Skip to content

GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit)

65-point QA checklist covering data stream settings, BigQuery exports, ecommerce parameters, and Consent Mode v2.

By Gordon Geraghty·CC BY 4.0 Licence·Updated: 24 September 2026·INTERMEDIATE
01 Prerequisites & Architecture
Stage 01 Architecture

GA4 Enterprise Governance & Pipeline Architecture

Audits complete data pipeline from client dataLayer event initialization through tag orchestration, Consent Mode v2 gating, server-side enrichment, and BigQuery raw export streaming.

Difficulty:Intermediate Engineering
Time:45–60 mins
Required Access & Permissions:
GA4 Property AdministratorGTM EditorGCP IAM BigQuery Data Viewer
STEP 01Web DOM / App SDK
dataLayer StandardsSnake_case naming & parameter typing
STEP 02Google CMP / gtag.js
Consent Mode v2GCD/GCS bitmask enforcement & DMA gates
STEP 03Google Analytics 4
GA4 Data StreamsEnhanced measurement & session timeout (30m)
STEP 04GCP BigQuery Raw Export
BigQuery WarehouseDaily partition & real-time streaming tables
02 Interactive Configurator

GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit) Configurator

Worked Example · Deterministic Calculation

GA4 & Server-Side Tagging Health Check — 65-Point Architecture Audit

Comprehensive enterprise measurement audit evaluating property governance, dataLayer schema, server-side GTM, Consent Mode v2, and BigQuery export linkage.

1 Input Parameters & Assumptions

ParameterValueContext & Provenance
Property Governance & Retention15 Checks (20%) Weight: 0.2014-month data retention, BigQuery export, cross-domain configuration
Data Layer & Ecommerce Schema15 Checks (25%) Weight: 0.25items[] array compliance, snake_case standards, transaction_id uniqueness
Server-Side Tagging & CAPI15 Checks (25%) Weight: 0.25event_id deduplication, first-party cookie extension, Cloud Run scaling
Consent Mode v2 & DMA10 Checks (15%) Weight: 0.154-signal defaults, CMP integration, cookieless ping modeling
BigQuery Export & Telemetry10 Checks (15%) Weight: 0.15Daily export, raw event unnesting, thresholding elimination

2 Explicit Mathematical Formula

Audit Health Score = ∑ (Passed Checks in Category / Total Category Checks) × Category Weight × 100
Category Breakdown (65 Total Checks):
1. Property Governance & Retention: 15 checks (Weight: 20%)
2. Data Layer & Event Architecture: 15 checks (Weight: 25%)
3. Server-Side Tagging & Deduplication: 15 checks (Weight: 25%)
4. Consent Mode v2 & DMA Compliance: 10 checks (Weight: 15%)
5. BigQuery Export & Thresholding: 10 checks (Weight: 15%)
Certification Rating: PRODUCTION READY (>= 90%) / ATTENTION REQUIRED (70% - 89%) / CRITICAL GAPS (< 70%)

3 Computed Output Metrics

Total Audit Checkpoints65 CriteriaChecksExhaustive QA checklist covering every tier of enterprise measurement infrastructure
Data Retention Standard14 MonthsProperty LimitAdmin setting upgraded from default 2 months to maximum 14 months
CAPI Deduplication Standard99%+Match RateNear-perfect event_id alignment between browser Pixel and server CAPI hits
Certification RatingProduction ReadyRating TierTarget benchmark required before launching high-scale paid acquisition
Computed MetricResultInterpretation & Threshold
Total Audit Checkpoints65 Criteria ChecksExhaustive QA checklist covering every tier of enterprise measurement infrastructure
Data Retention Standard14 Months Property LimitAdmin setting upgraded from default 2 months to maximum 14 months
CAPI Deduplication Standard99%+ Match RateNear-perfect event_id alignment between browser Pixel and server CAPI hits
Certification RatingProduction Ready Rating TierTarget benchmark required before launching high-scale paid acquisition

Strategic Takeaway & Operational Guidelines

The default GA4 setup drops data after 2 months, thresholds custom dimensions, and loses 20-30% of conversion signals to ad blockers. Completing this 65-point audit ensures clean, unthresholded telemetry streams directly to BigQuery.

INSTRUMENT BOUNDARIES

GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit) — Scope & Limitations

Explicit operational boundaries and constraints defining target use cases and out-of-scope scenarios.

Built For (Target Use Cases)

  • Running a 65-point manual QA audit across GA4 property governance, event schema, server-side tagging, consent, and BigQuery export.
  • Tracking pass, fail, or not-applicable status per checklist item, saved locally in the browser.
  • Exporting completed audit results as a CSV or Markdown report for a client or internal record.

Not Built For (Limitations & Out-of-Scope)

  • Automated GA4 configuration scanning; every checkpoint requires a person to inspect the property and tick it.
  • Syncing progress across devices or team members; saved state lives only in one browser's local storage.
  • Auditing GA4 properties outside the 5 categories and 65 checkpoints defined in this checklist.

Operational Assumptions & Defaults

  • Assumes the person completing the audit has admin access to inspect each GA4 and GTM setting checked.
  • Category weightings (20/25/25/15/15%) are fixed and not configurable per audit.
  • Clearing browser storage or switching browsers resets all checked items and notes for that checklist.

GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit)

65-Point Weighted Audit

Stateful multi-category audit engine. Your progress and notes are saved automatically in your browser.

Overall Health Index0 / 100Category-weighted health score
Audit Progress0%0 of 65 items evaluated
Passed Checks0Verified compliant checkpoints
Action Items / Fails0Requires remediation
Weighted Category Score Breakdown
1. Property Governance & Retention (15 Checks) (Weight: 20%)0/15 passed (0%) : +0.0 pts
2. Data Layer & Event Architecture (15 Checks) (Weight: 25%)0/15 passed (0%) : +0.0 pts
3. Server-Side Tagging & Deduplication (15 Checks) (Weight: 25%)0/15 passed (0%) : +0.0 pts
4. Consent Mode v2 & DMA Compliance (10 Checks) (Weight: 15%)0/10 passed (0%) : +0.0 pts
5. BigQuery Export & Thresholding (10 Checks) (Weight: 15%)0/10 passed (0%) : +0.0 pts

1. Property Governance & Retention (15 Checks)

Weight: 20%

Core GA4 data stream setup, retention limits, thresholding, and BigQuery export linkage.

gov-1Data Retention set to 14 monthsCRITICAL

Default is 2 months. Update to 14 months in Admin > Data Settings > Data Retention.

gov-2BigQuery Daily and Streaming Export configuredHIGH

Ensure raw unthresholded event tables stream to GCP BigQuery.

gov-3Google Signals thresholding reviewedHIGH

Set Reporting Identity to Device-based or Blended to prevent row thresholding on custom dimensions.

gov-4Internal IP and Developer Traffic filtering activeMEDIUM

Traffic filters set to Active to exclude office and staging hits from production.

gov-5Cross-Domain Measurement configured for all checkout subdomainsCRITICAL

Domains listed in Data Stream > More Tagging Settings > Configure your domains.

gov-6Unwanted referrals exclusion list configuredHIGH

Payment gateways (PayPal, Stripe, Afterpay, Klarna) added to referral exclusion list.

gov-7Timezone and reporting currency aligned with primary accountingMEDIUM

Verify currency and time zone match business books to prevent conversion value skew.

gov-8Enhanced Measurement settings tailoredLOW

Verify scroll tracking, outbound clicks, site search, and file download triggers are active.

gov-9Custom Dimensions registered within 50-parameter quotaHIGH

All event parameters mapped in Custom Definitions to become visible in standard reports.

gov-10User-ID feature enabled for authenticated cross-device journeysMEDIUM

Deterministic hashed CRM IDs passed in user_id field for logged-in accounts.

gov-11Data-driven attribution model selected as defaultMEDIUM

Attribution Settings set to Data-driven with conversion credit distributed across channels.

gov-12Attribution lookback windows reviewed (30d / 90d)LOW

Acquisition conversion events set to 30 days; all other conversion events set to 90 days.

gov-13Measurement Protocol API Secret generated and securedHIGH

Active secret token created for offline CRM and server-side conversion imports.

gov-14User-provided data collection enabled for Enhanced ConversionsCRITICAL

Google Ads Enhanced Conversions enabled in GA4 Admin for first-party data matching.

gov-15Data collection acknowledgment and terms signedLOW

Ensure legal data sharing terms are formally acknowledged in property settings.

2. Data Layer & Event Architecture (15 Checks)

Weight: 25%

dataLayer timing, snake_case standards, and ecommerce event sequence.

dl-1dataLayer array initialised before GTM container snippetCRITICAL

window.dataLayer = window.dataLayer || [] declared in head before gtm.js loads.

dl-2Snake_case naming convention strictly enforcedMEDIUM

All event names and parameters use lowercase snake_case (no camelCase, kebab-case, or spaces).

dl-3Single-page app (SPA) page_view events deduplicatedHIGH

Virtual route changes do not fire native and manual page_views simultaneously.

dl-4Ecommerce items[] array structure conforms to schemaCRITICAL

Items array contains item_id, item_name, price, quantity, and item_category.

dl-5view_item_list and select_item tracking activeMEDIUM

Collection and catalog views pass item list name and product index positions.

dl-6view_item event firing with full SKU parametersHIGH

Product detail pages fire view_item with accurate item value and item_category hierarchy.

dl-7add_to_cart and remove_from_cart events trackedHIGH

Cart additions capture product quantity, price, and currency.

dl-8view_cart event tracking cart review intentMEDIUM

Cart drawer or page views fire view_cart with items array and cart total value.

dl-9begin_checkout event tracking initiationCRITICAL

Checkout start passes items array, value, and any applied coupon code.

dl-10add_shipping_info and add_payment_info events mappedMEDIUM

Fires when shipping tier and payment method are selected in checkout.

dl-11purchase event deduplication and transaction_id uniquenessCRITICAL

Purchase event passes unique transaction_id, value, tax, shipping, and currency.

dl-12refund and partial_refund events configuredMEDIUM

Returns and order cancellations pass transaction_id and refunded item values.

dl-13Lead generation form submission events trackedHIGH

Lead forms push generate_lead with form_id and lead_type parameters.

dl-14Numeric parameters cast to integers or floatsHIGH

Price, value, and quantity parameters passed as numbers, not string literals.

dl-15Zero PII (email, phone, plaintext names) in URL strings or dataLayerCRITICAL

Ensure query strings and dataLayer events contain no unhashed personal information.

3. Server-Side Tagging & Deduplication (15 Checks)

Weight: 25%

Server GTM container setup, Meta CAPI, event_id deduplication, and cookie preservers.

ss-1sGTM running on dedicated first-party subdomainCRITICAL

Server container routed via sgtm.yourdomain.com with first-party SSL.

ss-2GA4 Client Tag routing incoming /g/collect hitsCRITICAL

GA4 Client Tag in sGTM parses incoming browser hits and claims requests.

ss-3Meta CAPI server tag configured with System User tokenCRITICAL

Meta Conversions API tag active and authenticated via permanent access token.

ss-4event_id unique identifier shared across browser and server hitsCRITICAL

Deterministic event_id generated client-side and matched in Meta CAPI server tag.

ss-5Meta CAPI deduplication rate verified at 99%+HIGH

Meta Events Manager confirms near 100% deduplication between Pixel and Server events.

ss-6Google Ads Server-Side Conversion tag configuredHIGH

Conversions routed via sGTM with user_data Enhanced Conversions matching.

ss-7First-party cookies set with HttpOnly and Secure flagsHIGH

FPID and _ga cookie lifetime extended via sGTM Set-Cookie server response headers.

ss-8ITP cookie lifetime preserver configured (730-day cap)HIGH

First-party server context protects client IDs from Safari 7-day ITP deletion.

ss-9Request headers sanitized before upstream forwardingMEDIUM

sGTM transformation removes client IP and sensitive headers where required.

ss-10sGTM autoscaling configured (minimum 3 instances in Cloud Run)HIGH

Ensures zero dropped tracking hits during peak conversion spikes and traffic surges.

ss-11Health check endpoint /healthy monitoredMEDIUM

Uptime monitor pings sGTM health URL to alert on container cold-starts or downtime.

ss-12Test Event Code supported for staging validationLOW

testEventCode parameter injected when testing Meta CAPI in staging.

ss-13Advanced Measurement Protocol transport URL override activeCRITICAL

Client-side gtag config sets transport_url pointing to sGTM server domain.

ss-14Edge CDN caching & compression enabled for tagging assetsMEDIUM

Cloudflare / CloudFront caches gtm.js and analytics.js proxies for sub-50ms loads.

ss-15Client IP and User Agent forwarded accurately in CAPI payloadsHIGH

Server tag extracts x-forwarded-for and user-agent for EMQ parameter matching.

4. Consent Mode v2 & DMA Compliance (10 Checks)

Weight: 15%

Consent defaults, 4-parameter v2 signals, CMP integration, and cookieless pings.

con-1Consent default state executed before GTM container loadsCRITICAL

gtag("consent", "default", {...}) fires in head before gtm.js initializes.

con-2All 4 Consent Mode v2 parameters declaredCRITICAL

ad_storage, analytics_storage, ad_user_data, and ad_personalization all initialized.

con-3Default state set to denied for EEA and UK trafficCRITICAL

Default denied signals enforced for European Economic Area visitors under DMA.

con-4CMP fires gtag consent update upon user choiceCRITICAL

Consent banner acceptance/rejection triggers consent update push immediately.

con-5gcd parameter verified in Tag Assistant network hitsHIGH

Outgoing hits contain 10-char gcd string (e.g. 13r3r3r3r5 or 13t3t3t3t5).

con-6Legacy gcs parameter upgraded to Consent Mode v2MEDIUM

Verify absence of legacy G100/G111 without companion gcd v2 parameters.

con-7Advanced Consent settings applied to non-Google tags in GTMHIGH

Meta, TikTok, and LinkedIn tags configured to require explicit ad_storage consent.

con-8Cookieless pings transmitting when consent is deniedMEDIUM

GA4 receives anonymous pings without reading or setting client cookies.

con-9Google Ads Conversion Modeling enabled in linked accountMEDIUM

Conversion modeling calibrates unconsented traffic pings against consented benchmarks.

con-10Annual CMP cookie scan and policy audit scheduledLOW

Automated monthly cookie categorization scanner active to catch newly added scripts.

5. BigQuery Export & Thresholding (10 Checks)

Weight: 15%

Raw event streaming, partitioning, unnesting SQL marts, and access control.

bq-1GCP Project linked with daily and streaming exportCRITICAL

GA4 Admin > Product Links > BigQuery Links configured with active GCP billing.

bq-2Partition expiration and clustering configured on events_* tablesHIGH

Partitioned by _TABLE_SUFFIX date and clustered by event_name and user_pseudo_id.

bq-3Reporting Identity set to Device-based or BlendedHIGH

Eliminates Google Signals thresholding in standard GA4 exploration reports.

bq-4Raw unnested event parameters dimensional mart createdHIGH

Scheduled query creates flattened table of custom dimensions for BI dashboards.

bq-5ga_session_id and user_pseudo_id unnested for session length calculationsMEDIUM

SQL unnesting calculates true multi-touch session durations and bounce rates.

bq-6E-commerce items record unnested into flattened order linesHIGH

SQL unnesting converts items nested array into item-level revenue records.

bq-7Service account granted least-privilege BigQuery rolesMEDIUM

Analytics service account granted BigQuery Data Viewer and Job User roles only.

bq-8GCP budget alerts configured for BigQuery query scansMEDIUM

Cost alert thresholds set up in Google Cloud Billing to prevent run-away queries.

bq-9Data retention policy configured for historical complianceLOW

Table expiration set according to enterprise data retention and GDPR policy.

bq-10Intraday streaming events_intraday_* tables monitored for pipeline lagLOW

Real-time streaming tables verified with sub-10 minute ingestion latency.

Export & Deployment Actions1-click clipboard transfer, shareable URL hash, and local file downloads.

Built by Gordon Geraghty, Head of Performance MediaLocalStorage Persistence & Zero Server Calls
03 Deployment & Export

Execute Audit Findings & Remediation Plan

Complete the 65-point stateful audit checklist above, export your categorized action plan to Markdown or CSV, and apply the governance rules directly to your GA4 property.

Client-Side DataLayer QA Hookga4-data-layer-validator.jsjavascript

Inject into development consoles to validate event naming conventions and required e-commerce parameters.

// GA4 DataLayer Governance Assertion Hook
(function auditDataLayer() {
  const events = window.dataLayer.filter(item => item.event && !item.event.startsWith('gtm.'));
  console.group('🔍 GA4 DataLayer Governance Audit');
  events.forEach(e => {
    const isSnakeCase = /^[a-z0-9_]+$/.test(e.event);
    console.assert(isSnakeCase, '❌ Non-snake_case event detected:', e.event);
    if (e.event === 'purchase') {
      console.assert(e.ecommerce?.transaction_id, '❌ Purchase missing transaction_id:', e);
      console.assert(typeof e.ecommerce?.value === 'number', '❌ Purchase value must be numeric:', e);
    }
  });
  console.groupEnd();
})();

Why Data Layer Governance Determines Measurement Integrity

Analytics leads spend dozens of hours diagnosing broken conversions, thresholded custom dimensions, and misconfigured data streams. This audit framework standardises the QA process across property settings, data layer initialisation, parameter casing, and consent timing.

Prerequisites & Implementation Guidance

Before running this 65-point audit, ensure your team has linked Google Analytics 4 with BigQuery to preserve raw event streaming. Standard UI sampling limits can hide parameter loss during high-traffic sales events.

Recommended Audit Cadence

Run this verification monthly for high-volume accounts and immediately after any website release, checkout update, or Consent Mode version change.

Common Failure Points

  1. Unintended Referral Attribution: Payment gateways such as PayPal, Stripe, and Afterpay appearing as organic referrers due to missing unwanted referral configuration.
  2. Duplicate Transaction Events: Purchase triggers firing on both order confirmation page render and subsequent user browser refreshes without transaction ID deduplication.
  3. Parameter Truncation: Custom event parameters exceeding the standard 100-character limit, resulting in silent data drops in standard exploration reports.

Related Resources

Changelog

  • 1.0.0 (2026-08-01T08:00:00+10:00): Initial publication with 65 audit checkpoints across 7 governance pillars.
04 QA & Verification Guide

GA4 Property Health & Thresholding QA

Verify that data thresholds, thresholding asterisks, session timeouts, and cross-domain tracking match enterprise specifications.

Pre-Production Verification Checklist

✓
Data Retention Set to 14 Months

Ensure Admin > Data Settings > Data Retention is set to 14 months rather than default 2 months.

✓
Google Signals Thresholding Evaluated

Switch Reporting Identity to "Device-based" if cardinality thresholding masks granular landing page metrics.

✓
Internal IP Filters Active in Production

Verify internal developer/office IP ranges are set to "Active" rather than "Testing" state.

✓
BigQuery Export Streaming Status

Confirm daily export and intraday streaming datasets show zero billing export errors in GCP Cloud Logging.

Terminal Diagnostic & Debug Commands

Inspect DataLayer in Chrome Consolejavascript

Dumps all purchase transactions pushed to dataLayer on current page session.

window.dataLayer.filter(i => i.event === "purchase")

Failure Remediation & Troubleshooting

Issue: Thresholding Applied Warning in Standard Reports

Cause: Google Signals is enabled with low volume per dimension, triggering automated privacy masking.

Fix: Go to Admin > Reporting Identity > Show all > Select "Device-based" identity to unmask dimension rows.

Issue: (not set) Session Source/Medium in E-Commerce

Cause: Payment gateway redirect broke cross-domain linker or stripped _ga cookie on return callback.

Fix: Add payment gateway domain (e.g. pay.stripe.com) to "List Unwanted Referrals" in GA4 Web Stream settings.

How to cite and attribute this tool

CC BY 4.0 Licence

This resource is free, open and un-gated under the Creative Commons Attribution 4.0 (CC BY 4.0). You are encouraged to use, integrate and cite it with attribution:

Geraghty, G. (2026). GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit). Gordon Geraghty Resources Hub. https://gordongeraghty.com/resources/gtm-analytics/ga4-audit-checklist
BibTeX Format
@misc{geraghty_ga4_audit_checklist,
  author = {Geraghty, Gordon},
  title = {GA4 & Server-Side Tagging Health Check Suite (65-Point QA Audit)},
  year = {2026},
  url = {https://gordongeraghty.com/resources/gtm-analytics/ga4-audit-checklist},
  note = {Head of Performance Media, Empire Amplify}
}

Changelog & Version History

  • v1.0.0Initial publication with 65 audit checkpoints across 7 governance pillars.