"The conversion rate has fallen by 12%." Before correcting the offer, you have to answer another question: has the behaviour changed, or the measure?
A new banner can reduce observed events. An update can double purchases. A payment on another domain can break the session. A CRM can create two leads for one person. A platform can add modelled conversions.
The audit does not seek to obtain the same number everywhere. It explains why the systems differ and designates the appropriate source for each decision.
1. Pre-audit figures
Eurostat estimates that in 2025, 33.02% of European Union enterprises had at least ten employees and 13.85% via a service provider. A total of 39.85% analysed data through at least one of these channels, so reliable collection is not a topic reserved for large platforms.
The use of business intelligence software amounted to 16.28% of European companies, with about 11% of small to 69% of large enterprises. Visualisation tools are more accessible, but the gap in the ability to feed and govern them remains significant.
In 2025, CNIL issued two fines relating to trackers: 325 million euros against Google and 150 million euros against Shein. These decisions have their own circumstances. They remind above all that the refusal, the actual setting of cookies and the presentation of the choice are technically auditable.
Google Analytics specifies that, when analytics_storage is refused, the client ID is not stored. Ten page views cannot then reveal whether they came from one user or ten. The platform may display modelled behavioural data when the required conditions are met. The audit must identify this layer.
Google also states that from June 15, 2026, the Consent Mode settings on the Google Ads side control exclusively the collection of cookies and ad identifiers from Analytics tags for related properties. a compliant tracking plan at initial acceptance testing may become incorrect after a change of product or configuration.
2. The seven questions to which the audit answers
- What events and identifiers leave each page or application?
- Does the behaviour respect the choice of consent in all states?
- Do events describe important decisions and results?
- Are the values complete, unique, fresh and properly typed?
- Which system is valid for income, customer, lead and refund?
- What part of reporting is observed, attributed, enriched or modelled?
- Which correction plan produces the most confidence per unit effort?
The scope list domains, subdomains, applications, environments, country, CMP, tag managers, SDK, advertising platforms, CRM, warehouse and BI tools. Third-party routes — payment, reservation, authentication — are included.
3. Evidence architecture
The audit builds a chain for each critical event.
| Step | Evidence |
|---|---|
| Action | capture or reproducible protocol |
| Application layer | data layer or SDK event |
| Network | request, payload, consent status |
| Collection | debugger or server log |
| Transformation | rule, filter, version |
| Storage | gross line and time stamping |
| Model | definition of the metric |
| Reporting | number, source and freshness |
| Business system | order, payment or lead reference |
This string avoids declaring "tag triggers" on the sole basis of a tag manager preview. Payload can be refused, converted or duplicated further.
Each piece of evidence receives a test ID, device, consent status and time stamp. It can be replayed after correction.
4. Phase 1 — Inventory the setup without relying on documentation
The auditor collects tracking plans, dictionaries, access records, containers, configurations, policies, contracts, data flows and dashboards. They then compare the declared inventory with the network traffic actually observed.
Tags can be injected by a CMS, a chat app, an A/B testing or a partner, without appearing in the main manager tag. The scan covers several pages and routes. It identifies domains called, cookies, local storage, settings, pixels and scripts.
The environments are separated. A production tag in the staging pollutes the data. A test that does not use the production CMP does not test the final behaviour.
The result is a map: tool, purpose, owner, data, consent, recipient, duration, country, trigger and pages concerned.
5. Phase 2 — Test consent states
A serious audit tests at least six scenarios.
Before any choice. No unauthorised storage or appeal shall precede the decision according to the applicable framework.
Overall acceptance. The authorised categories are triggered, with the correct status transmitted.
Global refusal. The tools respect the refusal; any pings without ID are documented and framed.
Granular choice. Analytics accepted and advertising refused, then the reverse if the interface allows.
Withdrawal. A consent granted is revoked. Subsequent processing changes and retention is managed according to policy.
Back. Status persists according to the expected duration and remains subject to change.
The tests are performed without cookies, with existing cookies, on mobile, desktop and third-party path. Browsers and blockers can modify the result; they are included in a sample, without requiring an impossible uniformity.
The audit also examines the interface: refusing must be as accessible as accepting, information must be clear, boxes must not be preselected, choices must be granular and evidence retained. Final legal qualification belongs to the controller and its advisers; the audit supplies the technical facts.
6. Phase 3 — Verify the event model
The current plan is compared to decisions. Each event must answer a question.
The audit classifies events:
- business result, as
order_confirmed; - growth, as
checkout_started; - diagnostic interaction, as
filter_applied; - context, as version or channel;
- sensitive or unnecessary data to be deleted.
Names describe a stable action rather than a visual element. Properties have type, domain, mandatory character and definition. A currency uses ISO, an amount an explicit unit, an identifier a rule of persistence.
Obsolete events are identified by consumption and volume. Keep them "in case" increases costs, confusion and data surface.
The ideal plan is not maximum. It covers the server result, the steps explaining the breaks and the segments necessary for action.
7. Phase 4 — Test quality on controlled journeys
The auditor executes a set of scenarios with test IDs: first visit, return, account creation, connection, multi-device, quote, purchase, payment error, refund, cancellation and support.
For each event, it verifies:
Presence. The expected event is coming.
Unique. An action does not produce two unwarranted occurrences.
Order. The steps remain temporally consistent.
Value. Amount, currency, product and identifiers correspond.
Persistence. Identity survives or does not survive according to the rule.
Attribution. Source and campaign settings are not overwritten.
Fresh. The data comes before the decision.
Reconciliation. The fact exists in the business system.
A table of results shows expected, observed, deviation, severity, cause and capture. The manual sample is supplemented by requests over several weeks to find distribution anomalies.
8. Phase 5 — Reconcile systems
The reconciliation covers a closed period and a defined cohort. For e-commerce: confirmed orders, amount of VAT/VAT, currency, refunds, cancellations and accounting date.
The formula does not necessarily seek 100% equality. The systems use different windows, spindles, consents and definitions. It explains each category of deviation.
Example of a bridge:
- 10,000 orders in the ERP;
- minus 200 off-site telephone orders;
- minus 1,500 journeys without agreed measures;
- plus 120 analytic duplicates;
- minus 80 events blocked by an error;
- 8,340 orders observed on the analytic side.
The figures are illustrative. The real bridge makes the difference intelligible and actionable.
For leads, the audit brings together submission, lead created, lead qualified, opportunity and sale. It identifies deduplication and delay. A conversion rate marketing without return CRM measures only the form.
9. Phase 6 — Separate measurement layers
The analysis separates four categories.
Observed. Event received with applicable identifiers and permissions.
Job. Confirmed in CRM, ERP or finance.
Alloted. Credit according to a rule or model.
Moled. Estimated volume to compensate for non-observation or forecast a result.
Google explains, for example, that its Consent mode can model conversions and display a uplift calculated as modelled conversions divided by observed conversions, when thresholds are reached. The indicator can only appear after at least seven days and its display window is limited to four weeks after the beginning of the modelling, according to the documentation consulted.
This information belongs to a configuration annex. Above all, a leader must see how much of his number comes from each layer.
10. Phase 7 — Audit identity and deduplication
Checking cookie mapping, device ID, user ID, chopped e-mail, lead, account, command and customer. It specifies what is collected before and after login.
A user ID must not contain a directly identifiable data if the tool is prohibited or not necessary. The matching table remains protected. Merger rules are documented.
Deduplication uses a stable identifier per transaction. When browser and server send the same purchase, the tool must recognise an occurrence. The auditor tests retries, back-navigation and reloads.
The deletions are propagated. Google Analytics states in particular that some requests for deletion may require an extension of seven days to the end date to account for data used in consent models. The audit identifies these behaviours produced instead of assuming a uniform deletion.
11. Phase 8 — Assess governance
Access to the tag manager, analytics and platforms are inventoried. Agency accounts and former employees are removed. Publishing rights are limited. Important changes go through review and version.
The tracking plan has a product owner. The DPO or appropriate legal adviser is consulted on purposes and consent. Developers implement the contract. The analytics team controls quality. Marketing does not change a critical pixel without acceptance testing.
A release contains: request, impact, test, approval, date and rollback. The published container can be restored. Secrets and endpoints server-side are protected.
Monitoring follows volumes, duplicates, nulls, errors, latency and discrepancies with back-office systems, consent status and modelled part. An alert has an owner.
12. Audit score
Logiks uses six separate scores out of 100:
- Decision-making coverage
- technical quality;
- compliance and consent;
- trade reconciliation;
- governance and exploitability;
- transparency of reporting.
An overall score can be displayed, but a cap rule applies. A critical consent violation or unreconciled revenue prevents the mention "controlled", even if many events are correct.
Each note has test coverage and confidence level. An audit without access to the server configuration does not give strong assurance on this scope.
The defects are classified P0 to P3. P0 corresponds to a legal risk or a major decision corruption requiring immediate action. P1 affects a critical result. P2 reduces the diagnosis. P3 is hygiene or optimisation.
13. Case study: 23% of revenue was missing
An e-commerce finds that GA4 earns 23% less income than the ERP. The team believes that consent explains everything.
The audit builds the bridge. 11 points come from refusal or lack of ID, 4 points from a poorly configured payment area, 3 off-site B2B command points, 2 points from an event blocked on Safari and 3 refund points treated differently. At the same time, 1.5 point of duplicates inflates some campaigns.
The correction does not seek to "retrieve" the 23 points in Analytics. The domain and Safari are corrected. The B2B commands are separated. Consent remains respected. The dashboard uses ERP revenue as a total, then shows the observed share and allocation.
An experience of Incrementality is planned to calibrate platforms. The number becomes smaller in a report, but the decision becomes better.
14. Deliverables expected
- Inventory of tools, tags, cookies, SDK and feed;
- goal matrix–consent–recipients;
- current and target tracking plan;
- network proof test file;
- Analytical/CRM/finance reconciliation bridge;
- identity card and deduplication;
- dimensional score with confidence;
- backlog P0–P3, effort and owner;
- monitoring plan and continuous acceptance testing;
- distinguishing instrument panel observed, assigned and modelled.
The report provides corrected payload examples and acceptance criteria. It is not limited to "reviewing the data layer".
15. Four-wave correction plan
48 hours. Suspend unauthorised tags or corrupt events, secure access and preserve evidence.
30 days. Correct critical results, consents, identifiers, duplicates and reconciliations.
60 days. Remake tracking plan, dictionary, useful server-side and semantic model. Train owners.
90 days. Install monitoring, automated acceptance testing, tool review and experimentation. Remove events without use.
Each wave ends with a test identical to that of the audit. Closing a ticket is not proof of correction.
16. Frequently Asked Questions
16.1. What gap between analytics and the ERP is acceptable?
There is no universal percentage. The difference must be explained by stable categories and the source adapted to the decision. A variable and bridgeless difference is problematic.
16.2. Can an audit ensure compliance?
It verifies the technical facts and consistency with the rules defined. The legal qualification depends on the processing activity, its context and advice from the appropriate specialist. The report distinguishes observation and advice.
16.3. Does server-side tracking resolve consent?
No. It changes the collection point and can improve control and reliability. It does not create a legal basis and should not circumvent the user's choice.
16.4. How many routes should be tested?
All critical results and a sample of variants: devices, consents, country, connected/unconnected, errors and refunds. The volume depends on the site, not a fixed number.
16.5. How often will the audit be repeated?
After a recast, change of CMP, migration analytics, new domain, application or major platform, then an annual review. Automatic controls work continuously.
17. What each sample must make reproducible
The retest transforms the report into insurance. The auditor chooses several critical events—purchase, refund, lead qualified, consent withdrawn—and asks another person to rebuild their trajectory without oral explanation.
For everyone, the folder keeps identifying, time stamping, source, useful payload, rules, consent, transformations, destination and value in the table. Discrepancies are classified: loss, duplicate, delay, wrong definition, join, attribution or access problem.
The sample combines random cases and risk cases. A calm period does not represent the balances, a single currency does not test the exchange and a successful purchase does not cover the failure to pay. The acceptance criteria are written before the correction.
When a new implementation announces 99.5% of events received, the audit also checks whether the 0.5% missing are focused on Safari, a country, a refusal of consent or the highest orders, whether the events arrive in order, whether a retry creates duplicates, whether the CRM reconciles the amounts and whether the rate lasts several days; an overall average can otherwise mask exactly the population that distorts the decision.
The fence requires a controlled production test, reconciliation with the reference system and a demonstrated alert. A capture of the management tag tool does not prove reception or use.
Recurring control follows coverage, latency, anomalies, unknown events, consent and financial divergence. Its frequency depends on the cost of latency. A critical daily metric cannot wait for a quarterly review.
18. Conclude with an observable decision
The last workshop does not go through a list of tags. It takes up three decisions—moving a budget, reminding a prospect, stopping a feature—and asks if the corrected data now allow them to be taken with the expected time and level of confidence.
For each decision, the owner shows the definition, denominator, exclusions, freshness, reference source and alert that would signal a break; when these elements exist in the tools rather than in the consultant's memory, the audit may conclude that the capacity has been transferred and that the next anomaly will be detected before becoming a committee dispute.
Test data is deleted or stored according to the intended framework. Temporary access expires. The report only archives the necessary extracts with proportionate protection.
19. What Logiks recommends
Start with a command or lead and follow it in each system. Test the consent choices in the network, reconcile with the business source and label any modelled data. First, correct events that change a decision or expose a risk. The amount of data is of value only if their status is understandable.
20. Main sources
- Eurostat, analysis of data in enterprises in 2025: https://ec.europa.eu/eurostat/statistics-explained/SEPDF/cache/33473.pdf
- Eurostat, BI in enterprises in 2025: https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20260520-1
- CNIL, audience measurement solutions and exemption conditions: https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies-solutions-pour-les-outils-de-mesure-daudience
- CNIL, penalties for trackers against Google and Shein: https://cnil.fr/fr/regulation-des-cookies-la-cnil-poursuit-le-plan-daction-initie-en-2019-et-prononce-deux-amendes
- Google Analytics, data collection and identifiers: https://support.google.com/analytics/answer/11593727?hl=en
- Google Analytics, control update from June 15, 2026: https://support.google.com/analytics/answer/17016975?hl=en
- Google Analytics, Impact Results of Consent Mode: https://support.google.com/analytics/answer/11954524?hl=en
- Google Analytics, deletion requests: https://support.google.com/analytics/answer/9940393?hl=en
