GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit)
65-point QA checklist covering data stream settings, BigQuery exports, ecommerce parameters, and Consent Mode v2.
GA4 Enterprise Governance & Pipeline Architecture
Audits complete data pipeline from client dataLayer event initialization through tag orchestration, Consent Mode v2 gating, server-side enrichment, and BigQuery raw export streaming.
GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit) Configurator
GA4 & Server-Side Tagging Health Check — 65-Point Architecture Audit
Comprehensive enterprise measurement audit evaluating property governance, dataLayer schema, server-side GTM, Consent Mode v2, and BigQuery export linkage.
1 Input Parameters & Assumptions
| Parameter | Value | Context & Provenance |
|---|---|---|
| Property Governance & Retention | 15 Checks (20%) Weight: 0.20 | 14-month data retention, BigQuery export, cross-domain configuration |
| Data Layer & Ecommerce Schema | 15 Checks (25%) Weight: 0.25 | items[] array compliance, snake_case standards, transaction_id uniqueness |
| Server-Side Tagging & CAPI | 15 Checks (25%) Weight: 0.25 | event_id deduplication, first-party cookie extension, Cloud Run scaling |
| Consent Mode v2 & DMA | 10 Checks (15%) Weight: 0.15 | 4-signal defaults, CMP integration, cookieless ping modeling |
| BigQuery Export & Telemetry | 10 Checks (15%) Weight: 0.15 | Daily export, raw event unnesting, thresholding elimination |
2 Explicit Mathematical Formula
Audit Health Score = ∑ (Passed Checks in Category / Total Category Checks) × Category Weight × 100
Category Breakdown (65 Total Checks):
1. Property Governance & Retention: 15 checks (Weight: 20%)
2. Data Layer & Event Architecture: 15 checks (Weight: 25%)
3. Server-Side Tagging & Deduplication: 15 checks (Weight: 25%)
4. Consent Mode v2 & DMA Compliance: 10 checks (Weight: 15%)
5. BigQuery Export & Thresholding: 10 checks (Weight: 15%)
Certification Rating: PRODUCTION READY (>= 90%) / ATTENTION REQUIRED (70% - 89%) / CRITICAL GAPS (< 70%)3 Computed Output Metrics
| Computed Metric | Result | Interpretation & Threshold |
|---|---|---|
| Total Audit Checkpoints | 65 Criteria Checks | Exhaustive QA checklist covering every tier of enterprise measurement infrastructure |
| Data Retention Standard | 14 Months Property Limit | Admin setting upgraded from default 2 months to maximum 14 months |
| CAPI Deduplication Standard | 99%+ Match Rate | Near-perfect event_id alignment between browser Pixel and server CAPI hits |
| Certification Rating | Production Ready Rating Tier | Target benchmark required before launching high-scale paid acquisition |
GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit) — Scope & Limitations
Explicit operational boundaries and constraints defining target use cases and out-of-scope scenarios.
Built For (Target Use Cases)
- Running a 65-point manual QA audit across GA4 property governance, event schema, server-side tagging, consent, and BigQuery export.
- Tracking pass, fail, or not-applicable status per checklist item, saved locally in the browser.
- Exporting completed audit results as a CSV or Markdown report for a client or internal record.
Not Built For (Limitations & Out-of-Scope)
- Automated GA4 configuration scanning; every checkpoint requires a person to inspect the property and tick it.
- Syncing progress across devices or team members; saved state lives only in one browser's local storage.
- Auditing GA4 properties outside the 5 categories and 65 checkpoints defined in this checklist.
Operational Assumptions & Defaults
- Assumes the person completing the audit has admin access to inspect each GA4 and GTM setting checked.
- Category weightings (20/25/25/15/15%) are fixed and not configurable per audit.
- Clearing browser storage or switching browsers resets all checked items and notes for that checklist.
GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit)
65-Point Weighted AuditStateful multi-category audit engine. Your progress and notes are saved automatically in your browser.
Weighted Category Score Breakdown
1. Property Governance & Retention (15 Checks)
Weight: 20%Core GA4 data stream setup, retention limits, thresholding, and BigQuery export linkage.
gov-1Data Retention set to 14 monthsCRITICALDefault is 2 months. Update to 14 months in Admin > Data Settings > Data Retention.
gov-2BigQuery Daily and Streaming Export configuredHIGHEnsure raw unthresholded event tables stream to GCP BigQuery.
gov-3Google Signals thresholding reviewedHIGHSet Reporting Identity to Device-based or Blended to prevent row thresholding on custom dimensions.
gov-4Internal IP and Developer Traffic filtering activeMEDIUMTraffic filters set to Active to exclude office and staging hits from production.
gov-5Cross-Domain Measurement configured for all checkout subdomainsCRITICALDomains listed in Data Stream > More Tagging Settings > Configure your domains.
gov-6Unwanted referrals exclusion list configuredHIGHPayment gateways (PayPal, Stripe, Afterpay, Klarna) added to referral exclusion list.
gov-7Timezone and reporting currency aligned with primary accountingMEDIUMVerify currency and time zone match business books to prevent conversion value skew.
gov-8Enhanced Measurement settings tailoredLOWVerify scroll tracking, outbound clicks, site search, and file download triggers are active.
gov-9Custom Dimensions registered within 50-parameter quotaHIGHAll event parameters mapped in Custom Definitions to become visible in standard reports.
gov-10User-ID feature enabled for authenticated cross-device journeysMEDIUMDeterministic hashed CRM IDs passed in user_id field for logged-in accounts.
gov-11Data-driven attribution model selected as defaultMEDIUMAttribution Settings set to Data-driven with conversion credit distributed across channels.
gov-12Attribution lookback windows reviewed (30d / 90d)LOWAcquisition conversion events set to 30 days; all other conversion events set to 90 days.
gov-13Measurement Protocol API Secret generated and securedHIGHActive secret token created for offline CRM and server-side conversion imports.
gov-14User-provided data collection enabled for Enhanced ConversionsCRITICALGoogle Ads Enhanced Conversions enabled in GA4 Admin for first-party data matching.
gov-15Data collection acknowledgment and terms signedLOWEnsure legal data sharing terms are formally acknowledged in property settings.
2. Data Layer & Event Architecture (15 Checks)
Weight: 25%dataLayer timing, snake_case standards, and ecommerce event sequence.
dl-1dataLayer array initialised before GTM container snippetCRITICALwindow.dataLayer = window.dataLayer || [] declared in head before gtm.js loads.
dl-2Snake_case naming convention strictly enforcedMEDIUMAll event names and parameters use lowercase snake_case (no camelCase, kebab-case, or spaces).
dl-3Single-page app (SPA) page_view events deduplicatedHIGHVirtual route changes do not fire native and manual page_views simultaneously.
dl-4Ecommerce items[] array structure conforms to schemaCRITICALItems array contains item_id, item_name, price, quantity, and item_category.
dl-5view_item_list and select_item tracking activeMEDIUMCollection and catalog views pass item list name and product index positions.
dl-6view_item event firing with full SKU parametersHIGHProduct detail pages fire view_item with accurate item value and item_category hierarchy.
dl-7add_to_cart and remove_from_cart events trackedHIGHCart additions capture product quantity, price, and currency.
dl-8view_cart event tracking cart review intentMEDIUMCart drawer or page views fire view_cart with items array and cart total value.
dl-9begin_checkout event tracking initiationCRITICALCheckout start passes items array, value, and any applied coupon code.
dl-10add_shipping_info and add_payment_info events mappedMEDIUMFires when shipping tier and payment method are selected in checkout.
dl-11purchase event deduplication and transaction_id uniquenessCRITICALPurchase event passes unique transaction_id, value, tax, shipping, and currency.
dl-12refund and partial_refund events configuredMEDIUMReturns and order cancellations pass transaction_id and refunded item values.
dl-13Lead generation form submission events trackedHIGHLead forms push generate_lead with form_id and lead_type parameters.
dl-14Numeric parameters cast to integers or floatsHIGHPrice, value, and quantity parameters passed as numbers, not string literals.
dl-15Zero PII (email, phone, plaintext names) in URL strings or dataLayerCRITICALEnsure query strings and dataLayer events contain no unhashed personal information.
3. Server-Side Tagging & Deduplication (15 Checks)
Weight: 25%Server GTM container setup, Meta CAPI, event_id deduplication, and cookie preservers.
ss-1sGTM running on dedicated first-party subdomainCRITICALServer container routed via sgtm.yourdomain.com with first-party SSL.
ss-2GA4 Client Tag routing incoming /g/collect hitsCRITICALGA4 Client Tag in sGTM parses incoming browser hits and claims requests.
ss-3Meta CAPI server tag configured with System User tokenCRITICALMeta Conversions API tag active and authenticated via permanent access token.
ss-4event_id unique identifier shared across browser and server hitsCRITICALDeterministic event_id generated client-side and matched in Meta CAPI server tag.
ss-5Meta CAPI deduplication rate verified at 99%+HIGHMeta Events Manager confirms near 100% deduplication between Pixel and Server events.
ss-6Google Ads Server-Side Conversion tag configuredHIGHConversions routed via sGTM with user_data Enhanced Conversions matching.
ss-7First-party cookies set with HttpOnly and Secure flagsHIGHFPID and _ga cookie lifetime extended via sGTM Set-Cookie server response headers.
ss-8ITP cookie lifetime preserver configured (730-day cap)HIGHFirst-party server context protects client IDs from Safari 7-day ITP deletion.
ss-9Request headers sanitized before upstream forwardingMEDIUMsGTM transformation removes client IP and sensitive headers where required.
ss-10sGTM autoscaling configured (minimum 3 instances in Cloud Run)HIGHEnsures zero dropped tracking hits during peak conversion spikes and traffic surges.
ss-11Health check endpoint /healthy monitoredMEDIUMUptime monitor pings sGTM health URL to alert on container cold-starts or downtime.
ss-12Test Event Code supported for staging validationLOWtestEventCode parameter injected when testing Meta CAPI in staging.
ss-13Advanced Measurement Protocol transport URL override activeCRITICALClient-side gtag config sets transport_url pointing to sGTM server domain.
ss-14Edge CDN caching & compression enabled for tagging assetsMEDIUMCloudflare / CloudFront caches gtm.js and analytics.js proxies for sub-50ms loads.
ss-15Client IP and User Agent forwarded accurately in CAPI payloadsHIGHServer tag extracts x-forwarded-for and user-agent for EMQ parameter matching.
4. Consent Mode v2 & DMA Compliance (10 Checks)
Weight: 15%Consent defaults, 4-parameter v2 signals, CMP integration, and cookieless pings.
con-1Consent default state executed before GTM container loadsCRITICALgtag("consent", "default", {...}) fires in head before gtm.js initializes.
con-2All 4 Consent Mode v2 parameters declaredCRITICALad_storage, analytics_storage, ad_user_data, and ad_personalization all initialized.
con-3Default state set to denied for EEA and UK trafficCRITICALDefault denied signals enforced for European Economic Area visitors under DMA.
con-4CMP fires gtag consent update upon user choiceCRITICALConsent banner acceptance/rejection triggers consent update push immediately.
con-5gcd parameter verified in Tag Assistant network hitsHIGHOutgoing hits contain 10-char gcd string (e.g. 13r3r3r3r5 or 13t3t3t3t5).
con-6Legacy gcs parameter upgraded to Consent Mode v2MEDIUMVerify absence of legacy G100/G111 without companion gcd v2 parameters.
con-7Advanced Consent settings applied to non-Google tags in GTMHIGHMeta, TikTok, and LinkedIn tags configured to require explicit ad_storage consent.
con-8Cookieless pings transmitting when consent is deniedMEDIUMGA4 receives anonymous pings without reading or setting client cookies.
con-9Google Ads Conversion Modeling enabled in linked accountMEDIUMConversion modeling calibrates unconsented traffic pings against consented benchmarks.
con-10Annual CMP cookie scan and policy audit scheduledLOWAutomated monthly cookie categorization scanner active to catch newly added scripts.
5. BigQuery Export & Thresholding (10 Checks)
Weight: 15%Raw event streaming, partitioning, unnesting SQL marts, and access control.
bq-1GCP Project linked with daily and streaming exportCRITICALGA4 Admin > Product Links > BigQuery Links configured with active GCP billing.
bq-2Partition expiration and clustering configured on events_* tablesHIGHPartitioned by _TABLE_SUFFIX date and clustered by event_name and user_pseudo_id.
bq-3Reporting Identity set to Device-based or BlendedHIGHEliminates Google Signals thresholding in standard GA4 exploration reports.
bq-4Raw unnested event parameters dimensional mart createdHIGHScheduled query creates flattened table of custom dimensions for BI dashboards.
bq-5ga_session_id and user_pseudo_id unnested for session length calculationsMEDIUMSQL unnesting calculates true multi-touch session durations and bounce rates.
bq-6E-commerce items record unnested into flattened order linesHIGHSQL unnesting converts items nested array into item-level revenue records.
bq-7Service account granted least-privilege BigQuery rolesMEDIUMAnalytics service account granted BigQuery Data Viewer and Job User roles only.
bq-8GCP budget alerts configured for BigQuery query scansMEDIUMCost alert thresholds set up in Google Cloud Billing to prevent run-away queries.
bq-9Data retention policy configured for historical complianceLOWTable expiration set according to enterprise data retention and GDPR policy.
bq-10Intraday streaming events_intraday_* tables monitored for pipeline lagLOWReal-time streaming tables verified with sub-10 minute ingestion latency.
Execute Audit Findings & Remediation Plan
Complete the 65-point stateful audit checklist above, export your categorized action plan to Markdown or CSV, and apply the governance rules directly to your GA4 property.
Inject into development consoles to validate event naming conventions and required e-commerce parameters.
// GA4 DataLayer Governance Assertion Hook
(function auditDataLayer() {
const events = window.dataLayer.filter(item => item.event && !item.event.startsWith('gtm.'));
console.group('🔍 GA4 DataLayer Governance Audit');
events.forEach(e => {
const isSnakeCase = /^[a-z0-9_]+$/.test(e.event);
console.assert(isSnakeCase, '❌ Non-snake_case event detected:', e.event);
if (e.event === 'purchase') {
console.assert(e.ecommerce?.transaction_id, '❌ Purchase missing transaction_id:', e);
console.assert(typeof e.ecommerce?.value === 'number', '❌ Purchase value must be numeric:', e);
}
});
console.groupEnd();
})();Why Data Layer Governance Determines Measurement Integrity
Analytics leads spend dozens of hours diagnosing broken conversions, thresholded custom dimensions, and misconfigured data streams. This audit framework standardises the QA process across property settings, data layer initialisation, parameter casing, and consent timing.
Prerequisites & Implementation Guidance
Before running this 65-point audit, ensure your team has linked Google Analytics 4 with BigQuery to preserve raw event streaming. Standard UI sampling limits can hide parameter loss during high-traffic sales events.
Recommended Audit Cadence
Run this verification monthly for high-volume accounts and immediately after any website release, checkout update, or Consent Mode version change.
Common Failure Points
- Unintended Referral Attribution: Payment gateways such as PayPal, Stripe, and Afterpay appearing as organic referrers due to missing unwanted referral configuration.
- Duplicate Transaction Events: Purchase triggers firing on both order confirmation page render and subsequent user browser refreshes without transaction ID deduplication.
- Parameter Truncation: Custom event parameters exceeding the standard 100-character limit, resulting in silent data drops in standard exploration reports.
Related Resources
- Read our Server-Side GTM Container Recipe Pack to move client-side tag execution to server-side containers.
- Review the GA4 Framework Case Study to see this audit applied to enterprise multi-brand setups.
Changelog
- 1.0.0 (2026-08-01T08:00:00+10:00): Initial publication with 65 audit checkpoints across 7 governance pillars.
GA4 Property Health & Thresholding QA
Verify that data thresholds, thresholding asterisks, session timeouts, and cross-domain tracking match enterprise specifications.
Pre-Production Verification Checklist
Ensure Admin > Data Settings > Data Retention is set to 14 months rather than default 2 months.
Switch Reporting Identity to "Device-based" if cardinality thresholding masks granular landing page metrics.
Verify internal developer/office IP ranges are set to "Active" rather than "Testing" state.
Confirm daily export and intraday streaming datasets show zero billing export errors in GCP Cloud Logging.
Terminal Diagnostic & Debug Commands
Dumps all purchase transactions pushed to dataLayer on current page session.
window.dataLayer.filter(i => i.event === "purchase")Failure Remediation & Troubleshooting
Cause: Google Signals is enabled with low volume per dimension, triggering automated privacy masking.
Fix: Go to Admin > Reporting Identity > Show all > Select "Device-based" identity to unmask dimension rows.
Cause: Payment gateway redirect broke cross-domain linker or stripped _ga cookie on return callback.
Fix: Add payment gateway domain (e.g. pay.stripe.com) to "List Unwanted Referrals" in GA4 Web Stream settings.
How to cite and attribute this tool
CC BY 4.0 LicenceThis resource is free, open and un-gated under the Creative Commons Attribution 4.0 (CC BY 4.0). You are encouraged to use, integrate and cite it with attribution:
@misc{geraghty_ga4_audit_checklist,
author = {Geraghty, Gordon},
title = {GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit)},
year = {2026},
url = {https://gordongeraghty.com/resources/gtm-analytics/ga4-audit-checklist},
note = {Head of Performance Media, Empire Amplify}
}Changelog & Version History
v1.0.0Initial publication with 65 audit checkpoints across 7 governance pillars.
Strategic Takeaway & Operational Guidelines
The default GA4 setup drops data after 2 months, thresholds custom dimensions, and loses 20-30% of conversion signals to ad blockers. Completing this 65-point audit ensures clean, unthresholded telemetry streams directly to BigQuery.