In short: A GA4 audit is a systematic review of the property settings, data collection, events, attribution and consent in Google Analytics 4, to confirm that the numbers in your reports reflect what actually happens on the site. The checklist below has 25 checks across five areas, and you can work through it yourself in one to two hours. The three problems we find most often: data retention left at the two-month default, the payment page showing up as a traffic source and "stealing" the sale from the campaign, and a purchase event that fires twice. In 2026 two new items joined the audit: the AI Assistant channel (May 2026) and the hostname filter (June 2026).
This page was rewritten in September 2026. It does not explain what GA4 is (for that, read our complete Google Analytics 4 guide) and it does not list measurement types (types of measurements in Analytics 4). It answers one question: can you trust your data, and how do you check. If you want someone to run the audit and fix what it finds, that is our Google Analytics specialist service.
What is a GA4 audit and when do you need one?
A GA4 audit is a configuration and data-quality review, not a performance report. It does not ask "how many leads did we get this month" but "was every lead counted, exactly once, and credited to the right channel". The difference matters: budget decisions in Google Ads, conversion optimization and channel mix all rest on this data, and wrong data looks exactly like right data.
When to run one:
| Situation | Why now | Urgency |
|---|---|---|
| After a new site launch, platform migration or theme change | Tracking code gets dropped, duplicated or moved to another domain | High, the same week |
| Before increasing ad spend | Bidding algorithms learn from the conversions you send them | High |
| Orders in your system and in GA4 differ by more than 10% | A classic sign of a missing, duplicated or blocked event | High |
| A high share of Unassigned or (not set) in reports | Broken UTM tags or events sent without a session | Medium |
| A new marketing vendor or in-house team | Nobody knows who configured what, or why | Medium |
| Routine | Google changes the product several times a year | Once a quarter |
Part 1: Property settings (checks 1-6)
| # | What to check | Where | What good looks like |
|---|---|---|---|
| 1 | Data retention | Admin → Data collection and modification → Data retention | 14 months on a standard property. The default is two months, and it applies to Explore reports |
| 2 | Time zone and currency | Admin → Property details | Your business time zone and the currency your store actually sells in |
| 3 | Internal traffic filter | Admin → Data streams → Configure tag settings → Define internal traffic, then Data filters | An IP rule for the office and team, with the filter set to Active, not Testing |
| 4 | Hostname filter (new, June 2026) | Admin → Data filters | Events from staging, dev environments or sites that copied your code stay out of the property |
| 5 | Search Console link | Admin → Product links | Linked, so organic queries appear next to landing pages (see our Google Search Console guide) |
| 6 | User access | Admin → Property access management | No users from former vendors, and at least two people in the business with Administrator access |
Why check 1 matters more than it looks: standard reports keep showing historical data even with two-month retention, so nobody notices. The problem only surfaces when you try to build a year-over-year comparison or a funnel in Explore, and the data simply is not there. The change applies from the day you make it, not retroactively.
Part 2: Data collection (checks 7-12)
| # | What to check | How to check | The common failure |
|---|---|---|---|
| 7 | Exactly one tracking implementation | Tag Assistant or the browser Network tab, filter for collect?v=2 | gtag hard-coded in the theme plus a tag in Google Tag Manager = every page view counted twice |
| 8 | Coverage of every page | Pages and screens report against your sitemap | Thank-you page, external landing pages or a checkout on another domain without the tag |
| 9 | Enhanced measurement | Admin → Data streams → Web | Automatic form tracking firing on every search box and inflating "conversions" |
| 10 | Unwanted referrals | Configure tag settings → List unwanted referrals | The payment page (PayPal, Stripe checkout or a local gateway) appears as a source and takes the credit instead of the campaign |
| 11 | Cross-domain measurement | Configure tag settings → Configure your domains | Site and booking system on different domains = a new session in the middle of the purchase |
| 12 | Property diagnostics | The notifications bell and Task Assistant (April 2026) | An alert about missing GBRAID or gad_ parameters in URLs (July 2026) that nobody read |
Check 10 is the one most businesses fail. When a customer goes to an external payment page and returns to the thank-you page, GA4 treats them as arriving from the payment domain. In the Traffic acquisition report it looks like a "traffic source" with a perfect conversion rate, and in reality it erases the credit of the campaign that brought the customer. Adding the domain to the list fixes it.
Part 3: Events and key events (checks 13-18)
| # | What to check | What good looks like |
|---|---|---|
| 13 | Key events list (formerly Conversions) | Only real business actions: lead, purchase, call, sign-up. Not page_view, not scroll |
| 14 | The lead event fires only on a successful submit | Tested in DebugView: a submission with a missing field creates no event |
| 15 | purchase event with a unique transaction_id | Refreshing the thank-you page does not create a second purchase |
| 16 | value and currency on every monetary event | GA4 revenue within a few percent of your system, in the same currency |
| 17 | Complete ecommerce events (view_item, add_to_cart, begin_checkout) | A purchase funnel with no gaps between steps |
| 18 | Custom parameters registered as custom dimensions | A parameter that is sent but not registered will not appear in any report |
The simplest test for this part: compare 30 days of purchases or leads in GA4 against your own system (Shopify, WooCommerce, CRM). A gap of up to 5%-10% is normal, caused by ad blockers and users who declined cookies. A gap of 30% or more, in either direction, is a fault. More conversions in GA4 than in your system almost always means double counting.
Part 4: Traffic sources and attribution (checks 19-22)
| # | What to check | What good looks like |
|---|---|---|
| 19 | Share of Unassigned in the channel report | Low. A high share = non-standard UTMs (utm_medium=Facebook instead of paid_social and so on) |
| 20 | AI Assistant channel (new, May 2026) | Traffic from ChatGPT, Gemini and Claude appears in its own Default Channel Group channel instead of disappearing into Referral |
| 21 | Google Ads link and key event import | The property is linked and the primary conversion is counted once: from GA4 or from the Google Ads tag, not both as primary |
| 22 | Attribution model and conversion window | The choice is documented. Since August 2026 you can set a custom window: 1-90 days for clicks and 1-30 days for engaged views |
About check 21: this is an expensive trap. When both the GA4 conversion and the Google Ads conversion tag are set as primary, the bidding system sees two conversions for every lead, concludes the campaign is twice as profitable, and raises bids. If you run Google campaign management, this is the first check to do.
Part 5: Privacy and consent (checks 23-25)
| # | What to check | What good looks like |
|---|---|---|
| 23 | Consent Mode v2 | All four signals (analytics_storage, ad_storage, ad_user_data, ad_personalization) are sent and update with the visitor's choice |
| 24 | A cookie banner that is actually wired to the tags | Declining blocks advertising tags. A "decorative" banner that changes nothing is a regulatory risk under GDPR and Israel's Privacy Protection Law Amendment 13 |
| 25 | No personal data in URLs or parameters | No email, phone or name in thank-you page URLs or event parameters. Google prohibits sending PII to Analytics |
What changed in GA4 in 2026 that affects the audit
| Date | Change | What it means for the audit |
|---|---|---|
| 2026-01-16 | Cross-channel budgeting, a conversion attribution analysis report and improved conversion management for Google Ads advertisers (beta) | Check whether your property qualifies before buying an external attribution tool |
| 2026-02-10 | Generated insights on the Home page: the three biggest changes in your data | An automatic insight is only as good as the data beneath it |
| 2026-04-29 | Task Assistant: configuration recommendations tailored to the property | A good starting point for the audit, not a replacement |
| 2026-05-07 | Data Manager API as an alternative to the Measurement Protocol | Relevant for server events (CRM leads, phone sales) |
| 2026-05-13 | AI Assistant channel in the Default Channel Group | Check 20. Make sure a custom channel group does not override it |
| 2026-06-08 | Google Business Profile integration: calls, bookings and direction requests | For local businesses, measuring actions that do not happen on the site |
| 2026-06-11 | Source Group (consolidating Facebook, Instagram and TikTok source values) and the hostname filter | Check 4, and cleaner source reports |
| 2026-07-28 | Cost data import requires a currency field mapping | Importing Meta or TikTok costs without currency will fail |
| 2026-07-30 | Diagnostic alert for missing GBRAID and gad_ identifiers in URLs | Check 12. Usually a redirect that strips parameters |
| 2026-08-11 | Custom conversion window for clicks (1-90 days) and engaged views (1-30 days) | Check 22 |
| 2026-09-09 | Dashboards with drag-and-drop and new visualizations | Worth building after the audit, not before |
How to run the audit: a two-hour order of work
- 15 minutes - Admin: checks 1-6. These are one-click changes, and fixing data retention should start today.
- 30 minutes - DebugView and Tag Assistant: walk the site like a customer, submit a form, add to cart and reach the thank-you page (for a store, a test purchase). Note every event that fires, fires twice or does not fire.
- 30 minutes - reconcile against your system: 30 days of leads or orders in GA4 against the CRM or store, including revenue.
- 20 minutes - channel report: Unassigned, (not set), payment domains as sources, and AI Assistant traffic.
- 15 minutes - Google Ads: which conversion actions are primary, and from which source.
- 10 minutes - consent: decline cookies and confirm in the Network tab that advertising tags do not fire.
When to do it yourself and when to bring in an expert
Checks 1-6, 9, 13 and 19 can be done by any business owner with Administrator access using this checklist. The checks that need experience are the ones where you have to read code and understand how systems talk to each other: double counting (7, 15), payments and domains (10, 11), duplication with Google Ads (21) and Consent Mode (23). A single fault there can skew the entire ad budget, and that is where it pays to work with a Google Analytics 4 expert who also understands the campaign side. If the audit exposes wider funnel problems, the next step is a full marketing audit or conversion rate optimization.
Sources and methodology
Dates and capabilities on this page come from Google's official documentation: What's new in Google Analytics (AI Assistant channel, hostname filter, Source Group, Task Assistant, Data Manager API, custom conversion window, GBRAID alert, Dashboards and cross-channel budgeting), and the Google Analytics Help Center for data retention, unwanted referrals, cross-domain measurement and Consent Mode. The order of checks, the reasonable gap ranges (5%-10%) and the list of common failures are observations by the SFB team from properties we audit and manage, not official Google figures. Written by Shay Cohen, CEO and founder of SFB, last updated on September 19, 2026.
Frequently Asked Questions about GA4 audits
What is a GA4 audit?
A GA4 audit is a review of the property configuration and data quality in Google Analytics 4: data retention, tracking code, events and key events, traffic sources and attribution, and cookie consent. The goal is to confirm that every lead and purchase is counted once and credited to the right channel before you make budget decisions based on it.
How long does a GA4 audit take?
A basic audit using this checklist takes one to two hours for a brochure site or small store. For a store with several domains, an external payment page, an app or server-side events, a full audit including fixes can take several working days.
How do I know GA4 is tracking correctly?
Compare 30 days of purchases or leads in GA4 against the source system (your store or CRM). A gap of up to 5%-10% usually comes from ad blockers and declined cookies. A larger gap points to a missing, duplicated or blocked event, and more conversions in GA4 than in your system almost always means double counting.
Why does my payment page show up as a traffic source in GA4?
Because the customer returns from the payment domain to the thank-you page, and GA4 treats that return as a new referral. The fix is to add the payment domain to List unwanted referrals in the tag settings, so the sale stays credited to the campaign that brought the customer.
What is the default data retention in GA4?
Two months. On a standard property you can extend it to 14 months under Admin → Data retention. The setting affects Explore reports rather than standard reports, which is why it gets forgotten, and the change only applies from the day you make it.
What is the AI Assistant channel in GA4?
A channel Google added to the Default Channel Group on May 13, 2026 that groups traffic from AI assistants such as ChatGPT, Gemini and Claude. Before that, this traffic mostly landed in Referral. If your property uses a custom channel group, make sure it does not reclassify this traffic.
Can I run a GA4 audit myself?
Most of the configuration checks, yes, with Administrator access and the checklist on this page. Checks for double counting, cross-domain measurement, conversion duplication with Google Ads and Consent Mode require reading code and knowing the ad platforms, and that is where it is better to work with an analytics specialist.
How often should I audit GA4?
Once a quarter as routine, plus immediately after a new site or theme launch, a platform migration, a payment provider change, or before a significant increase in ad spend.




