What the audit usually covers
- Inventory — names, domains, lifetimes, first vs third party.
- Purpose — analytics, advertising, functional, strictly necessary.
- Legal basis — consent, legitimate interest, or contract as applicable.
- Consent behavior — what loads before Accept vs after Reject.
- Gaps — unknown vendors, stale documentation, tag manager drift.
Why spreadsheets alone fail
Vendor lists go stale the week marketing adds a pixel. A live scan captures what a visitor’s browser receives today — including tags injected through GTM or A/B tools you forgot to document. That is what privacy teams and regulators expect when they ask whether your cookie policy is still true.
Running an audit with CookieComply
- Open the URL in Chrome with the CookieComply extension (no site-wide script required).
- Capture cookies before and after consent choices when you need the pre-consent state.
- Review AI-assisted classifications and risk notes, then share a report with legal or clients.
- Re-run after banner, CMP, or tag changes to show improvement.
Audit vs. CMP
A consent management platform collects and stores visitor choices on live traffic. CookieComply is the verification layer: it tells you whether those choices are reflected in what actually loads. Most teams that take this seriously use both — CMP for visitors, periodic audits to check the page still matches the banner.