One of the most requested services we’re seeing right now is the cookie audit. Why? Between CIPA litigation, enforcement actions, and more privacy laws, companies are finally paying attention to what’s happening to those digital trackers and cookies on their sites.
We find it’s the same story we run into with clients constantly. A company sets up a cookie banner. They configure a consent tool. They feel good about it and move on to the next fire. And then, sometimes a year later, sometimes three years later, they finally have someone dive deeper and realize it’s not all functioning the way it should.
This isn’t a story about companies cutting corners. Most of the businesses we work with genuinely believe they’re compliant. They bought and configured the tool and feel like they did what was supposed to happen. Since then though, it has not been reviewed or tested.
The gap doesn’t come from carelessness. It comes from complexity, and from how quietly these things can drift once nobody’s watching.

Where it actually goes wrong
Picture a retailer selling products across three branded websites, plus a loyalty program on top of that. Marketing runs a shared tag management platform across two agency partners, and each site has its own cookie banner. That’s the kind of setup a lot of teams point to as proof they’ve handled cookies. A banner is up. A tool is running. Box checked, moving on.
Then a cookie audit finds this instead: cookies sitting in an “uncategorized” bucket, with some of them dropping before the visitor ever makes a consent choice. Global Privacy Control is working correctly on two of the three sites, but not the third, because nobody had checked whether the configuration carried over. And a “Do Not Sell or Share” link in the footer that works fine on desktop yet quietly 404s on mobile.
None of these are the kind of problems anyone would catch by glancing at the homepage. They’re the kind of problems that only show up when someone goes looking specifically for them, site by site, page by page, device by device.

The six places we consistently find the gap
After enough of these audits, we see the same handful of failure points keep showing up, almost regardless of industry. Here’s where to look first.
Cookies miscategorized as strictly necessary. This is one of the most common findings in our audits. Advertising and analytics cookies quietly get filed under “strictly necessary,” which means they fire before anyone has a chance to say yes or no. 🍪 Fix: Pull the actual cookie inventory from a scan, not from what the original setup notes say, and recheck every category against what the cookie is really doing. This might go all the way back to checking the contract too.
No clarity on which jurisdictions actually apply. We regularly find teams that build one cookie experience and assume it covers everyone, without mapping where visitors are actually coming from. ⚖ Fix: Map your audience geography against the laws that apply to each region first, then build or verify a consent experience for each one. What’s a non-issue for a US-only visitor can be a real violation for someone arriving from the EU.
“Do Not Sell or Share” and privacy rights links that don’t work. This is a near-constant finding in our audits. These links get built once, tested once, and never touched again. ⚙ Fix: Test them on desktop and mobile, on every site, on a recurring schedule, not just at launch.
Dark patterns in the consent experience. Pre-checked boxes, “accept all” buttons that are bigger and bolder attracting attention to pick that one, confusing wording that nudges people toward saying yes. We flag at least one of these items almost every time we review a consent flow. 💡 Fix: Have someone unfamiliar with the site try to opt out cold. If they struggle, so will your visitors and so will a regulator reviewing it.
No functioning universal opt-out. We often find that Global Privacy Control gets implemented on the main site and never verified across every other property. 🛠 Fix: Confirm GPC actually works site-by-site, not just once at rollout, since one working example doesn’t mean the rest are covered. Sometimes website updates can impact these settings.
Privacy notices that don’t match reality. We often see the effective date updated to the current year, but the notice describes a cookie program that may have existed a year ago, not the one actually running today. 📃 Fix: Treat the privacy notice as a living document tied to your audit cadence, not a one-time write-up.
No written record of what was actually configured. This one is becoming a more common issue we see daily, as some of these consent managers were set up years ago by someone else. The entire consent setup was never written down, so companies almost have to start over. ✍ Fix: Keep a short written record of the configuration, including jurisdictions, consent setup, categories, GPC status, who owns it, and when it was last reviewed. It’s also important to update it whenever something changes, not just at initial setup.

Why the gaps hide where they hide
The first place a cookie audit usually gets interesting is the web property inventory, before anyone even starts scanning for cookies. Teams we engage with generally have a good handle on the main domain and its subdomains. It’s the landing pages, recruiting sites, and microsites that are easy to miss.
Each of those properties can behave completely differently from the main site, and each one needs its own setup. The gap between “the sites we actively manage” and “the sites that are live and collecting data right now” is almost never zero. Properties fall off the radar while they keep quietly gathering information in the background, exactly like that subscription I forgot about.
There are some digital tracker scanning tools (Privado, ObservePoint, Boltive, Sentinel Insights are a few we see clients use) that monitor for various requirements, like opt-in or opt-out working properly, miscategorized cookies, or GPC not working. Some consent managers have similar capabilities built in, and we’ve seen people use both the third-party scanning tool and the consent software’s built-in check.
However, all these tools are only as good if someone’s assigned to review what they’re reporting AND actually addressing what’s found. A really common miss is ignoring the findings and fixing the issues.
Without any testing tool in place, someone needs to perform the audit manually (and we see plenty of companies doing this too).
What this means for your program
A cookie audit tests whether the pieces of your program actually talk to each other the way you assume they do, using the seven checks above as your starting point rather than your finish line.
Agency partners often have direct access to shared tag management platforms, and they can add new tags to hit a campaign deadline without necessarily routing it through a formal approval process. You, the company, are responsible for every cookie on the site. Which means you have to have the right processes in place to catch everything and know what’s happening.
A cookie audit should be part of each new webpage rollout, part of each new digital tracker placement, be a part of the agency monthly review process, and overall considered part of website maintenance.
Save this handy process reminder to start planning your cookie audit.

Building a repeatable audit process, even a lightweight one you run on a set schedule, is what keeps you from being surprised a year from now by something that’s been sitting there the whole time.
If you’re the one responsible for your company’s cookie program, the honest question worth asking this week is, “When’s the last time someone actually checked whether the consent setup is doing what it should be doing?” If the answer is not sure, it’s probably time to do one asap.
We’ve done enough of these audits to know the finding is rarely “everything’s fine.” It’s usually something like the retailer above: mostly right, with a few quiet gaps nobody had reason to notice until someone went looking.
Want a clearer picture of your company’s cookie universe before someone else finds the gaps for you? Check out our deeper guide on building a repeatable audit process or hit reply and we can talk about how we can help.
Jodi
💡 When you’re ready, here’s how we can help:
⚙ Privacy Advisory & Implementation: We help companies navigate privacy requirements with confidence. Our advisory support covers strategy, operations, and real-world implementation.
⚙ Fractional Privacy Services: We provide fractional privacy leadership tailored to your needs and pace. From program development to day-to-day support, we help you build and sustain a strong privacy program.