's default. Revenue reports rely on that value, so a missing currency means a purchase with no revenue. If GA4 is linked to Google Ads, also check that the key event you optimize campaigns for is the right one — you can compare against the setup in our GA4 service.

Layer 3: which GA4 property settings to review

Property settings determine how GA4 interprets correctly sent data, and most “silent” errors live here because nobody reviews them after implementation. Retention matters most: by default GA4 keeps event data for 2 months and for 14 at most, so year-over-year analysis in Explorations only works after you change this setting.

SettingWhereWhat to look for
Event data retentionAdmin → Data collection → Data retentionSet 14 months (default is 2)
Internal trafficStream → Configure tag settings → Define internal traffic, then a data filter in the “Active” stateTeam and agency visits inflate sessions; a filter in “Testing” state excludes nothing
Referral exclusionsStream → Configure tag settings → Show all → List unwanted referralsPayment gateways (e.g. PayU, Przelewy24) should not start a new session
Key eventsAdmin → Events → Mark as key eventUp to 30 in a standard property; keep only those with business value
Custom definitionsAdmin → Custom definitionsAn event parameter without a registered definition will not appear in reports (limit of 50 event-scoped dimensions in a standard property)
Time zone and currencyAdmin → Property detailsMust match the market and the store, otherwise daily totals differ from the order system
Attribution windowsAdmin → AttributionCheck that the key event window fits the length of your buying cycle
GA4 property settings to check in an audit

Referral exclusions directly change the sources report. When a customer pays through an external gateway and returns to the site, GA4 may treat the gateway as a new traffic source and credit it with a purchase that actually came from an ad. The result is deflated campaigns and inflated “referral”. Add payment and login gateway domains (e.g. paypal.com) to the unwanted referrals list.

Layer 4: does measurement respect consent and avoid collecting personal data

Correct measurement honors user consent: without consent, tags do not collect identifiers, and with Consent Mode v2 they send only cookieless signals. The second part of this layer is personal data: Google prohibits sending email addresses, phone numbers and names to GA4, and it happens more often than you would assume, for example through a page URL with an ?email= parameter or a form field value sent as an event parameter.

  • Review URLs with parameters in the Pages and screens report: if you see emails, names or order numbers tied to a person, they need to be redacted or no longer sent.
  • In DebugView check the parameters of form and site search events: a search box is often where customers type their own data.
  • Test the site in three states: before choosing in the banner, after accepting and after rejecting. Scripts should not send hits with a client ID before consent.
  • After a consent change, gtag sends page_view again so the hit carries the “granted” state. That is not a double implementation, but tell it apart from two hits from two tags.
  • We describe configuration details and the impact on data in Consent Mode v2: how much data you lose; you can test the banner with the free Consent Mode Checker.
Risograph-style illustration: a detective with a magnifying glass over a bar chart in which the same bar has been counted twice

What you can check yourself in an hour and what needs container and account access

From the outside you can only verify what is visible in the browser's network traffic: the number of tags, measurement IDs, sent events, parameters and request addresses. The inside of the property (retention, key events, links, filters) and the GTM container configuration are visible only to a person with access, which is why a full audit combines both approaches.

  • You can check yourself in an hour: DebugView and Tag Assistant (tag, page_view, funnel events on a test order), URLs with personal data in the Pages and screens report, retention and internal traffic in the settings.
  • A quick scan from a URL: our free GA4 audit opens the site, clicks consent and checks tags and events (up to the first checkout step); it never submits an order or a form.
  • Needs access: trigger rules in GTM, browser and server deduplication, links to Google Ads, custom definitions and revenue reliability against the store system.

What to do with the GA4 audit results

After the audit, order fixes by their impact on decisions, not by their position on the list: first whatever distorts revenue and conversions (a doubled page_view, purchase without transaction_id, missing currency), then whatever distorts sources (referral exclusions, internal traffic), and last the housekeeping (event names, dead tags, definitions). Verify every fix in DebugView and note the deployment date, because from that day the data in reports stops being comparable with earlier data.

When measurement runs through the browser and you lose some events to blockers and Safari, the next step is sometimes moving tags to your own server — if you are considering it, start with the server-side GTM offer and the article on whether it pays off, and fix the basics from this checklist first, because server-side repeats configuration errors instead of fixing them. Data loss without cookies has its own scale, described in Conversions Without Cookies.

FAQ: GA4 audit

Q.How do I check whether GA4 measures correctly?

Open the site with Tag Assistant and DebugView on, run the purchase path with a test order and count the events: one page_view per pageview, one each of view_item, add_to_cart, begin_checkout and purchase with a filled-in transaction_id. Then compare the number of orders and revenue in GA4 with the store system for the same period.

Q.What difference between GA4 and the store is normal?

A small discrepancy is normal, because some users reject consent or block scripts and GA4 does not see their purchases. If the gap exceeds a dozen or so percent or changes from week to week, look for the cause: a missing transaction_id, a purchase event on a page that part of customers never reach, or a misconfigured consent banner.

Q.How often should I run a GA4 audit?

A full review once a quarter and after every site redesign, cookie banner change, platform migration or new tag deployment. Before a big sales campaign a shorter version is worth doing: tag, funnel events and currency.

Q.How long does a GA4 audit take?

A basic review of the tag, events and settings takes 2–3 hours for one property. A store with several domains, a server-side GTM or several GA4 properties usually takes a few days, because you have to go through container configurations and compare data with external sources.

Q.Does a GA4 audit require account access?

Partly. Events, tags and parameters can be checked from the outside by looking at the browser's network traffic, but property settings (retention, key events, Google Ads links, filters) are visible only after signing in with read permissions.

Author
Karol Majewski
Karol Majewski
Co-founder of the digital agency Zest

Implements and audits GA4 and GTM measurement for online stores and service businesses. In most audits the problem is not in the reports but in what the tag sends from the page.

Related articles

Contact

Let's talk growth

Send a brief or drop your contact — we'll reply within 24h.

Get a quote
Founders