SL

The Google Ads Audit Checklist: 100+ Points, in the Order a Real Audit Runs

Sapun Lamichhane37 min read
A person filling in a printed checklist on a clipboard, an open notebook, pens and a keyboard on the desk
Every audit checklist online is a list. The thing that makes an audit useful is the order — each stage has to be trustworthy before the next one means anything.

Key takeaways

  • Audit in a fixed order, because each stage decides whether the next one is meaningful. Reviewing bidding before verifying conversion data means grading a strategy against numbers that may be wrong.
  • Measurement integrity is the gate. If conversion actions do not correspond to events the business genuinely values, nothing downstream in the audit — bidding, budget, structure, reporting — can be trusted or acted on.
  • A checkpoint asks whether a setting is deliberate and consistent with intent, not whether a metric hit a number. Benchmarks vary so much by market, offer and season that a threshold-based audit produces confident nonsense.
  • An audit that produces forty findings with no priority gets ignored. Every finding needs a severity, the evidence behind it, the estimated direction of impact, and the exact change being requested.
  • The most dangerous account is the one that looks healthy on platform metrics while the business sees nothing — and the only way to catch it is reconciling against the system where revenue is actually recorded.

Why the order matters more than the list

Search for a Google Ads audit checklist and you will find dozens of flat lists. Check your Quality Score. Check your negative keywords. Check your ad extensions. Every item on those lists is a real thing worth checking, and the lists are still close to useless, because they leave out the one property that determines whether an audit produces a decision or a document: the order.

Here is the problem in one sentence. If you audit bidding strategy before you have verified that the conversion data is real, you are grading a strategy against numbers that may be wrong — and worse, you will write down a confident finding about it. The same applies further along. Judging keyword performance before checking whether two campaigns are competing for the same query tells you nothing about the keyword. Judging landing pages before checking whether the form actually submits on mobile tells you nothing about the page.

So this checklist is structured as a sequence of eleven stages, each with a gate: something that has to be true before the next stage's findings can be trusted. There are 126 checkpoints across those stages. Work them in order. When a gate fails, the honest move is to stop, fix it, and re-run everything downstream — not to note it and keep going.

The gate principle

Each stage of an audit produces findings whose validity depends on the stage above it being sound. A finding about bidding is only as trustworthy as the conversion data it was measured against; a finding about conversion data is only as trustworthy as the access and scope you started with. When a gate fails, everything below it is provisional until the gate is fixed. Say so in the report.

One more constraint on what follows, and it is deliberate. There are no benchmark numbers here — no "a healthy click-through rate is X", no target cost per lead, no expected conversion rate. Those figures vary so much by market, offer, season and brand strength that quoting one as an audit standard produces confident nonsense. Every checkpoint below asks the same underlying question instead: is this configured deliberately, and is it consistent with what the account is supposed to be doing?

The eleven stages and the gate each one has to pass
StageWhat it establishesThe gate
0 — Access and scopeWhat you can see and what success meansYou have written the objective down in the business owner's words
1 — Measurement integrityWhether reported conversions are realConversion actions reconcile against the system of record
2 — ArchitectureWhether campaigns are separable and comparableNo two campaigns are competing for the same intent
3 — Keywords and search termsWhat the account is actually buyingThe search terms report has been read, not skimmed
4 — Negatives and wasteWhat the account should stop buyingExclusions are applied at the level they were intended
5 — Ads and assetsWhat the market is being shownEvery active ad has been read and its claims verified
6 — Landing pagesWhether a click can become a leadYou have submitted every form yourself, on a phone
7 — Bidding and budgetHow money is allocatedStages 1 and 2 passed, so the inputs are trustworthy
8 — TargetingWho is being reached and whenTargeting matches the service area and response capacity
9 — Attribution and reportingWhat decision-makers are being toldThe report reconciles to the business, not just the platform
10 — GovernanceWhy the account is in this stateChange history explains the last quarter

Stage 0 — Access and scope

Almost every bad audit is bad because it started here badly. An auditor who begins with partial access writes findings full of hedges, and an auditor who never established what the account is supposed to achieve writes findings against an objective they invented. The first thing I do in any account is not open it — it is ask the owner what a good month looks like and write the sentence down.

  1. Confirm you have standard or admin access to the Google Ads account itself, not a shared report link or a screen-share session. A read-only export cannot show you settings, and settings are most of the audit.
  2. Check whether the account sits under a manager account, and get visibility into that manager account if one exists — shared budgets, shared negative lists, account-level exclusions and cross-account conversion imports all live above the account.
  3. Get at least viewer access to the GA4 property the account is connected to, and confirm it is the property the business actually uses rather than a legacy one.
  4. Get read access to the Google Tag Manager container, or confirm the tags are hardcoded and get access to whoever can see the source.
  5. Get access to the CRM, booking system, or spreadsheet where the business records real outcomes. Without this you can audit the account but not the advertising.
  6. Get the URLs of every landing page in use, including any that live outside the main site or on a page builder subdomain.
  7. Fix the audit window and write it down. Use a period long enough to contain a full sales cycle, and note where it sits relative to any seasonality the business has described.
  8. Ask the business owner, in their own words and without prompting them with marketing vocabulary, what a successful month from this spend looks like and how they would know it happened. Write the answer verbatim.
  9. Ask who has had edit access over the audit window — internal staff, an agency, a freelancer, a platform partner — because the change history will make far more sense with names attached.
  10. Ask what has already changed recently that the account does not know about: a price change, a new competitor, a service area change, a staffing change in whoever answers the phone. These explain findings that otherwise look like account problems.

That last checkpoint earns its place more often than any other in this stage. An account whose performance visibly changed in March is frequently an account where the business changed its pricing in March, and no amount of examining bid strategies will surface that.

Stage 1 — Measurement integrity

This is the gate. Nothing below this stage is trustworthy until it passes, because every downstream judgment — which campaign works, which keyword to cut, whether the bidding strategy is performing — is a judgment about conversion data. If the conversion data is wrong, the audit is confidently wrong.

This site already has a dedicated four-step sequence for this: how to audit Google Ads conversion tracking before scaling spend walks through GA4 event reconciliation, container hygiene, mapping conversion actions to revenue events, and reconciling a full cycle against the CRM. That is the deep dive for this stage and I am not going to repeat it here. What follows is the account-side configuration layer that sits alongside it — the settings inside Google Ads that determine what the numbers in the interface actually mean.

  1. Inventory every conversion action in the account, including paused and removed ones, and write down what real-world event each is supposed to represent.
  2. Check which actions are set as primary and therefore counted in the Conversions column and used by Smart Bidding, versus secondary and merely observed. A secondary action that the business considers its main outcome is a serious finding.
  3. Check the counting setting on each action — every conversion versus one conversion per interaction — and confirm it matches the business model. A lead generation form counted as "every" will inflate on repeat submitters.
  4. Check the conversion window on each action and confirm it is long enough to contain the real decision cycle without being so long that it swallows unrelated later activity.
  5. Check the attribution setting on each conversion action, and whether the actions in a single bidding strategy are set consistently.
  6. Look for double counting: the same real event tracked both by a Google Ads conversion tag and imported from GA4, both marked primary.
  7. Check the value assigned to each action. Confirm whether it is a real value, a placeholder someone typed once, or absent — and whether the bidding strategy depends on it.
  8. Check how phone calls are counted: calls from ads, calls from a website number, and whether a minimum call duration is set to something the business agrees represents a real enquiry.
  9. Check whether enhanced conversions are enabled and, if so, whether the data source feeding them is still live.
  10. Check whether auto-tagging is on and whether the GCLID actually arrives in the CRM record. This is what makes closed-loop reconciliation possible later, and it silently breaks on form rebuilds.
  11. Look for primary conversion actions that have recorded nothing across the entire audit window. Either the event stopped firing or the action should not be primary; both are findings.
  12. Reconcile a sample of platform-reported conversions against the system of record for the same window, name by name where possible. This single check finds more real problems than the rest of the stage combined.

Where to stop

If the reconciliation in the final checkpoint fails badly, stop the audit and say so. Continuing produces a long document full of findings derived from numbers you have just demonstrated are unreliable, and the client will act on them. A three-page report that says "the measurement layer has to be rebuilt before any performance conclusion is possible" is a better deliverable than forty items of well-formatted guesswork.

Stage 2 — Account and campaign architecture

Structure decides whether the account can be read. Two campaigns competing for the same query make each other look worse and neither look attributable. Brand traffic mixed into a non-brand campaign makes the whole campaign look efficient regardless of what the non-brand side is doing. Before judging any campaign, establish that the campaigns are actually separable.

A hand drawing a red flowchart on a whiteboard, one dashboard box branching into plans, budget and media
Structure is not an aesthetic preference. It determines whether any performance number in the account can be attributed to a decision someone made.
  1. List every campaign with its type, status and the conversion goal it is set to optimize toward. Confirm each campaign has one clear job.
  2. Check whether each campaign type was chosen or inherited. Display, Video and Demand Gen campaigns created by a setup wizard and never revisited are common, and they spend.
  3. Check whether brand and non-brand traffic are separated. If they are not, every efficiency number in the account is partly a brand number.
  4. Look for two or more campaigns eligible for the same query — most often a Search campaign and a Performance Max campaign, or two Search campaigns with overlapping keyword sets.
  5. If Performance Max is running alongside Search, check whether brand terms are excluded from it and whether that decision was made deliberately or by default.
  6. Check the Search Partners and Display Network settings on every Search campaign, and whether their inclusion was a decision or a leftover default.
  7. Check ad group counts per campaign and whether each ad group has a coherent single theme rather than being a bucket.
  8. Check keyword counts per ad group against the ad copy in that ad group. An ad group with many loosely related keywords cannot have ad copy that matches all of them.
  9. Check naming conventions for consistency. Inconsistent naming is not a cosmetic finding — it is the reason nobody can report on the account by segment.
  10. Look for paused campaigns and ad groups that still carry live assets, active audiences or shared budget allocations.
  11. Check shared budgets: which campaigns sit inside them, and whether the sharing was intentional or a way of avoiding a budgeting decision.
  12. Check for campaign-level conversion goal overrides that differ from the account default, and whether anyone knows they exist.

Stage 3 — Keywords, match types and search terms

The keyword list is what the advertiser asked for. The search terms report is what the account actually bought. Auditing the first without the second is the most common way to produce a checklist that looks thorough and finds nothing, because a keyword can look perfectly reasonable while the queries it triggers are nothing like its intent.

A hand holding a pen over printed spreadsheet pages of cost columns, banknotes on the desk beside them
Export the search terms report and read it line by line. It is the only place the account tells you the truth about what your match types are doing.
  1. Export the full search terms report for the audit window and sort it by spend. Read the top of that list line by line rather than skimming a summary.
  2. Identify how much spend went to terms that do not map to any keyword the advertiser deliberately added, and where that spend came from.
  3. Check the distribution of match types across the account, and ask whether it reflects a decision or an accumulation.
  4. Look for duplicate keywords across ad groups and campaigns, which split data and make each copy look worse than the term actually is.
  5. For each high-spend keyword, read the search terms it triggered and check whether the intent drifted. This is the core check of the stage.
  6. Check keyword status flags — low search volume, rarely served, below first page — and whether anyone has acted on them.
  7. Check that each keyword points to a landing page matching its specific intent, not to a generic homepage that happens to be the campaign default.
  8. Look for informational and transactional intent mixed in the same ad group, which forces one ad to speak to two different states of mind.
  9. Check whether competitor terms are being bid on, and confirm with the business whether that is a deliberate policy they are comfortable with.
  10. Check how close variants are behaving, particularly on exact match, where the matched term can differ meaningfully from the keyword.
  11. Look for keywords added at launch and never reviewed against a search terms report since. The date they were added is in change history.
  12. If broad match is in use, check that the discipline it requires is actually in place — verified conversion tracking and an actively maintained negative list. Broad match does not fail on its own; it fails without those two things.

On that last point, there is a widespread belief that broad match inherently damages relevance and Quality Score. It does not — irrelevant traffic does, and match type is only one of the ways irrelevant traffic arrives. The reasoning is worked through in the four Quality Score myths that cost advertisers money, and it matters here because an auditor who treats broad match as a finding in itself will recommend a change that costs volume without fixing the underlying problem. If you are reading the diagnostic columns during this stage rather than at the end of the audit, the guide to what Quality Score measures and what moves it explains which of the three components a keyword-level finding actually points at.

Stage 4 — Negative keywords and waste

Stage 3 established what the account is buying. This stage establishes what it should stop buying, and where the exclusions that were supposed to prevent it are failing. Most negative keyword problems are not missing negatives — they are negatives applied at the wrong level, in the wrong match type, or blocking something the account actually wants.

  1. Inventory every negative keyword list in the account and every campaign each list is applied to. Lists that exist but are applied to nothing are common.
  2. Check for negatives applied at ad group level that should be at campaign level, and campaign-level negatives that should be account-level.
  3. Check the match type of each negative. A broad-match negative blocks far more than most people expect, and this is a frequent cause of unexplained volume loss.
  4. Look for conflicts: negatives that block terms the account is also actively bidding on. Google surfaces some of these, but not all combinations.
  5. Read the search terms report again specifically for recurring irrelevant themes — job seekers, free and DIY intent, students, competitor support queries, wrong product category — and check whether each theme is already excluded.
  6. Check placement exclusions on any Display, Video, Demand Gen or Performance Max activity, and whether the placement report has ever been reviewed.
  7. Check whether mobile app inventory and specific app categories are excluded where that inventory is not wanted.
  8. Check content suitability and inventory type settings on video and display placements against what the business would be comfortable appearing beside.
  9. Check whether negatives are being added on a cadence or were added once at launch. Change history will show which.
  10. Check account-level negative keywords, which are easy to forget and apply everywhere.
  11. Check audience exclusions — existing customers, recent converters, current employees — and whether excluding them is right for this business. For some accounts it is exactly wrong.

Stage 5 — Ads, assets and extensions

This stage is mostly reading. Open every active ad and read it as a stranger would, then check that what it promises is a thing the business will actually deliver. The number of accounts running ads that promise a discount which ended, a service the business dropped, or a delivery window it no longer meets is not small, and no metric in the interface flags it.

  1. Count active ads per ad group and check their approval status, including any approved with limitations, which serve in fewer situations without ever failing loudly.
  2. Check responsive search ad asset counts — headlines and descriptions — against what the ad group can genuinely support without repeating itself.
  3. Check every pinned asset and whether the pinning was a deliberate constraint, usually for a legal or brand reason, or an old habit that is limiting combinations.
  4. Read each ad against the keywords in its ad group and check that the ad could plausibly answer any of them.
  5. Check every claim in every ad against the current offer: prices, guarantees, delivery times, free trials, opening hours, service areas.
  6. Look for seasonal or promotional copy that has outlived the promotion. Change history will show when it went live.
  7. Check sitelinks: whether they exist at the right level, whether they are distinct from each other, and whether each one lands somewhere useful rather than back on the same page.
  8. Check callout assets and structured snippets for duplication with the ad copy itself, which wastes the space.
  9. Check call assets, including the number, the tracking, and the schedule they are set to display on.
  10. Check lead form assets if used, including where the submissions go and whether anyone is receiving them.
  11. Check image, logo and business name assets for correctness and for cropping that breaks on the placements they actually serve in.
  12. Check whether automatically created assets and dynamically generated headlines are enabled, and whether the business is comfortable with copy it did not write appearing in its ads.
  13. Check asset-level reporting availability, and whether anyone has ever used it to remove an asset. An asset set that has never been edited since launch is a finding about process, not creative.

Stage 6 — Landing pages and post-click

The unglamorous prerequisite nobody wants in an audit report: you have to use the pages yourself, on a phone, on mobile data, and submit every form with real details. Not open them. Not check them in a desktop browser with an ad blocker and a logged-in session. Submit them and confirm the submission arrives where the business thinks it arrives.

  1. Click every active final URL in the account and confirm none of them 404, redirect through a chain, or land on a maintenance page.
  2. Check every tracking template and final URL suffix, and confirm parameters survive any redirect between the click and the page.
  3. Load each page on a phone, on a normal mobile connection, and check that the first screen contains what the ad promised rather than a hero image and a menu.
  4. Submit every form yourself, end to end, on mobile, and confirm the submission arrives in the inbox or CRM the business actually monitors.
  5. Confirm a successful submission produces a distinct confirmation state or thank-you URL that tracking can fire on, and that a failed submission does not.
  6. Check what happens on a validation error — whether the conversion tag fires anyway, which is one of the most common sources of phantom conversions.
  7. Check the consent banner and how it interacts with tag firing. A banner added after the tags were built frequently blocks the very events the account optimizes toward.
  8. Check the phone number displayed on each landing page and whether it is the tracked number the account is counting calls from.
  9. Check page load behavior, since landing page experience is one of the three components Google evaluates and a slow page degrades it directly.
  10. Check that the form fields being collected are the ones the sales process actually needs, and that fields nobody uses are not suppressing completion.
  11. Check whether the page a keyword points to matches that keyword's specificity, or whether specific searches are being sent to a general page.
  12. Check what happens to a submitted lead next — where it routes, who owns it, and whether there is a fallback if that person is unavailable. An audit that stops at the form submission stops one step before the failure most accounts actually have.

That final checkpoint routinely sits outside the scope people expect from an ads audit, and it is frequently where the money is going. A perfectly configured account feeding leads into a routing process that drops them is an advertising problem in every sense except the technical one; the mechanics of building routing that does not drop leads are covered in the post on lead routing that does not lose leads, and it is worth flagging in an audit even though fixing it is not an ads task.

Stage 7 — Bidding, budget and pacing

Now, and only now, is bidding worth auditing — because a bidding strategy is a function that takes conversion data as input, and Stage 1 established whether that input is real. Auditing bidding first is the single most common ordering mistake, and it produces findings that sound authoritative and are built on sand.

  1. List the bidding strategy on every campaign and confirm each one was chosen for a stated reason rather than accepted from a setup flow.
  2. For each target-based strategy, check when the target was last changed and what it was changed from. Change history has this.
  3. Check which conversion goals each strategy is actually optimizing toward, and confirm they are the primary actions validated in Stage 1 rather than a legacy set.
  4. Check for portfolio bid strategies and what is inside them. Campaigns with different jobs sharing one portfolio strategy will pull against each other.
  5. Check daily budget against actual daily spend patterns across the window, looking for campaigns that consistently exhaust their budget early in the day.
  6. Check which campaigns show as limited by budget and whether that state is a deliberate ceiling or an unnoticed constraint.
  7. Check for recent bidding strategy changes and whether the account has been left alone long enough afterward for the change to mean anything.
  8. Look for bid adjustments left over from a manual era — device, location or schedule modifiers that a Smart Bidding strategy now largely ignores or that conflict with it.
  9. Check whether seasonality adjustments or data exclusions have been used, and whether they were applied for genuine events like a site outage or a closure.
  10. Check the distribution of a shared budget across its campaigns and whether one campaign is consuming it.
  11. Check whether any campaign is still funded against a goal the business has since deprioritized. This is a conversation with the owner, not a number in the interface.
  12. Check the change cadence itself — how often bids and budgets are being touched, and whether there is a written rule governing when a change is allowed.

That last checkpoint is a governance finding disguised as a bidding one. Accounts edited daily in response to yesterday's numbers never accumulate enough stable data for anyone to learn from, and the fix is a written decision rule rather than more diligence. The model I use is set out in the bid governance framework for agencies managing real client budgets, and in an audit the useful question is simply whether such a rule exists in writing anywhere.

Stage 8 — Targeting: geo, schedule, device, audience

Targeting findings are usually the cheapest wins in an audit and the easiest to miss, because the settings are buried and the defaults are reasonable-sounding rather than obviously wrong. The location targeting presence setting alone accounts for a large share of spend that businesses cannot explain.

  1. Check the location targeting option on every campaign — whether it targets people in the location, people interested in the location, or both — and confirm which one the business intended.
  2. Check the excluded locations list and the same presence setting on exclusions, which is set separately and frequently missed.
  3. Pull the geographic report and look for meaningful spend outside the area the business can actually serve.
  4. Check radius targets against the real service area, including whether the radius is drawn around the right point.
  5. Check the ad schedule and compare it against when the business can genuinely respond. Ads running at 3am for a service that requires a phone call is a decision, not a default.
  6. Check device settings and any device bid adjustments, especially where mobile experience and desktop experience differ materially.
  7. Check which audience segments are attached to each campaign and whether they are in observation or targeting mode — the difference between narrowing reach and merely reporting on it.
  8. Check that remarketing lists are still populating rather than sitting stale from a tag that stopped firing.
  9. Check customer match lists and when they were last uploaded, since a list from a year ago is a list of last year's customers.
  10. Check demographic inclusions and exclusions, and whether any exclusion was made on an assumption nobody has tested.
  11. Check language targeting against the language the landing pages are actually written in.
  12. Check optimized targeting or audience expansion toggles, and whether their being on was a decision.

Stage 9 — Attribution and reporting

By this point you know what the account is doing. This stage asks a different question: what are the people who fund it being told, and does that match reality? An account can be in fine shape while the reporting layer quietly misleads everyone, and an account can be in poor shape while the report looks excellent.

A laptop screen filled with a dark analytics dashboard: load time against bounce rate, and session totals
A dashboard reconciles to the platform by construction. The only question worth asking is whether it reconciles to the business.
  1. Check the attribution model in use and whether anyone has changed it during the audit window, which would make period comparisons invalid.
  2. Check the reporting window against the real conversion lag. A report pulled the day a month ends will undercount conversions that had not yet landed.
  3. Check whether the client-facing report reconciles to the CRM or only to the platform. A report that only reconciles to the platform is a report about the platform.
  4. Check for double counting between GA4-imported conversions and Google Ads tag conversions inside the report itself.
  5. Check whether the report separates brand from non-brand, since combining them makes the non-brand side unreadable.
  6. Check whether the report contains at least one business metric — qualified leads, booked jobs, revenue — rather than only clicks, impressions and platform conversions.
  7. Check the comparison periods used and whether they are like-for-like against seasonality.
  8. Check for cross-account conversion imports at manager level that may be adding or duplicating actions.
  9. Check GCLID and UTM hygiene end to end — whether the identifiers that arrive on the site actually make it into the CRM record and survive the lead's lifecycle.
  10. Ask who reads the report and what decision they make from it. If nobody can name a decision, the reporting finding is that the report should be shorter and different, not more accurate.

Stage 10 — Governance and change history

The last stage explains the first nine. Change history tells you whether a performance shift was the market or an edit somebody made on a Tuesday. Access review tells you how many people can change things without a record. This stage produces the findings that prevent the account from returning to its current state six months after your audit.

  1. Read the change history across the full audit window, filtered by change type, and look specifically at what happened immediately before any visible shift in the account.
  2. Check who currently has access, at what level, and whether any of them no longer work with the business.
  3. Check for automated rules, and read what each one does. Rules created for a temporary situation and never removed are a recurring source of unexplained pauses and budget changes.
  4. Check for scripts running on the account, who wrote them, and whether anyone still maintains them.
  5. Check the auto-apply recommendations settings. Recommendations applied automatically are changes nobody decided on, and they show up in change history attributed to the system.
  6. Check the optimization score prompts that have been applied historically, and whether applying them was a considered choice.
  7. Check whether experiments or drafts have been used, and whether any experiment is still running with nobody watching it.
  8. Check who owns the account and the payment profile. Where an agency owns the account rather than the business, the business cannot take its history with it — flag this as a commercial finding regardless of the relationship's current health. Do not attempt to advise on billing, tax or currency specifics; direct the business to Google Ads billing documentation and their own bank.
  9. Check whether a change log exists outside the platform, with the reason for each change rather than just the fact of it.
  10. Check whether the account has a named owner and a stated review cadence. Most of what an audit finds is the result of not having either.

The metric that lies

There is one specific account state that this ordering exists to catch, and it is the reason I distrust audits that begin with performance metrics. The account reports a rising conversion count. Cost per conversion is falling. The dashboard is green in every panel. The business owner, meanwhile, says the phone is quieter than it was last year.

Both are true. The conversion count is real in the sense that the events fired. What broke is the correspondence between those events and anything the business cares about. There are several ordinary ways this happens: a tag that fires on page load rather than on submission, so every visit counts; a conversion action counting "every" conversion on a form people resubmit when nothing seems to happen; a newsletter signup marked primary alongside a quote request, so Smart Bidding steadily reallocates toward the cheaper event; a consent banner change that altered which sessions get tracked, moving the number without moving reality.

The tell is always the same, and it is never inside the platform. The second number that catches it is the count of real outcomes in the system of record — booked jobs, signed contracts, qualified enquiries someone actually spoke to — over the same window, compared against the platform's count of conversions. When those two lines diverge and keep diverging, the platform metric is the one that is lying, and every optimization made against it since the divergence began has been pushing the account further from the business.

The check that catches it

Pull platform-reported conversions and real recorded outcomes for the same window and put them side by side, then do it again for the equivalent window a year earlier. You are not looking for the two numbers to match — they never will, because of attribution, lag and unrecorded contacts. You are looking at whether the gap between them is stable. A widening gap is a measurement failure regardless of how good the platform number looks.

The 60-minute version

Sometimes there is not time for a full audit — a sales conversation, a second opinion on someone else's account, a quick sanity check before a budget decision. This is the shortlist, in the same order, chosen because each item catches a disproportionate share of serious problems. It does not replace the full sequence and should never be presented as though it did.

  1. Ask the owner what a good month looks like, and write down the sentence. Five minutes, and it frames everything else.
  2. Open the conversion actions table. Check which are primary, what their counting and window settings are, and whether any primary action has recorded nothing across the window.
  3. Ask for the count of real outcomes in the CRM for the same period and compare it against the platform conversion count. If these diverge badly, stop here — this is the finding.
  4. Open the campaign list and look for two campaigns eligible for the same queries, and for brand traffic sitting inside a non-brand campaign.
  5. Export the search terms report, sort by spend, and read the top of the list. Ten minutes here finds waste that no dashboard shows.
  6. Check the location targeting presence setting on the highest-spending campaign.
  7. Open the highest-spending ad and read it, then click through to its landing page on a phone and submit the form.
  8. Check whether the campaigns are budget-limited and whether the bidding strategy targets have been changed recently.
  9. Open change history for the last ninety days and scan it, particularly for automated rules and auto-applied recommendations.
  10. Ask who currently owns the account and who reads the report. The answers are frequently the most useful findings of the hour.

Writing the findings up so they get acted on

An audit that produces a forty-item list with no priority gets read once and filed. I have written that document and watched it change nothing. The failure is not thoroughness — it is that an undifferentiated list transfers the entire prioritization burden to the person least equipped to carry it, who then does the easiest three items and stops.

Every finding needs four things, and a finding missing any of them should not go in the report. Severity, so the reader knows where to start. Evidence, so the finding survives being challenged by whoever built the thing. Estimated impact, stated directionally and honestly rather than as an invented number. And the specific change being requested, written precisely enough that someone could execute it without asking a follow-up question.

  1. Severity — critical, high, medium or noted, using a stated definition rather than a feel. The definitions matter more than the labels; publish them in the report so the reader can disagree with a classification rather than with the whole document.
  2. Evidence — where you saw it, with the date range and the exact location in the account. "Search terms report, last ninety days, sorted by spend" beats "significant wasted spend on irrelevant terms" in every conversation that follows.
  3. Estimated impact — the direction and the mechanism, not a fabricated figure. "This conversion action is counted as primary and is included in the Smart Bidding target, so bidding is currently allocating toward it" is defensible. "This is costing you thirty percent of your budget" is not, unless you can show the arithmetic from the account itself.
  4. The specific change requested — the setting, the new value, and who has to make it. Not "improve ad relevance" but "split ad group X into two, one for each intent, and rewrite the ad in each to match".
  5. The dependency — whether this finding can be acted on independently or has to wait for something above it. Anything downstream of an unresolved measurement finding should say so explicitly, because acting on it early wastes the effort.
  6. The owner — a named person or role for each finding. A report where every action is assigned to "the team" is a report where nothing is assigned.
Severity classification — what makes a finding critical rather than worth noting
SeverityWhat qualifiesWhat the reader should do
CriticalThe account is spending against measurement that does not correspond to reality, or money is going somewhere the business cannot serve or does not want to appear.Stop or pause the affected spend, fix before anything else, and treat every downstream finding as provisional.
HighA configuration error is actively distorting decisions or allocation — competing campaigns, a primary conversion action nobody agreed to, a broken form on a funded landing page.Fix within the current cycle. These are the findings that change results without changing budget.
MediumA structural or hygiene issue that limits how well the account can be managed or read, but is not currently misdirecting money.Schedule it. Bundle these into one planned piece of work rather than doing them piecemeal.
NotedA deviation from good practice with no demonstrated consequence in this account, or a decision that looks unusual but may be deliberate.Raise it, ask whether it was intentional, and accept the answer. Padding a report with these is how audits lose credibility.

One discipline that matters more than the classification itself: separate findings from preferences. An auditor reviewing an account built by someone else will encounter many decisions they would have made differently, and almost none of those are findings. If you cannot state the mechanism by which a setting causes a worse outcome for this business, it belongs in the noted tier at most, phrased as a question rather than a correction.

What an audit cannot tell you

This is the section most audit content leaves out, and leaving it out is how audits get oversold. An audit examines the machinery between a search and a form submission. That is a genuinely important stretch of the process and it is not the whole business, and a report that implies otherwise sets up a client to be disappointed by a technically successful engagement.

  • Whether the offer is competitive. If the market can buy the same thing cheaper, faster or from a more trusted name, the account can be flawless and still lose. No setting in Google Ads fixes an offer problem, and an auditor who does not say this out loud is letting the client believe otherwise.
  • Whether the price is right. Pricing shows up in an account as poor conversion behavior, which looks identical to a landing page problem from inside the interface. Distinguishing them requires talking to people who did not buy.
  • Whether the sales team follows up. Leads that arrive and are never called back produce exactly the same account-side data as leads that arrive and convert badly. This is the most common cause of an audit finding nothing wrong while the client remains unhappy.
  • Whether the market exists at the volume the business is assuming. Search demand is finite, and an account already capturing most of the available intent for its category cannot grow by being managed better.
  • Whether the brand carries any weight. Search behavior differs enormously between a known name and an unknown one, and the difference shows up in the account as a performance gap that looks like an execution problem.
  • Whether the internal capacity exists to handle more. Increasing volume into a business that cannot answer the phone is not a win, and this is a question an auditor has to ask directly because the account cannot answer it.

A useful audit report says which of these it examined and which it did not. Where the honest answer is "the account is well configured and the problem is upstream of it", that is a finding — arguably the most valuable one available — and it should be written in the first paragraph rather than buried after thirty configuration items.

Running it as a repeatable process

The full sequence is not something to run monthly. A full audit is warranted when something structural changes: a new manager takes over the account, spend increases materially, the offer or service area changes, or the account has simply drifted for a quarter without anyone looking properly. Running it more often than that produces diminishing findings and audit fatigue, where the report stops being read.

What is worth running continuously is a small subset. The measurement reconciliation from Stage 1 and the search terms read from Stage 3 catch most of what a full audit would find, far earlier and at a fraction of the effort. Set both on a cadence, write down the date each was last done, and the full audits get shorter every time.

The other half of the value is what the audit changes about how the account is run afterward. Most of the findings in a typical report are the accumulated result of no written decision rule and no named owner. Fixing the settings without fixing that returns the account to the same state within a year, which is why Stage 10 is in the sequence rather than being an appendix.

Where to start

If you are auditing your own account, do the sixty-minute version this week and be honest about the conversion reconciliation, because that is the checkpoint people skip when they suspect what it will show. If you are auditing someone else's, do not open the interface until you have the sentence describing what a good month looks like. Everything the audit finds is ultimately a gap between that sentence and what the account is configured to do.

The measurement stage is the one to get right first, and there is a dedicated sequence for it — the four-step conversion tracking audit covers the GA4, tag manager and CRM reconciliation work in detail. Once that gate passes, the rest of this checklist starts producing findings you can act on. I run this sequence on client accounts through Arcetis, and the pattern that holds across almost every account is the one this post opened with: the order is the method, and the list is just what the order contains.

Frequently asked questions

How do you audit a Google Ads account?

Audit in stages, in order. Start with access and a written statement of what the account is supposed to achieve. Verify measurement next, because every later judgment depends on the conversion data being real. Then work outward: account structure, keywords and search terms, negatives, ads and assets, landing pages, bidding and budget, targeting, attribution and reporting, and finally governance and change history. Auditing out of order produces findings that contradict each other.

What should a Google Ads audit checklist include?

It should cover conversion action configuration, campaign and ad group architecture, keyword match types and the search terms they actually trigger, negative keyword and placement exclusions, ad and asset configuration, landing page and form functionality, bidding strategy and budget pacing, geographic, schedule, device and audience targeting, attribution settings, reporting reconciliation, and account governance including change history and access. Each item should test whether a setting is deliberate, not whether a metric hit a target.

How long does a Google Ads audit take?

It depends almost entirely on account size and how much of the measurement stage checks out. A small single-campaign account with clean tracking can be worked through in a few hours. A large multi-campaign account where conversion actions do not reconcile against the CRM will take considerably longer, because the reconciliation itself becomes the work and everything downstream has to wait for it. Budget for the tracking stage to expand.

Can you audit a Google Ads account without access to the CRM?

You can complete most of the technical audit, but not the part that matters most. Without the system where the business records revenue, you cannot tell whether the conversions the platform reports correspond to anything real. That check is the difference between auditing the account and auditing the advertising. If CRM access is genuinely unavailable, state that limitation explicitly in the findings rather than writing around it.

What is the first thing to check in a Google Ads audit?

Not the account — the intent. Ask the business owner, in their own words, what a successful outcome from this spend looks like and how they would know it happened. Write that down before opening the interface. Almost every serious finding in an audit is a gap between that sentence and what the account is actually configured to pursue, and you cannot see the gap if you never wrote down one side of it.

Does a good Google Ads audit include benchmark numbers?

No. Benchmark click-through rates, cost per click and conversion rates vary enormously by industry, geography, offer, seasonality and brand strength, so a finding based on an external average is a guess presented as evidence. Compare an account against its own history and against the business outcome it is meant to produce. If a number appears in a finding, it should come from the account or the CRM, with the date range stated.

How often should a Google Ads account be audited?

A full audit is worth running when something structural changes — a new manager takes over, spend increases materially, the offer or service area changes, or the account has drifted for a quarter without review. Between full audits, a short recurring check on the measurement stage and the search terms report catches most of what a full audit would find, far earlier and at much lower cost.

What can a Google Ads audit not tell you?

It cannot tell you whether your offer is competitive, whether your pricing is right, whether the sales team follows up on the leads it generates, or whether the market wants what you sell. An audit examines the machinery between a search and a form submission. If the problem sits before that — a weak offer — or after it — leads nobody calls back — a technically perfect account will not fix it.

Book a free 10-minute consultation

Sapun Lamichhane is a business growth analyst and founder of Arcetis, based in Pokhara, Nepal. If you want a second opinion on your account, your funnel, or whether a channel is worth your budget at all, book a free 10-minute call — no pitch, and a straight answer even when the answer is that you do not need help.

Direct: +977 9846162626 · lamichhanesapun2@gmail.com

This post supports the frameworks documented in full on the Authority page.