Audit Checklist Pre-Launch
Last updated: October 4, 2026
Use this checklist before every production go-live.
1. Banner and UX
Section titled “1. Banner and UX”- EEA/UK flow: Accept and Reject are both visible and equally accessible.
- US flow: required opt-out/privacy controls are visible.
- Non-banner/global informational flow: banner suppression (or informational-only Continue) matches policy.
- Where consent UI is shown, it can be reopened from a persistent link/button.
- First and second layer text matches approved legal copy.
- Keyboard navigation works for all controls.
2. Consent Mode v2
Section titled “2. Consent Mode v2”defaultcommand fires before tag execution.updatecommand fires after user action in banner regions.- A verified no-banner regional policy reaches its intended grant; failed delivery never counts as a no-banner policy.
- All four keys are present:
ad_storage,analytics_storage,ad_user_data,ad_personalization.
3. Direct Web TCF
Section titled “3. Direct Web TCF”__tcfapiis available.- TCF decisions update when relevant choices change; separate Analytics-only changes remain observable even if the TC string is unchanged.
- Verify current Web TCF disclosure requirements and the actual languages presented.
- Vendor and purpose settings match dashboard policy.
4. Technical Quality
Section titled “4. Technical Quality”- CMP script loads once only.
- CSP and allowlist permit CMP domains.
- No console errors during consent flow.
- Caching layer does not serve stale CMP config.
5. Evidence Package
Section titled “5. Evidence Package”- Screenshot of banner first layer and second layer (EEA/UK test session).
- Screenshot/log from non-banner session showing granted defaults.
- Tag Assistant trace.
- Browser console output for consent checks.
- TCF checks and TC string sample.
- Debug export from Cybexo Debug Tool.
6. Sign-Off
Section titled “6. Sign-Off”- Engineering sign-off
- Privacy/legal sign-off
- Release owner sign-off
- Support runbook updated