# Cookie audit report

This is an editable template, not a completed audit or legal certificate. Replace bracketed fields with reviewed evidence. Remove unused sections.

## Engagement and scope

- Client: [client name]
- Prepared by: [reviewer]
- Test date and timezone: [date and timezone]
- Application build: [version]
- CMP / tag-manager configuration: [versions or unknown]
- Browser / device / viewport: [environment]
- Region and third-party cookie settings: [environment]
- Authentication state: [logged out or test account]
- URLs and journeys tested: [explicit list]
- Excluded pages and flows: [explicit list]
- Observation window and interactions: [duration and actions]

## Executive summary

[State the main observations, practical impact and recommended next action. Distinguish observed behavior from unconfirmed causes. Do not infer whole-site compliance from a sample.]

## Scenario results

| Scenario | URL / journey | Expected behavior | Observed behavior | Outcome | Evidence |
| --- | --- | --- | --- | --- | --- |
| Fresh visit, no choice | [URL] | [requirement] | [observation] | [expected / unexpected / inconclusive] | [reference] |
| Reject all | [URL] | [requirement] | [observation] | [outcome] | [reference] |
| Reload with refusal | [URL] | [requirement] | [observation] | [outcome] | [reference] |
| Partial consent | [URL] | [categories] | [observation] | [outcome] | [reference] |
| Accept then withdraw | [journey] | [requirement] | [observation] | [outcome] | [reference] |

## Finding [ID]

- Technical priority and rationale: [state your priority scheme]
- Observed behavior: [what the capture actually establishes]
- Expected behavior: [agreed implementation requirement]
- Reproduction steps: [ordered actions from a documented starting state]
- Cookie identity / endpoint: [name, domain, path or reviewed endpoint; omit secret values]
- Evidence: [private capture references]
- Cause and confidence: [confirmed source or hypothesis]
- Responsible owner: [team]
- Proposed remediation: [action]
- Acceptance test: [repeatable condition for closing the finding]
- Status: [open / awaiting retest / closed / inconclusive]

## Retest

- Date and build: [values]
- Configuration changes: [values]
- Repeated scenarios: [list]
- Results and evidence: [references]
- Remaining limitations: [untested or inconclusive items]
- Reviewer: [name]

## Evidence handling

Review all screenshots, URLs, payloads and exports before sharing. Remove session credentials and unnecessary personal information. Redaction of cookie values alone does not make every artifact safe for public distribution.

## Limitations

This report describes the listed scenarios and environment. Automated flags and scores are diagnostic indicators, not legal conclusions. Untested regions, pages, account states and interaction paths remain outside scope.

Template: https://www.consentscope.pro/blog/cookie-audit-report-template-for-clients
