Skip to main content
Resource Checklist Beginner

SEO Audit Checklist for Small Businesses

Audit whether Google can access, understand, and index your important pages, then check content quality, local visibility, links, and conversions.


SEO Audit Checklist for Small Businesses

An SEO audit should answer three questions: Can search engines access and index the pages you want people to find? Can a visitor understand and trust what those pages say? Do organic visits lead to calls, bookings, purchases, or another useful outcome?

Start with evidence rather than a sitewide score. Export a baseline, inspect representative pages, and record the URL or report behind every failed check. Fix crawl and indexation blockers first. Then improve the pages closest to a business outcome before working through lower-impact cleanup.

This checklist reflects Google guidance reviewed on August 19, 2026. It does not promise rankings or citations in AI-generated answers.

Before you start

  • Verify the correct website property in Google Search Console.
  • Record the audit date, site owner, CMS or platform, and any recent redesign, migration, domain, or tracking changes.
  • Export at least several months of Search Console Performance data so you can compare queries, pages, countries, and devices later.
  • Confirm which actions count as conversions, such as a qualified call, form submission, appointment, purchase, or subscription.
  • Choose a representative URL set: the homepage, a primary service or product page, a location page if applicable, a high-traffic article, a low-traffic priority page, and one recently published page.
  • Give every issue a status, evidence link, owner, priority, and verification date. Use “not applicable” when a check does not fit the business.

Do not mark a check complete from a crawler report alone. When a finding affects indexation or rendering, confirm it with the live page and Search Console’s URL Inspection tool.

Crawl and indexation

  • The homepage and each representative priority URL return the intended HTTP status without a redirect chain.
  • Pages intended for search return a successful response and do not contain an accidental noindex directive.
  • Private, duplicate, filtered, staging, or otherwise non-search pages use the appropriate access or indexing control.
  • robots.txt does not block important page resources or prevent Google from crawling pages that need to be indexed.
  • Pages intentionally excluded from results use noindex or access control rather than relying on robots.txt. Google notes that a disallowed URL can still be indexed without its content; see its robots.txt guidance.
  • Search Console’s Page Indexing report is reviewed by reason, not just by the total number of excluded URLs. Expected redirects, duplicates, and removals are separated from genuine problems.
  • Each representative URL is checked in URL Inspection for crawl permission, index status, Google-selected canonical, last crawl, and rendered content.
  • The preferred URL is consistent across redirects, internal links, canonical tags, and the XML sitemap. Google’s canonicalization guidance treats redirects and rel="canonical" as strong signals and sitemap inclusion as a weaker one.
  • The XML sitemap is accessible, contains only preferred indexable URLs, uses accurate absolute URLs, and was processed without errors in Search Console.
  • Sitemap lastmod values change only when a page receives a meaningful update, not on every build or crawl. Google’s sitemap documentation says the value should reflect the last significant page update and be consistently accurate.
  • Important pages are linked from another crawlable page with a standard <a href> link and descriptive anchor text. Google recommends at least one internal link to every page you care about in its link best practices.
  • Broken internal links, accidental soft 404s, and unnecessary redirect hops are documented and assigned for repair.
  • If important content is added with JavaScript, the rendered HTML in URL Inspection contains that content and its links.

Mobile experience, security, and Core Web Vitals

  • Priority templates are used on real phones or responsive browser widths. Navigation, forms, consent controls, text, tables, and calls to action remain usable without horizontal scrolling or overlap.
  • Every public page and resource loads over HTTPS, and browsers report no mixed-content or certificate errors.
  • PageSpeed Insights is run for representative mobile and desktop URLs. Field data and lab data are recorded separately.
  • When enough real-user data exists, the Core Web Vitals assessment is reviewed at the 75th percentile: Largest Contentful Paint at 2.5 seconds or less, Interaction to Next Paint at 200 milliseconds or less, and Cumulative Layout Shift at 0.1 or less. These are Google’s current “good” thresholds; see Core Web Vitals and Search.
  • The Search Console Core Web Vitals report is checked for affected URL groups, while PageSpeed Insights or Lighthouse diagnostics are used to investigate specific templates.
  • A green Lighthouse score is not treated as proof that real visitors have a good experience. PageSpeed Insights explains that its field data reflects real users over a rolling 28-day period, while lab data is a simulated diagnostic run.
  • Large images, render-blocking resources, third-party scripts, slow server responses, and layout shifts are prioritized using measured impact on the affected template.

There is no universal “page must load in under three seconds” pass/fail rule. Record the Core Web Vitals result, conversion impact, and specific bottleneck instead.

Search appearance and on-page clarity

  • Every indexable page has a descriptive, concise <title> that distinguishes it from other pages and matches the page’s main purpose.
  • Repeated boilerplate, vague titles, keyword stuffing, and title text that conflicts with the visible heading are flagged.
  • Every priority page has a useful, page-specific meta description. Search Console pages with high impressions and low click-through rates are reviewed at comparable positions before rewriting snippets.
  • Titles and descriptions are evaluated in context rather than against a fixed character count. Google says title links and snippets are truncated as needed for the device; see its guidance for title links and meta descriptions.
  • The main heading states what the page is about. Subheadings form a readable outline rather than repeating keyword variations.
  • A page created to answer a question gives a clear answer near the beginning, then supplies the evidence, conditions, examples, or steps a reader needs.
  • Each page has a defined purpose and audience. Related questions can share one useful page; separate near-duplicate pages are not created for every keyword variation.
  • Internal links point to useful next pages and use descriptive text rather than repeated “click here” labels.
  • Informative images have accurate alt text that describes their role on the page. Decorative images use empty alt text, and alt attributes are not stuffed with keywords.
  • Images use appropriate dimensions, compression, and responsive sources. A modern format is helpful when supported, but WebP is not a universal requirement.
  • Structured data uses a Google-supported type only when it fits the visible page. Names, dates, ratings, prices, addresses, and other marked-up claims match what a visitor can see.
  • Structured data passes the Rich Results Test, while the audit notes that valid markup makes a page eligible for a feature rather than guaranteeing one. Google’s structured data guidelines require markup to represent visible, relevant content.

Content quality and evidence

  • The page satisfies the task its title promises without making the reader search again for the basic answer.
  • The content contributes something beyond a summary of other pages: direct expertise, a documented process, an original example, a useful comparison, local detail, or data the business is authorized to publish.
  • Experience, tests, customer outcomes, and product use are claimed only when the author can document them. Otherwise, the page states the actual research method and its limitations.
  • Claims that are consequential or likely to change—such as prices, legal requirements, product features, market figures, or search-platform rules—link to a primary source beside the claim.
  • Time-sensitive facts include a source and a checked or measured date. The page is revised when the facts change; its date is not changed merely to make it look fresh.
  • Authorship and review credits are accurate. A named author or reviewer has a relevant bio, and no experience or credential is invented for search visibility.
  • Facts, estimates, opinions, and recommendations are distinguishable. Comparisons name the criteria used and disclose material affiliate or ownership relationships.
  • Unsupported superlatives, ranking guarantees, and vague attributions such as “experts say” are removed or sourced.
  • Duplicate, doorway, and overlapping pages are consolidated, redirected, or given clearly different purposes.
  • Thin utility pages are judged by whether they complete their task, not by a minimum word count. Google explicitly says it has no preferred word count in its people-first content guidance.
  • Old pages are reviewed according to risk, traffic, and how quickly their facts change—not a universal six-month schedule.
  • Pages that no longer help the intended audience are improved, combined, redirected, or removed with an intentional plan for their links and search history.

AI search and citation readiness

Google says the same SEO foundation applies to AI Overviews and AI Mode. A supporting page must be indexed and eligible to appear with a snippet, but there is no special schema or technical requirement that guarantees inclusion. See Google’s AI features guidance and generative AI optimization guide.

  • Important pages are indexable and eligible for snippets; nosnippet, restrictive max-snippet, and data-nosnippet controls are intentional.
  • The main answer and supporting facts are present as readable text in the rendered HTML, not available only inside an image, video, canvas, or inaccessible widget.
  • Headings, paragraphs, lists, and tables are used where they make the answer easier for people to follow. The page is not broken into artificial “chunks” solely for an AI crawler.
  • Claims have nearby evidence, primary-source links, dates, and limitations where appropriate, so a reader can verify them without guessing which source supports which sentence.
  • Original examples, methods, first-party data, or direct expertise are included only when the business can support them. Commodity summaries are not multiplied across many keyword variants.
  • Relevant images and video add information and include the surrounding context and metadata needed to understand them.
  • Supported structured data matches visible content, but no special “AI schema” is added. Google’s current guide says structured data is not required for generative AI search.
  • llms.txt, machine-readable AI files, mass-produced fan-out pages, and manufactured mentions are not treated as Google ranking or citation requirements.
  • Search Console performance is monitored after substantial changes. If a Generative AI performance report is available for the property, it is reviewed alongside standard query, page, device, and conversion data.

No checklist can guarantee an AI citation. The useful goal is to make accurate, original information accessible, understandable, and easy to verify.

  • Search Console’s Links report and any available analytics referral data are exported as a baseline.
  • Important pages have credible ways to earn references, such as original research, a useful tool, a strong local resource, expert commentary, partnerships, or publicity tied to real work.
  • Paid, exchanged, sponsored, or user-generated links use the appropriate link attributes and are not sold internally as guaranteed ranking credit. Google’s outbound link guidance explains when to use sponsored, ugc, or nofollow.
  • Suspicious link spikes are investigated in context. A third-party “toxic link” score alone is not treated as evidence that a domain must be disavowed.
  • The Search Console Manual Actions and Security Issues reports are checked.
  • A disavow file is considered only when there is a considerable pattern of artificial or low-quality links and those links caused, or are likely to cause, a manual action. Google’s disavow documentation says most sites do not need the tool and warns that incorrect use can harm search performance.
  • If those disavow conditions are met, removal is attempted first, the decision is documented, and organic links are not disavowed blindly.

Local SEO

  • The business is eligible for a Google Business Profile, and each active profile is claimed and verified by the business.
  • The business name, address or service area, phone, website, hours, primary category, and attributes accurately reflect the real business.
  • Holiday hours, closures, moves, and phone or URL changes have an owner and update process.
  • The website, Business Profile, and important directories do not present conflicting contact or location details.
  • Reviews are monitored and answered when a response is useful. Review requests follow platform policies and do not condition an incentive on a positive rating.
  • Photos, services, products, and appointment or order links are current where those profile features apply.
  • Each indexable location page contains useful information specific to that location instead of swapping a city name into duplicate copy.
  • LocalBusiness structured data uses the most specific appropriate type, reflects visible information, and identifies the correct location. Validate it against Google’s LocalBusiness documentation.
  • Local calls, directions, bookings, forms, or purchases can be measured without displaying conflicting tracking numbers to users or crawlers.

Google says local results are mainly based on relevance, distance, and prominence. Complete, accurate profile information helps Google understand the business, but there is no way to request or pay for better local ranking; see Google’s local ranking guidance.

Measurement and prioritization

  • Search Console data is segmented by page, query, device, country, and search appearance before drawing a conclusion from an average.
  • Branded and non-branded demand are reviewed separately when the distinction affects the decision.
  • A click-through-rate change is compared at similar positions and query mixes rather than attributed to a title edit automatically.
  • Organic landing pages are connected to the conversions that matter, and duplicate or internal test conversions are excluded.
  • Major releases, migrations, content updates, outages, and tracking changes are annotated so later comparisons have context.
  • Each recommendation names the affected URLs, evidence, expected user or search benefit, effort, dependency, owner, and verification step.
  • Completed work is checked on the production page and in the deciding report. A ticket or CMS save is not proof that the fix shipped correctly.

Prioritize the resulting work in this order:

  1. Access and safety: security incidents, manual actions, accidental noindex, blocked resources, failed responses, and migration errors.
  2. Priority-page failures: canonical conflicts, broken rendering, missing internal links, unusable mobile layouts, or severe performance problems on pages tied to conversions.
  3. Answer and evidence gaps: unclear search intent, weak or duplicated content, unsupported claims, missing sources, and stale facts.
  4. Search appearance and discovery: titles, snippets, media, structured data, internal links, and sitemap cleanup.
  5. Longer-term authority: original resources, partnerships, publicity, reviews, and expert-led content that earn attention because they are useful.

Keep the original baseline, the change log, and the verification result together. The audit itself does not improve visibility; the measured fixes and stronger pages that follow it can.

Sources and further reading