Skip to content

How to audit a client website: a repeatable process

A client website audit is only useful if it changes what the client does next. Here is a repeatable process you can run on any new or existing client site, from scoping the work to a plan they will actually approve.

Scope the audit around what the client actually cares about

Before opening a single tool, ask the client what success looks like: more leads, more sales, higher rankings for specific terms, or fewer support tickets. That answer shapes the whole audit. A lead-generation consultancy needs its contact forms and page speed checked first; an ecommerce store needs its checkout flow and product page SEO scrutinised first. Skip this conversation and you hand over a generic report the client skims once and forgets. Also ask about current traffic sources, their main competitor, and anything that changed recently - a redesign, a migration, a traffic drop they noticed after a Google update. Write the answers down. You will use them in step three to decide what actually matters.

Check every area, not just the one you specialise in

Most agencies are strong in one or two areas - usually SEO or design - and quietly skip the rest. A proper client audit covers technical health and page speed, on-page and content SEO, security (SSL, headers, exposed admin paths, outdated software), privacy and compliance (cookie consent, a working privacy policy, data collection disclosure), accessibility, how the site is showing up in AI answers and assistants, and the client's reputation and social presence beyond the site itself. A site can rank well and still be leaking customer data through an unsecured form, or losing trust through unanswered reviews. Miss one area and you either miss the client's real problem or a future client conversation catches you out.

Prioritise findings by business impact, not just severity

A generic scoring tool will flag a missing meta description as high and a broken checkout button as medium because it is scoring technical severity, not business consequence. Re-rank every finding against the goals you captured in step one. If the client's goal is sales, a broken payment step or a slow product page outranks a title tag issue every time. If the goal is lead volume, a contact form that silently fails outranks a minor accessibility label. Group findings into three tiers - fix now, fix this quarter, monitor - rather than a flat severity list. This is the difference between a report the client acts on and one that gets filed.

Present findings so the client acts, not just nods

Avoid jargon entirely - "your contact form silently fails on mobile, which means you're losing enquiries" lands better than "form validation error on viewport breakpoint". Back every claim with evidence: a screenshot, a before/after, or the actual page it happened on. Structure the deliverable as a 30/60/90 day plan - what gets fixed this week, what needs a sprint, what's a longer-term project - rather than a flat list of forty issues. Walk the client through it live if you can; a report that's only ever emailed gets skimmed, not actioned. End every finding with the fix, not just the problem.

Doing this by hand, every time, does not scale

Manually checking nine areas across technical, content, security, privacy, accessibility, AI visibility and reputation takes hours per site, and the result depends on who ran it and how thorough they were that day. Two analysts auditing the same site by hand will surface different findings. That inconsistency is fine for a single one-off audit; it becomes a real problem once you're running this process across ten or fifty client sites a month, or trying to prove a consistent standard to a client who compares you to a competitor's report. The fix isn't working faster by hand - it's starting from the same automated baseline every time and spending your actual time on the parts a tool cannot do: interpretation and the client relationship.

Start every audit from the same automated baseline

Run AuditHQ's free scan on the client's site before you open any manual tool. In about 60 seconds it samples across all nine suites - technical, marketing and SEO, security, privacy, social, reputation, employer brand, AI readiness and AI visibility - so you walk into the client conversation with a consistent, evidenced baseline instead of a blank page. For a deeper engagement, the full report gives you findings across every suite to prioritise using the process above, and agencies can pull results into a white-label client report under their own brand. Use the free scan first; spend your billable time on the judgement calls a scan can't make.

Frequently asked questions

How long should a client website audit take?

A baseline scan across technical, SEO, security, privacy, accessibility and reputation signals takes about 60 seconds when you start with an automated tool. Turning that into a client-ready report with prioritised findings and a 30/60/90 plan typically takes an hour or two of interpretation, depending on how many issues need writing up in plain language. Doing the same coverage entirely by hand across every area usually takes half a day or more per site.

What should I include in a client website audit report?

Cover technical performance, on-page SEO, security, privacy and compliance, accessibility, AI visibility, and reputation and social presence, but lead with the two or three findings that map directly to the client's stated goal, not a flat list of every issue found. Include evidence for each finding - a screenshot or the specific page - and close with a 30/60/90 day action plan so the client knows what happens next.

How often should I re-audit an existing client's site?

Quarterly is a reasonable default for an active client, with a fresh audit after any major change - a redesign, a migration, a new product launch, or a noticeable drop in traffic or rankings. Running the same baseline scan each time makes it easy to show the client measurable progress against the previous audit, rather than starting the conversation from scratch.