← All guides

GTM audit checklist

Last updated 17 September 2026 · 3 min read

This Google Tag Manager audit checklist walks through everything worth checking in a container — tags, triggers, variables, consent, and governance — so you can spot what's broken, redundant, or non-compliant. Work through it manually, or let Tagwise run every check automatically from your exported container.

An audit is only as good as the list you run it against. These are the checks that catch the problems that actually distort data or create compliance risk, grouped the way a container is structured.

Tags

  • Exactly one GA4 configuration ("Google") tag per Measurement ID — no duplicates.
  • No tag firing without a trigger, and no paused tag left standing in place of a deleted one.
  • No manual event tag duplicating something GA4 Enhanced Measurement already collects.
  • Advertising and pixel tags (Google Ads, Meta) present where expected, and not firing twice.
  • Custom HTML tags reviewed for what they inject and whether they're still needed.

Triggers

  • Every trigger is attached to at least one tag — no orphans.
  • No event tag sitting on an "All Pages" trigger that should be scoped to specific pages.
  • Trigger conditions actually match the events they're meant to catch (confirm in Preview).
  • No duplicate triggers doing the same job under different names.

Variables

  • IDs (Measurement IDs, conversion IDs) held in variables, not hardcoded inside tags.
  • Data layer variables reference keys that are genuinely pushed to the data layer.
  • No unused variables left cluttering the container.

Consent & privacy

  • Consent Mode v2 configured with the required signals: analytics_storage, ad_storage, ad_user_data, and ad_personalization.
  • Tags that need consent are gated and don't fire before it's granted.
  • Behaviour verified under both granted and denied consent in Preview.

Naming & governance

  • A consistent naming convention across tags, triggers, and variables.
  • Folders used to group related elements.
  • Version notes recorded so changes can be traced and rolled back.

Data layer

  • A consistent data layer present before GTM loads.
  • Ecommerce and key events push complete, correctly named parameters.
  • Tags read from the data layer only after the relevant values exist.

How to run this checklist

Manually, work through each item in the GTM interface and GA4 DebugView — thorough, but a few hours on a mid-sized container. Or run it automatically: Tagwise checks every item against your exported container in seconds, scores container health, and ranks what to fix first. Either way, re-run the checklist after any major change.

Key takeaways

  • The highest-impact checks are duplicate GA4 tags, orphaned triggers, and missing consent gating.
  • Hold IDs in variables, name everything consistently, and keep version notes.
  • Verify consent behaviour under both granted and denied states.
  • Re-audit after any significant site or tracking change.

Frequently asked questions

Want this checklist run for you? Run a free check

Start free assessment