What a Consent Audit Actually Finds

“Audit” is a word that makes people picture a spreadsheet and a large invoice. In this context it means something narrower and more concrete: we load your site the way an actual first-time visitor’s browser loads it, and we write down everything that happens.

What that produces is rarely what the site owner expects. Below is a composite of the findings that come up again and again — not one client’s report, but the recurring cast of characters that shows up across sites of every size.

The scripts nobody remembers adding

This is the single most common finding, and it is almost never anyone’s fault in particular.

A site that has been running for five or six years has been touched by a succession of people. An agency ran a campaign in 2021 and left its pixel behind. Someone trialed a heatmap tool, decided against it, cancelled the subscription — and the script stayed in the header, still firing, still resolving, still sending a request on every page view. A retargeting tag from a platform the company no longer advertises on. A conversion tracker for a product that was discontinued.

None of this appears in any documentation because none of it was ever documented. It accumulated. And every one of these is a third-party request going out before consent, attached to a vendor relationship that no longer exists — which is a distinctly awkward thing to have to explain.

The embeds

Embedded content is tracking that does not look like tracking, which is why it survives so many rounds of cleanup.

  • An embedded video on your about page contacts the platform and can set cookies as soon as the page renders, whether or not anyone presses play. Most platforms offer a privacy-enhanced embed mode. Most sites are not using it.
  • An embedded map on the contact page loads third-party resources on arrival.
  • Social share buttons and follow widgets contact their platforms on load — the platform learns which page the visitor is reading regardless of whether anyone clicks.
  • Web fonts served from a third party transmit the visitor’s IP address to that provider. This has been the subject of enforcement decisions in Europe, and the fix is generally as simple as self-hosting.

The plugin that quietly started tracking

A particular favorite, and a good argument for scanning on a schedule rather than once.

A plugin that had nothing to do with tracking releases an update that adds analytics, a support widget, or a phone-home for usage telemetry. The site owner does what everyone does with plugin updates: applies it, sees the site still works, moves on. A new third-party request has just appeared on every page and nothing announced it.

Nobody is going to catch this by reading changelogs. It is caught by scanning and comparing against last month’s scan.

The banner that records but does not act

When a consent platform is already installed, the most frequent finding is that it is doing precisely half its job.

The banner appears. The visitor clicks reject. A cookie is written faithfully recording that rejection. The confirmation appears. And every script that was loading a moment ago continues to load, because the blocking layer was never switched on, or was switched on but only for the three scripts the platform auto-detected, or the scripts were added to the page directly rather than through the tag manager the platform knows about.

This is a worse position than having no banner at all. Without a banner, you have an unaddressed gap. With this, you have made an explicit representation to every visitor about what happens when they decline, and the representation is not accurate.

The categorization that was never done

Consent platforms ship with a script scanner. It is decent at recognizing the obvious names and poor at anything bespoke. What it cannot classify it usually files as necessary or leaves alone entirely — which is the safe default for not breaking the site, and the wrong default for compliance.

So the audit routinely finds a marketing tool sitting in the “strictly necessary” bucket. Not maliciously. The scanner did not recognize it, nobody reviewed the list afterward, and a category that is supposed to mean “the site cannot function without this” quietly acquired a passenger.

The pages that were never checked

Testing tends to happen on the homepage, because that is where everyone starts. But the homepage is often the cleanest page on the site.

Checkout flows carry payment and fraud scripts. Landing pages built for specific campaigns frequently have campaign-specific tags hardcoded into them, added in a hurry and never removed. Gated content pages have form and marketing-automation scripts. Blog posts have whatever was embedded in them at the time of writing, going back years.

A site can pass a homepage test comfortably and fail on the page where the most sensitive information is being entered.

What you get at the end

The report is deliberately not a legal document. It is an inventory: what loaded before consent, what cookies were set, what requests went out and to whom, what happened after clicking reject, and which items need attention first. Written in plain English, with screenshots, because the point is that you can read it yourself and decide what to do.

The reject test is where most existing setups fall apart, so it gets equal weight to the pre-consent scan. Recording what happens when someone accepts is easy. Recording what happens when they decline is the part that tells you whether any of it is real.

Most of what turns up is fixable in a single focused engagement. The scripts nobody needs get removed. The rest get categorized and properly gated. Consent Mode gets configured so measurement survives. Then it gets tested across browsers rather than just the one on our desk.

The value of the audit is not the fixing. It is that you stop guessing about what your own site does.

We’re not attorneys and this isn’t legal advice. We handle the technical side: making sure what’s on your site does what you think it does.


Find out what your site is actually loading

We’ll run the audit and show you what fires before anyone clicks accept.