Key Takeaways
- A professional website audit should connect technical findings to business outcomes, not deliver a long list of automated warnings.
- The core areas are search visibility, performance, user experience, accessibility, content, conversion, security, privacy and measurement.
- Automated tools are useful, but they cannot replace manual testing of real journeys such as submitting a form or buying a product.
- Every finding should include evidence, business impact, priority, recommended action and an owner.
- The final deliverable should be a phased roadmap that helps you decide what to fix now, later or not at all.
A professional website audit is a structured review of how well a website can be found, used, trusted, measured and maintained. For a UK business, it should also consider accessibility, cookies and personal data. The useful output is not a score. It is a prioritised plan tied to enquiries, sales, bookings, recruitment or another real business goal.
A brochure website, online shop and member portal need different checks. The audit scope should therefore begin with the website’s purpose and its most important customer journeys. This guide explains what a thorough audit normally includes and what you should expect to receive.

What Should Happen Before the Audit Starts?
The auditor should ask what the business sells, who the site serves and which actions matter. They should also ask about current concerns, recent redesigns, known technical limitations and planned campaigns. Without that context, even a technically correct finding can be commercially irrelevant.
Agree the scope in writing. It should name the domain and any subdomains, countries, languages, devices, platforms and integrations included. It should also state whether the work covers only diagnosis or includes implementation.
Useful access can include Google Search Console, analytics, tag management, the CMS and relevant advertising platforms. Access should follow the principle of least privilege: provide only what is needed, for the time it is needed. If you want a structured independent review, the website audit and consultation service sets out the current audit options and deliverables.
1. Technical SEO and Indexing
The technical review establishes whether search engines can discover, crawl, understand and index the right pages. It should cover response codes, redirects, canonical tags, robots.txt, XML sitemaps, internal links, duplicate URLs and accidental noindex directives.
The auditor should compare crawl data with Search Console rather than treating either as complete on its own. Google’s Search Console guidance explains how its reports reveal search performance, indexing, security issues and real-world page experience.
Important questions include:
- Are valuable pages indexable and present in the sitemap?
- Are old URLs redirected to relevant replacements without chains?
- Do canonical tags agree with internal links and sitemap URLs?
- Are parameter, filter or search-result pages creating unnecessary duplication?
- Can Google render the important content and links?
- Are structured data claims supported by visible page content?
This section should also identify content overlap. Several pages competing for the same broad query can weaken the site’s structure. Sometimes the right action is to consolidate or improve an existing page, not publish another article.
For a smaller, search-only self-review, use the DIY SEO audit checklist. A professional website audit should go further by testing business journeys and implementation quality as well.
2. Performance and Core Web Vitals
Performance testing should combine laboratory tests with real-user field data where it is available. A fast test from one laptop does not prove that a page works well on a typical mobile connection.
Google’s Core Web Vitals documentation focuses on loading performance, responsiveness and visual stability. The auditor should identify the cause of poor results, not merely repeat a score. Common causes include oversized images, slow server responses, render-blocking scripts, excessive third-party tags, heavy fonts and page elements that move while loading.
Check representative templates rather than only the home page: a service page, article, product, category, contact page and any logged-in area. Recommendations should distinguish quick wins from architectural work. If a slow theme, plugin stack or hosting setup needs hands-on work, website speed optimisation is a clearer next step than repeatedly running another test.
3. User Experience and Customer Journeys
The UX review asks whether a real visitor can understand the offer and complete an important task without unnecessary effort. It should test the site on current mobile and desktop devices and include common interruptions such as a validation error, slow connection or long page title.
Review:
- navigation labels and information structure;
- clarity of the main offer and audience;
- service, product and location page journeys;
- forms, checkout, booking and account flows;
- search, filtering and error recovery;
- readability, spacing and touch target sizes;
- calls to action and reassurance at decision points.
Record the exact journey and evidence for each problem. “The page feels confusing” is not enough. “On a 390-pixel-wide screen, the cookie panel covers the form submit button and cannot be dismissed by keyboard” is testable and fixable.
4. Accessibility
Accessibility cannot be assessed properly with an automated score alone. Automated tools can find missing labels, contrast failures and structural problems, but manual checks are needed for keyboard navigation, focus order, screen-reader meaning, zoom and understandable error messages.
The W3C overview of WCAG groups accessibility under four principles: content should be perceivable, operable, understandable and robust. A professional audit should state which WCAG version and conformance level it uses, which pages and components were sampled, and which methods were manual.
Typical checks include alternative text, headings, form labels, colour contrast, captions, keyboard access, visible focus, meaningful link wording and reflow at increased zoom. The existing guide to website accessibility audits in the UK explains this area in more detail, while the accessibility and WCAG compliance service covers remediation.
5. Content and Trust
Content should answer the questions a prospective customer actually has. Review whether service pages explain who the work is for, what is included, how the process works and what the reader should do next. Look for unsupported claims, obsolete dates, duplicated copy and pages written for keywords rather than people.
Trust checks should include accurate contact details, company information, author or expert context, privacy information, delivery and returns where applicable, and clear terms for regulated or higher-risk services. Case studies should distinguish real evidence from anonymous or invented results.
The audit should also identify useful pages that receive impressions but few clicks. Their title, description and search intent may need attention. Pages with traffic but no enquiries may have a different problem: a weak offer, poor journey or missing reassurance. Our guide to website traffic without enquiries helps separate those issues.
6. Conversion and Lead Handling
A conversion review follows the path from landing page to completed action. It checks whether calls to action match the visitor’s stage, whether forms ask only for useful information and whether the business can actually receive and respond to the lead.
Test every important form with permission. Confirm where the message arrives, whether spam filtering blocks it, what the visitor sees next and whether the conversion is recorded once. For telephone leads, check tap-to-call links on mobile and decide how calls are measured without collecting unnecessary data.
Review friction around pricing, delivery areas, availability and response times. Not every site needs prices, but hiding all commercial context can attract unsuitable enquiries and create avoidable work. Recommendations should suit the business rather than copy a generic “high-converting” template.
7. Analytics and Measurement
An analytics audit checks whether the data can support decisions. It should review property ownership, tag loading, consent behaviour, internal traffic, referral exclusions and the events marked as key conversions.
Compare recorded form completions with actual received enquiries for a sample period. Differences can reveal duplicate events, blocked scripts or forms that appear successful but never arrive. Check that old campaigns, staging domains and payment providers do not distort acquisition reports.
The measurement plan should name each important action, where it is captured and who owns it. Collecting more events is not automatically better; reliable events connected to a business question are more useful.
8. Privacy, Cookies and Security Hygiene
For a UK website, the audit should record cookies, pixels, local storage and similar technologies. The ICO’s cookies and similar technologies checklist covers identifying their purposes, distinguishing essential from non-essential technologies and giving people appropriate control.
An audit is not a substitute for legal advice, but it can flag visible problems such as marketing tags loading before a choice, a cookie list that does not match the site, insecure forms or personal data being sent to unexpected third parties.
Security hygiene should include HTTPS, software and dependency updates, administrative access, exposed debug information, backups and recovery arrangements. A non-invasive website audit should not attempt disruptive penetration testing unless that work is explicitly authorised and scoped.
What Should the Website Audit Report Contain?
Ask for a report that someone can act on. Each finding should include:
- the affected URL, template or component;
- evidence such as a screenshot, request or test result;
- the effect on customers or the business;
- severity and priority, which are not always the same;
- a recommended action;
- estimated effort or dependency;
- a suggested owner.
A useful roadmap normally separates urgent faults, high-value improvements and longer-term ideas. For example, a broken quote form is urgent even if only one page is affected. Rebuilding the whole CMS might have a larger technical impact but belong in a planned later phase.
The report should also say what was not tested. That prevents a sampled audit from being mistaken for a guarantee across every page and integration.
Professional Website Audit Checklist
- Business goals and important customer journeys agreed
- Domain, subdomains, platforms and integrations scoped
- Search Console and analytics data reviewed
- Crawl, indexing, redirects, canonicals and sitemap checked
- Representative templates tested for performance
- Mobile and desktop customer journeys completed manually
- Keyboard, zoom, focus, forms and key accessibility checks completed
- Service content, trust information and calls to action reviewed
- Forms, bookings, checkout and lead delivery tested
- Analytics events and consent behaviour verified
- Cookies and third-party tracking recorded
- Security hygiene, backups and update responsibilities reviewed
- Findings include evidence, impact, action, effort and owner
- Final roadmap prioritised by business value and risk
Frequently Asked Questions
How long does a professional website audit take?
A focused small-business audit may take several working days. A large shop, member platform or multi-language website takes longer because more templates, integrations and journeys need to be sampled. The scope should be agreed before work begins.
Is a free automated website report enough?
No. Automated reports are useful for discovering possible issues, but they cannot judge business context, complete every customer journey or verify whether a recommendation is worth implementing.
Do I need to give the auditor administrator access?
Not always. Start with read-only access to the relevant reports and provide additional access only when the agreed test requires it. Remove temporary access when the audit is complete.
Will a website audit improve rankings by itself?
No. An audit identifies and prioritises work; it does not improve the site until the right recommendations are implemented. Some fixes support search visibility, while others improve accessibility, measurement or conversions.
How often should a business website be audited?
Run focused checks after major changes and review important data regularly. A broader annual audit can be useful, but a site with frequent releases, products or integrations may need a shorter cycle.
Turn the Findings into a Sensible Roadmap
The best audit helps you stop guessing. It shows what is broken, what is merely untidy and which changes could genuinely improve the customer journey. If you need an independent review, you can contact MattDarm or compare the current website audit packages. The first decision is not how much to rebuild; it is what evidence says you should fix.




