Website Compliance Audit FAQ

Straight answers about cookie banners, consent, what a compliance risk audit actually reviews, what you receive at the end, and what it costs. If your question is not answered here, ask us directly.

Human-led. Evidence-based. Clear fixed pricing.

Written for UK business owners, directors, website managers and marketing teams responsible for a public-facing website.

Ask Us Your Questions

Common Questions About Website Compliance Risk Audits

What happens if a UK website isn't compliant with PECR or UK GDPR?

The ICO can take enforcement action ranging from advisory letters to formal notices and monetary penalties, and it has publicly signalled continued focus on cookie compliance on major UK websites. Beyond the regulator, non-compliance creates commercial risk: complaints from visitors, awkward questions in procurement and due diligence, and loss of trust. An audit does not make a website compliant by itself, but it shows you, with evidence, where the visible risk is sitting so you can prioritise fixes before anyone else finds them.

How is Stalytics different from a free automated cookie scanner?

Automated scanners are useful for a quick signal, but they misread consent behaviour, miss context, and produce scores nobody stands behind. Stalytics is human-led: a person reviews each page in the browser, records what actually happens across consent states, and captures the evidence by hand. You get considered observations backed by screenshots, written for decision-makers, with a clear scope and a fixed price. This provides you with information you can act on rather than a number you have to interpret.

Other providers scan a thousand pages. Why does Stalytics review five?

Because most websites are built from a handful of templates, and risk lives in the template, not the page count. A machine can list cookies on a thousand URLs, but it cannot judge consent behaviour, spot a policy that contradicts what the site actually does, or stand behind a finding. We hand-review your highest-risk pages, typically the templates the rest of your site is built from, and every observation ships with evidence you can check. Depth you can act on beats breadth you have to interpret. If your estate genuinely needs wider coverage, that is what the Enterprise tier is for.

What is a website compliance risk audit?

It is a structured review of what your public website actually does in a visitor's browser: the cookies it sets, the trackers and scripts it loads, how its consent banner behaves, and what it stores. The aim is to show you where compliance risk may be sitting so you can decide what to do next. Stalytics provides this as information for business decision-making; it is not legal advice.

What does a cookie compliance check actually look at?

We review observable, browser-side behaviour: cookies and trackers, the cookie and consent banner and its preference controls, local storage, session storage and IndexedDB, front-end scripts and network requests, and whether your privacy and cookie policy links are present and reachable. Findings describe what we observed at the time of review, not a legal ruling. The depth of review depends on the tier: the Basic Snapshot covers the visible indicators, while the Standard Audit adds network, script and consent-behaviour analysis.

Is the audit automated or human-led?

It is human-led. A person reviews each page in the browser, records what they observe, and captures supporting evidence by hand. That is the core difference from an automated scanner: you get considered, evidence-backed findings rather than an auto-generated score.

Do you need access to my website, CMS or servers?

No. The Basic and Standard reviews look only at public-facing pages. We do not need developer access, CMS logins, server access, or any passwords. You simply confirm the public URLs you would like reviewed.

How much does it cost and how long does it take?

The Basic Snapshot is £395 + VAT, typically delivered in 3 to 5 business days from payment and confirmation of your URLs. The Standard Audit is £2,995 + VAT, delivered in up to 15 business days from the deposit and your URLs, split into a 50% deposit to begin and a 50% balance before the final report is released. Enterprise work is scoped and quoted individually.

What is the difference between the Basic Snapshot and the Standard Audit?

The Basic Snapshot is a fast, tightly scoped screen of up to three pages that flags visible warning signs and gives you a concise executive report. The Standard Audit is a full, evidence-led review of up to five pages, with up to three chosen for deeper review, producing structured findings, a supporting evidence pack and a remediation action plan. In short, Basic indicates whether there is likely a problem; Standard shows you the detail and what to do about it.

What do I actually receive?

A branded PDF report. The Basic Snapshot includes an executive summary, concise visible-risk observations and limited supporting screenshots. The Standard Audit includes structured findings, a supporting evidence pack, and a remediation action plan with indicative budgetary guidance where appropriate.

Do you fix the issues you find?

The audit identifies and explains risk; it does not include remediation or implementation work. Where you want the issues fixed, that is handled separately, either by your own team using our report or as an enquiry to a separately scoped project by Stalytics.

Which businesses is this for?

UK businesses that want a clearer view of visible website compliance risk: owners, directors, website managers and marketing teams responsible for a public site. It is a business-to-business service. Larger or more complex environments, such as multiple domains, logged-in areas or e-commerce checkout flows, are handled through Enterprise scoping.

Ready to see where your website's compliance risk is sitting?

View Our Service Tiers