Methodology · ungated · no email required
The 60-point GTM systems audit checklist.
This is the checklist we actually run, published in full. Most audit checklists cover one platform. This one covers four layers, because the failures that cost the most money do not happen inside a system — they happen at the joins between them.
Take it and run it yourself. If you would rather not spend three weeks on it, that is what the paid audit is for.
A RevOps audit checks the CRM. A marketing-ops audit checks the automation platform. The connector and the reporting layer sit between two owners and belong to neither, which is exactly why they rot.
Mark each check pass, fail or unknown. Unknown counts as fail. If nobody can answer it today, it is not a control — it is an assumption.
Not "data quality is poor". A finding names the object, the count, the query that produced it and what it costs. Anything less is an opinion.
The automation platform
HubSpot, Marketo, Pardot, Eloqua, Braze · 15 checks
- Asset sprawlCount active vs total programs, workflows and lists. A platform where 70% of assets have not run in a year is a platform nobody can reason about.
- Orphaned automationWorkflows with no enrolment in 90 days, and workflows still enrolling into campaigns that ended. Both are live and both are lying.
- Enrolment overlapRecords sitting in two workflows that write the same field. Whichever runs last wins, and it is not the same one every time.
- Smart list driftFilters referencing fields that no longer populate, values that were renamed, or integrations that were switched off.
- Suppression integrityGlobal suppression actually applied everywhere, including one-off sends and any API-triggered mail.
- Consent and subscription stateOpt-out honoured across every asset type, and the subscription model matching what the preference centre promises.
- Scoring model provenanceWho set the thresholds, when, and against what. A score nobody can justify is a score sales will not act on.
- Score decayWhether points expire. Without decay, every record eventually qualifies and the model stops discriminating.
- Form field mappingEvery form field landing in a mapped, readable property — and not a free-text field nobody queries.
- Progressive profilingWhether repeat submitters are asked new questions or asked the same ones forever.
- Template and domain healthSending domains authenticated, link tracking on the right domain, and templates rendering in the clients your ICP actually uses.
- Deliverability signalsHard-bounce handling, complaint rate, and whether the platform is quietly suppressing what you think it is sending.
- Naming conventionsWhether a convention exists and whether it is followed. Partial adherence is worse than none, because reporting silently half-works.
- Sandbox and change controlWhether anything is tested before it touches production, and whether changes leave a record.
- Permission modelWho can edit a live workflow. In most inherited instances the answer is everyone.
The CRM
Salesforce, HubSpot CRM, Dynamics 365 · 15 checks
- Object model fitWhether leads, contacts, accounts and opportunities are used as designed or bent into shapes the reporting cannot follow.
- Duplicate rateMeasured, by object, with the matching rule stated. "We have some duplicates" is not a finding; 14% of contacts is.
- Merge historyWhat merges destroyed. Most CRMs lose the non-surviving record silently, taking its activity with it.
- Required-field realityFields marked required at the UI but routinely empty via API or import.
- Picklist entropyFree-text creeping into picklists, and picklist values that differ between the CRM and the automation platform.
- Ownership rulesWho owns a record at each stage, what happens on reassignment, and whether the rule survives a reorg.
- Routing logicAssignment rules traced end to end, including the fallback nobody remembers writing.
- Speed to leadMeasured from creation to first touch, at the percentile rather than the average. The average hides the tail.
- Stage definitionsWritten down, agreed, and enforced by validation rather than by hope.
- Stage regressionRecords moving backwards through lifecycle, which corrupts every funnel conversion number downstream.
- Opportunity hygieneClose dates in the past, amounts of zero, and opportunities with no contact roles attached.
- Contact rolesWhether buying-group members are attached to opportunities at all. Without this, attribution has nothing to attach to.
- Data decayRecords with no activity in 24 months, and what proportion of the database that represents.
- Validation coverageWhich of the above is enforced by a rule and which relies on training.
- Audit trailWhether field history is switched on for the fields that matter, and how far back it retains.
The connector between them
The seam nobody owns · 15 checks
- Sync direction per fieldDocumented, field by field. Most instances have at least one field syncing both ways and fighting itself.
- Conflict resolutionWhich system wins on a collision, and whether that answer is the same for every field.
- Sync errorsThe error queue, read. In most inherited instances nobody has opened it in months.
- Silent dropsRecords that fail validation on arrival and are discarded without an error anyone sees.
- Sync latencyActual time from create to appear, measured. Not the vendor documentation figure.
- Selective sync rulesWhat is deliberately excluded, and whether the exclusion still matches the business reason for it.
- Custom vs native integrationWhether the connector is the vendor one, an iPaaS, or bespoke code. Bespoke and undocumented is the common case.
- Integration user permissionsWhat the sync user can see and write. Over-scoped is a security finding; under-scoped is a data finding.
- API consumptionHeadroom against the daily limit, and what happens at the ceiling. Usually: silence.
- Retry and backoffWhether failures retry, and whether a retry storm can duplicate records.
- Deduplication at the boundaryWhich system dedupes, on what key, and what happens when the key is missing.
- Field length and type mismatchesTruncation on the way across. Long values silently clipped is a classic.
- Timezone and date handlingDates shifting by a day across the boundary, which quietly breaks cohort reporting.
- Deletion propagationWhat happens on delete in one system. Often nothing, leaving orphans on the other side.
- ReconciliationWhether anyone compares counts on both sides on a schedule. This is the single most common absent control.
The reporting on top
Attribution, dashboards, the numbers people argue about · 15 checks
- Source of truthWhich system the reported number comes from, per metric, written down.
- Definition driftWhether "MQL" means the same thing in the dashboard, the board deck and the CRM report.
- Campaign influenceWhether campaigns actually attach to opportunities, and what proportion of closed revenue has any campaign attached at all.
- Attribution modelWhich model, applied where, and whether anyone can explain it without opening a vendor help page.
- UTM taxonomyA convention, enforced at the point of link creation rather than cleaned up afterwards.
- Channel cost joinWhether spend data joins to the campaign record. Without this, ROAS is an estimate wearing a suit.
- Self-reported attributionWhether the "how did you hear about us" field is captured, and whether anyone reconciles it against the tracked source.
- Finance reconciliationMarketing-reported revenue against what finance closed, with the variance explained rather than ignored.
- Dashboard provenanceWho built each dashboard, when, and whether its filters still reference live fields.
- Spreadsheet dependenciesReports that only exist because somebody rebuilds them manually each month.
- Funnel conversion integrityWhether stage-to-stage rates are computed on cohorts or on snapshots. Snapshots flatter.
- Historical continuityWhether the numbers survive a platform migration, a field rename or a stage change.
- Access and distributionWho sees which number, and whether sales and marketing are looking at the same report.
- Refresh and stalenessWhen each dashboard last updated, and whether anyone would notice if it stopped.
- The question testPick the three questions leadership asks most. Time how long it takes to answer each from the system as it stands.
60 checks. Three weeks. Or run it yourself.
The checklist is the easy half. The hard half is the evidence — every finding tied to a query and a record count your own team can re-run, and the findings ordered by what they cost rather than by what is easiest to fix. That is the audit, and every engagement starts there.
From USD $1,500, credited in full against the work that follows.