When we tell business owners their site needs a CIPA audit, the most common response is some version of: “What does that even mean?”
It’s a fair question. “Website audit” sounds technical and vague, and most people don’t know what to expect. So, here’s exactly what we look at, what we test, and what you walk away with.
Step 1: We Build a Complete Tag Inventory
The first thing we do is identify every third-party script and tracking tool currently running on your site. This is often the most eye-opening part of the process.
We’re looking for:
- Analytics platforms like Google Analytics and Microsoft Clarity
- Advertising pixels including Meta, LinkedIn, TikTok, and Google Ads
- Chat widgets and chatbot tools
- Session replay and heatmap software
- CRM and email marketing integrations
- Any scripts from vendors you may no longer work with
Most businesses are surprised by how many tools show up. Scripts get added over time by developers, agencies, and plugins, and very few ever get removed.
Step 2: We Test When Scripts Fire
Finding the scripts is only half the picture. The more important question is when they fire.
Under CIPA, tracking that happens before a visitor provides consent is where the exposure lives. We test each script to determine:
- Whether it loads on page open before any banner interaction
- Whether a visitor clicking “Decline” stops the tracking
- Whether your consent banner is blocking scripts or just displaying a notice while they keep running
- Whether Global Privacy Control signals from a visitor’s browser are being honored
This step frequently reveals that a site’s cookie banner looks functional but isn’t doing what it promises. The banner exists, visitors see it, but the scripts behind it never stop.
Step 3: We Review Your Policies and Disclosures
Technical compliance and legal documentation have to be matched. We review:
- Your privacy policy to confirm it accurately describes how data is collected and shared
- Your cookie policy to verify it reflects the tools running on your site
- Whether required disclosures are visible and accessible to visitors
Outdated or incomplete policies can compound legal exposure even when the technical setup is otherwise solid.
Step 4: You Get a Clear Action Plan
At the end of the audit, you don’t get a list of jargon. You get a straightforward breakdown of what we found, what the risk level is, and exactly what needs to change.
For most businesses, the fixes are specific and manageable:
- Remove outdated or unnecessary tracking scripts
- Reconfigure existing tags to wait for consent before firing
- Update consent banner settings so opt-out signals propagate
- Revise policy language to match current practices
We tell you what to prioritize and why, so you’re not guessing where to start.
How Social Spice Media Can Help
Our CIPA website audits are designed to give business owners a clear picture of where they stand and a practical path to fixing it. No technical background required on your end. We handle the analysis and walk you through what we find in plain language.
Reach out to the Social Spice Media team to schedule your audit.















