GA4 Audit Checklist for New Agency Clients

A practical GA4 audit checklist for new agency clients - the 12 checks to run before your first report, plus first-party data on what usually breaks.

Ready to get started?

Set up in 2 minutes. White-label reports and AI insights.

14-day free trial - 2 min setup - no credit card required

GA4 audit checklist for new agency clients

You have signed the client. You have the logins. The first monthly report is due in three weeks, and somewhere in that Google Analytics 4 property is a setting nobody has touched since the site was built.

This is the part of onboarding that quietly decides whether your reporting looks competent for the next two years. A GA4 audit checklist takes an hour or two in week one and saves you the far worse conversation in month three, where you explain why the conversions in your report do not match the leads in the client's inbox.

We build an automated reporting platform that connects to Google Analytics 4, so we see a lot of client properties the moment an agency plugs them in. The pattern is consistent: the property is collecting data, it just is not collecting the data anyone wants to report on. Below is the checklist we would run, in the order we would run it, with the first-party numbers that explain why each step is on the list.

Last updated: October 2026

Key takeaways

  • A GA4 audit checklist is a fixed set of configuration checks you run on a new client's Google Analytics 4 property before you commit to reporting on it: access, property structure, key events, channel tagging, data settings and platform links.
  • Key events are the most common failure. Across 26 cached GA4 report snapshots covering 16 client properties inside ReportsMate (queried October 2026), 15 snapshots recorded zero conversions for the period and 25 of 26 recorded zero attributed revenue.
  • Channel tagging is the second failure. 20 of those 26 snapshots had at least one session landing in Unassigned, and not one snapshot recorded a single session in GA4's Email channel.
  • Do not treat bounce rate as a benchmark. Across the same snapshots the median bounce rate was 59% but the range ran the full 0% to 100%, so define the metric before you put it in front of a client.
  • Order matters, because GA4 changes are not retroactive. Fix access first, key events second, tagging third. Data you did not collect in October cannot be recovered in November.

Table of contents

What is a GA4 audit checklist?

A GA4 audit checklist is a repeatable list of configuration checks you run on a Google Analytics 4 property to confirm the data it collects is accurate, complete and safe to report on. It is not a performance review of the client's marketing. It is a check on the instrument you are about to measure that marketing with.

A proper google analytics 4 audit covers six areas: who has access and at what level, whether the property and data stream are the right ones, whether the actions that matter are configured as key events, whether traffic is being attributed to the right channels, what the data settings allow you to see, and whether the property is linked to the other Google products in scope.

Two bits of GA4 vocabulary worth pinning down before you start. Key events are what GA4 calls the events you have marked as important; Google renamed conversions to key events in the Analytics interface, and the two words now mean slightly different things depending on whether you are looking at Analytics or Google Ads, which is covered in our breakdown of GA4 key events versus conversions. Default channel groups are GA4's built-in rules for sorting sessions into buckets like Organic Search, Paid Search and Email, based on the source and medium values each visit arrives with.

Treat the audit as part of client onboarding rather than an optional extra. An analytics onboarding audit done in week one is diagnostic. The same audit done in month four is an apology.

Why audit GA4 before the first client report?

Because the most common state for a new client's GA4 property is "collecting traffic, measuring nothing". We can put numbers on that from our own platform.

ReportsMate caches the report data it pulls for each connected client. As at October 2026 that cache held 26 Google Analytics 4 report snapshots spanning 16 distinct client properties. In 15 of the 26 snapshots, GA4 returned zero conversions for the reporting period, and 10 of the 16 properties were in that position. In 25 of 26 snapshots, attributed revenue was zero.

One caveat before you quote that back at anyone: those snapshots come from only two agency accounts, so read them as directional evidence of what agencies inherit, not as an industry benchmark. Half of the properties were also small, with 10 of 26 snapshots under 100 sessions for the period.

The point stands regardless of sample size. A property with no key events marked cannot answer the only question a client actually cares about, which is whether the marketing produced anything. You can report sessions and users all year and still get fired, because sessions are not a business outcome.

GA4 is also the source agencies rely on most. Of the 43 clients with at least one platform connected in our database, 30 have Google Analytics 4 attached, which makes it the most-connected platform we see, ahead of Meta Ads (16) and Google Ads (13). If GA4 is wrong, most of the report is wrong.

There is a second reason to front-load the work: configuration changes in GA4 are not retroactive. Mark a key event today and you get data from today. There is no backfill, which is why "we will tidy up the analytics later" is the most expensive sentence in agency onboarding.

The 12-point GA4 audit checklist

Here is the whole ga4 audit checklist in one table. Work top to bottom; the early rows block the later ones.

#CheckWhat you are looking forWhy it matters for reporting
1Access levelEditor or Administrator on the property, granted to your agency's accountViewer access cannot fix anything you find
2Correct propertyOne live property and data stream per site, no abandoned test propertiesReporting on the wrong property is unrecoverable
3Timezone and currencyReporting timezone matches the client's trading hours; currency matches what they invoice inMisaligned timezones shift every daily and monthly total
4Internal traffic filterInternal IPs defined and the filter set to Active, not TestingStaff and agency visits inflate sessions and deflate conversion rate
5Unwanted referralsPayment gateways and booking tools excluded as referral sourcesCheckout redirects otherwise break the session and steal the credit
6Key events existThe actions that matter are firing as eventsNo events, no outcomes to report
7Key events markedThose events are toggled on as key eventsUnmarked events never reach the conversion columns
8No double countingOne key event per real-world outcomeA form event plus a thank-you page event doubles every lead
9Revenue valuesPurchase or value parameters actually populate, where revenue is in scopeZero revenue makes return on ad spend impossible to show
10Unassigned trafficThe Unassigned channel is close to zeroUnassigned traffic cannot be credited to any campaign
11Platform linksGoogle Ads and Search Console linked to the propertyUnlinked properties leave paid and organic reporting blind
12Data settingsEvent data retention raised from the default; thresholding understoodShort retention silently empties year-on-year comparisons

Print it, keep it in your onboarding doc, and record the answers per client. The audit is only worth doing once if the result is written down somewhere your team can find it.

How do you check GA4 access and permissions?

Start with access, because every other fix depends on it. Open Admin, then Property access management, and confirm your agency account has at least Editor on the property. Editor lets you create key events, define filters and change data settings. Viewer and Analyst do not.

Three details agencies get wrong here. First, access should be granted to a work account that survives staff turnover, not to one person's personal Google login. Second, check whether you have access at account level or only property level, because some settings sit above the property. Third, look at who else has Administrator, since a previous agency with lingering admin rights can undo your work without telling anyone.

In practice getting access is the slowest part of onboarding, and we can measure that too. Looking at the 43 connected clients in our database, the median gap between a client record being created and its first platform connection going live was about 25 days. Fourteen of those 43 connected inside the first hour, so the work itself is quick; the other 17 took more than a month, which is chasing, not configuring.

Ask for everything in one request rather than three. Our guide to getting client access to Google Ads and GA4 has the wording we use for that email. One more thing worth knowing from our own connection data: every Google connection in our platform stays active until someone revokes it, while the only expired credentials we see are on Meta Ads, where tokens lapse on a timer. Google access is a one-time ask; Meta is a recurring one.

How do you check the property, timezone and filters?

Confirm you are in the right property before you change a single setting. Many businesses have several GA4 properties: one from a web developer, one from a previous agency, one created by accident during the Universal Analytics migration. Check which one the live site's tag actually sends data to, rather than which one looks most official.

Then check the data stream. One website should have one web data stream. If you find two streams collecting the same site, sessions are probably being split or counted twice.

Next, the three settings that quietly distort every total:

  • Reporting timezone. GA4 buckets days by the property timezone. If a client trades in Sydney and the property is set to Los Angeles, your Monday is their Tuesday afternoon, and every daily figure you report is wrong by hours.
  • Currency. Revenue is converted to the property currency. A property set to USD for a business invoicing in GBP produces numbers the client's finance team will not recognise.
  • Internal traffic filter. Defining internal IPs is only half the job. The filter ships in Testing mode, where it tags traffic without excluding it. Set it to Active.

While you are in data streams, open the list of unwanted referrals. Payment gateways, booking engines and third-party checkouts break the session when they redirect, so the conversion gets credited to the gateway instead of the campaign that earned it. Adding those domains to the unwanted referrals list in the data stream's tagging settings is a two-minute fix that changes the shape of every attribution report you will ever send.

How do you check key events and conversions?

Open Admin, then Events, and look at two columns: whether the event exists, and whether it is marked as a key event. This is where most properties fail, and it is the single highest-value item on the checklist.

Work from the client's business, not from GA4's event list. Write down the three to five outcomes that make the client money, then find the event for each one. A lead generation business usually needs form submissions, phone taps and maybe a quote request. An ecommerce store needs the full purchase path. If an outcome has no event, it needs building before it can be reported.

Then check the toggle. An event that fires but is not marked as a key event will not appear in the conversion columns of any report, which is exactly the state we see in more than half of the GA4 snapshots we hold. It looks like a tracking failure and is actually a switch nobody flipped.

Now hunt for double counting. The classic version is a form submission event plus a thank-you page view, both marked as key events, which doubles every lead the client has. Compare one week of GA4 key events against the client's own record of enquiries, their CRM, their inbox, their phone log. If GA4 says 40 and the inbox says 20, you have found your problem before the client found it for you.

Finally, if revenue is in scope, confirm the value parameter is populating rather than arriving as zero. Attributed revenue was zero in 25 of our 26 snapshots, and while plenty of those properties are lead generation sites with no revenue to send, an ecommerce client with zero revenue in GA4 has a measurement problem that no reporting tool can paper over.

How do you check traffic sources and UTM tagging?

Open the Traffic acquisition report, set it to default channel group, and look for the Unassigned row. Unassigned means GA4 received a session it could not match to any channel rule, which almost always traces back to tagging, a redirect stripping parameters, or a campaign link built by hand.

Our own data says this is near-universal. Of 26 GA4 report snapshots, 20 had at least one session in Unassigned, covering 12 of the 16 properties; eight snapshots had Unassigned at 5% or more of sessions. The median share was small at 1.4%, so for most properties this is a nagging data-quality issue rather than a crisis, but the tail is ugly and the tail is where campaign reporting breaks.

The more telling number is the Email channel. Not one of those 26 snapshots recorded a single session in Email. GA4's Email rule only matches sessions whose source or medium looks like email, e-mail, e_mail or e mail, so a newsletter link tagged utm_medium=newsletter or utm_medium=Email_Campaign lands somewhere else entirely, usually Referral or Unassigned. Clients running email campaigns therefore see no email traffic in GA4 and conclude the channel does not work.

Three habits fix most of it:

  1. Lowercase every UTM value. GA4 channel rules are case sensitive in practice, and Email is not email.
  2. Use the medium values GA4 recognises for the standard channels, then use utm_campaign and utm_content for your own naming detail.
  3. Tag one link per destination and store the convention somewhere shared, so the client's email platform and your ad accounts do not invent two different schemes.

Direct traffic deserves a sanity check at the same time. The median Direct share across our snapshots was 50%, and seven of 26 snapshots had Direct above 70%. A very high Direct share usually means untagged links, not a famous brand. Our explainer on GA4 default channel groups sets out the exact rules each channel uses, and Google documents the full channel definitions in the Analytics Help centre at support.google.com/analytics.

How do you check data retention and thresholding?

Go to Admin, then Data settings, then Data retention, and check the event data retention window. New properties default to the shorter option, which is the setting that destroys year-on-year reporting. Raise it to the longest window your property allows and do it on day one, because the change is not retroactive: raising retention in March does not bring back the data that expired in January.

This matters more than it sounds for agency reporting. Across the 46 client records in our platform, 44 are less than a year old and the median is roughly six months. Nobody can show a client a true year-on-year GA4 comparison until the property has been retained properly for that long, which makes the retention setting a decision about what reports you will be able to produce in 2027.

While you are in data settings, understand thresholding. GA4 withholds rows when a report could identify individual users, usually when Google signals or demographics are enabled and the numbers are small. The effect is that totals stop reconciling between reports and some dimensions come back visibly incomplete. It is not a bug and you cannot switch it off per report, but you can recognise it, and you should explain it before a client spots it. We cover the mechanics in GA4 data sampling and thresholding.

One more sanity check belongs here: pick a metric with a contested definition and decide now how you will report it. Bounce rate is the usual candidate. Across our 26 snapshots the median bounce rate was 59%, the middle half sat between 48% and 71%, and the full range covered 0% to 100%. A spread that wide across 16 properties tells you there is no normal bounce rate to compare a client against, so report it as a trend on their own property or do not report it at all.

Open Admin, then Product links, and confirm the links the client's channel mix requires. For most agency clients that means Google Ads and Search Console; for local businesses it may also mean Google Business Profile reporting alongside GA4.

For Google Ads, check three things: the account is linked to the property, auto-tagging is enabled in the Google Ads account, and the GA4 key events you want to bid on are being imported. Without the link, paid traffic lands in Paid Search only when the landing URLs happen to be tagged manually, and you lose the campaign and keyword detail entirely. Auto-tagging settings live in the Google Ads account and are documented in Google Ads Help at support.google.com/google-ads.

Our snapshot data suggests this link is often missing. Only nine of 26 GA4 snapshots recorded any Paid Search sessions at all, and cross-network traffic, the channel Performance Max and other automated campaigns land in, appeared in just seven of the 16 properties. Some of those clients genuinely run no paid search. Some are running it into a property that cannot see it.

For Search Console, the link is what makes GA4's organic queries and landing page reports work. Google's own guidance on connecting Search Console to Analytics and on what each product measures sits in Google Search Central and Search Console Help. Expect the two tools to disagree on organic sessions versus clicks; they count different things, and saying so in the report is better than being asked.

If you report paid and organic together, do the reconciliation once during onboarding and write down the expected discrepancy. The first time a client compares your GA4 number to their Google Ads number is not the moment to start investigating.

What do you fix first after a GA4 setup check for clients?

Fix in this order: anything that stops data being collected, anything that misattributes data, then anything cosmetic. A GA4 setup check for clients routinely turns up a dozen issues, and they are not equally urgent.

Fix this week, because the data loss compounds:

  1. Missing or unmarked key events
  2. Event data retention still on the default window
  3. Internal traffic filter left in Testing mode
  4. Double-counted key events inflating every lead number

Fix this month:

  1. Google Ads and Search Console links
  2. Unwanted referral exclusions for gateways and booking tools
  3. UTM conventions documented and rolled out to the client's email and social tools
  4. Timezone and currency, if a change is safe to make mid-period

Document rather than fix:

  1. Historic data that predates the audit and cannot be corrected
  2. Thresholded reports and any known discrepancy between platforms

That last group matters more than it looks. Put a short note in the first report stating what was fixed, what date the clean data starts from, and which comparisons are therefore unavailable until that date passes. Clients do not punish you for inheriting a mess; they punish you for a number that changes without explanation.

Here is the one we have learned to say out loud: we built ReportsMate email-first because, after years around agency reporting, the dashboards clients were handed almost never got logged into, and the tracking problems nobody mentioned in writing always resurfaced in a renewal conversation. The audit note in report one is cheap insurance.

See how automated reporting works once the property is clean.

How do you turn the audit into a reporting cadence?

Connect the audited property to your reporting workflow the same week you finish the audit, while the configuration is fresh and you still remember what you changed. Reporting cadence just means how often reports go out and how predictably; the predictability is the part clients notice.

Connecting GA4 to ReportsMate takes about 60 seconds through a single Google OAuth click, with no API keys to manage, and the same connection flow covers Google Ads, Meta Ads, Search Console and Google Business Profile. From there you set a daily, weekly or monthly schedule and the report is delivered as a branded email, sent from your own domain and sender identity so it reads as your agency's work rather than a tool's. White-labelling means exactly that: your logo, your sending domain, no third-party branding in the client's inbox.

That is the deliberate difference between us and the dashboard tools. AgencyAnalytics, DashThis, Whatagraph, Swydo, Supermetrics and Looker Studio all build competent client dashboards, and if your clients log in regularly a dashboard is a fine answer. Our bet, as the people who make an email-first product, is that most clients never log in and the report that lands in the inbox is the one that gets read. Judge that claim against your own clients' behaviour, not ours.

A cadence also keeps the audit alive. Tracking breaks after a site migration, a new form plugin, a developer removing a tag. A report that arrives weekly surfaces a broken key event within days, weeks earlier than a monthly report would. Pair that with a short re-audit every quarter and you keep the data clean without another full onboarding exercise.

FAQs

Q: How long does a GA4 audit take?

A: Budget 60 to 90 minutes for the checks themselves on a single-site client, plus whatever implementation the findings require. The audit is fast because almost all of it is reading settings in the Admin area. What takes time is building missing key events, which may need a developer or a tag manager change, and chasing the access that lets you do it. In our own data the median gap between a new client record and its first live platform connection was about 25 days, and nearly all of that is waiting for permissions rather than doing the work. Ask for access on the day you sign, and book the audit for the week after.

Q: What is the most common GA4 problem on a new client property?

A: Missing or unmarked key events. Across 26 cached GA4 report snapshots covering 16 client properties in our platform, 15 returned zero conversions for the reporting period, and 10 of the 16 properties were affected. Sometimes the event does not exist; often it fires correctly but was never toggled on as a key event, so it never reaches the conversion columns in any report. The second most common problem is channel tagging, where traffic lands in Unassigned or misses the Email channel entirely. Both are configuration issues rather than tracking failures, which is good news: they are fixable in an afternoon.

Q: Can I fix GA4 data retroactively?

A: No. GA4 configuration changes apply from the moment you make them, with no backfill. Marking a key event, raising the data retention window, activating an internal traffic filter or excluding an unwanted referral all start working on the day you do them, and the historic data stays as it was collected. That is the entire argument for running the audit in week one rather than week ten. It is also why your first report should state the date the corrected data starts from, so the client understands why a comparison to last quarter is not available yet.

Q: Who should own the GA4 audit, the agency or the client?

A: The agency should own it, because the agency is the one whose reporting depends on it. Clients rarely have an internal analytics owner, and the developer who installed the tag has usually moved on. What you need from the client is administrator-level access, a list of the outcomes that make them money, and a decision-maker who can approve a tag manager change. Hand back a one-page summary of what you found and fixed; it is one of the easiest trust-building documents in onboarding, and it pairs well with a fixed GA4 report template for agency clients, and it positions every later report as measured work rather than guesswork.

Q: Should I audit GA4 or just rebuild the property?

A: Audit first, rebuild only if the property is unsalvageable. Creating a fresh property resets your history to zero, which means no year-on-year comparison and no trend line until the new property has run long enough to produce one. Given that 44 of the 46 client records in our platform are under a year old, most agencies are already short on history and cannot afford to throw more away. Rebuild when the existing property has structural problems you cannot fix, such as multiple sites collecting into one stream with no way to separate them. Otherwise fix what is there.

Q: What should be in the first report after a GA4 audit?

A: Lead with the outcomes the client cares about, the key events you just confirmed are working, then traffic and engagement as context. Add a short note covering three things: what you fixed, which date the clean data starts from, and which comparisons are therefore unavailable until that date passes. Keep the metric set small; a report with six numbers a client understands beats one with 30 they skim. If you report bounce rate, report it as a trend on their own property, because the spread across the 16 properties we hold data for ran the full 0% to 100% and there is no useful external average to compare against.

Q: How often should I re-audit a client's GA4 property?

A: Quarterly as a short re-check, and immediately after any site migration, theme change, form plugin swap or tag manager cleanup. The quarterly pass only needs to cover the settings most likely to drift: key events still firing, Unassigned share still low, product links still connected, filters still active. A regular reporting cadence does most of the monitoring for you, since a weekly report makes a broken key event obvious within days instead of at the end of the month. Put the re-check in the same recurring calendar slot as your retainer review so it never becomes optional.

Q: Does a GA4 audit replace a Google Ads or Meta audit?

A: No, though it makes both more useful. GA4 is where you verify that outcomes are being measured consistently across channels; the platform audits are where you examine spend, structure and creative. The GA4 audit should confirm the plumbing between them: that Google Ads is linked with auto-tagging on, that imported key events match what you intend to bid towards, and that paid traffic is landing in the right channel. Of 43 connected clients in our data, 13 have Google Ads attached and all 13 also have GA4, which is the normal pattern: GA4 is the shared measurement layer under every paid channel audit you run.

Run the checklist once, then automate the reporting

A GA4 audit checklist is not sophisticated work. It is reading a dozen or so settings in a fixed order and writing down what you find. The reason it pays is that almost nobody does it, which is why more than half the GA4 properties we see report zero conversions while cheerfully reporting sessions to the decimal point.

Do it in week one. Fix key events, retention and filters first because the data loss compounds. Document the rest, state the clean-data start date in your first report, and re-check it quarterly.

Then stop doing the reporting by hand. Once the property is configured properly, the monthly export, the copy-paste into a template and the Sunday night commentary are all work a machine should be doing, and a weekly or monthly schedule catches the next tracking break long before a client does.

Stop losing your Sundays to client reports. Start your free 14-day trial - no credit card, no setup fees, cancel anytime. Your clients get branded reports in their inbox automatically, from your domain, with the AI-written summary already in the email.

Automate Your Marketing Reporting

Join agencies automating client reporting with ReportsMate.

14-day free trial - 2 min setup - no credit card required