The Business Growth Audit

What the audit actually looks at

Fifty automated checks against your public website, sixty questions about the parts of the business no scan can see, and a scoring method that refuses to pretend it measured something it could not. This page describes what exists today — not a roadmap.

Three kinds of evidence, kept apart

Most audits blend measured facts, owner recollection and vendor assumption into one confident-sounding document. This one keeps them in separate buckets, because the difference between them is usually where the problem is hiding.

Automatically detected

Fifty checks run against your public website and DNS. Every result is stored with the raw evidence that produced it — the header that was returned, the tag that was found, the URL that responded. Nothing in this tier depends on anyone's opinion, and you can be shown exactly why each check landed the way it did.

Self-reported

Sixty questions covering the things a scan physically cannot see: what you actually spend, whether anyone follows up an enquiry, who holds the admin passwords, whether last month's revenue can be pulled up in five minutes. These are recorded as your claims, stored separately from measured evidence, and never presented as if they were measured.

Connected-account data

Some questions can only be settled by looking inside the accounts themselves — Google Analytics, Search Console, Google Ads, Meta, your CRM. There is no live OAuth connector for these in the product today. In the full audit engagement this is handled by exporting the reports and importing them: the platform accepts an uploaded report, maps its columns, and normalises the metrics. Anyone telling you a one-click connector exists here would be describing something that is not built.

What is detected automatically

Fifty checks run against the public site and its DNS. No access, no credentials and no cooperation from your developer is required — everything here is visible to anyone, which is precisely why it matters.

Security & trust

Does the domain resolve, is HTTPS enforced, is the SSL certificate valid, are standard browser security headers sent, is a secure page loading insecure assets, is a privacy policy linked, are contact details findable.

Search & SEO

Page title and its length, meta description and its length, canonical URL, H1, heading order, robots.txt, XML sitemap and how many URLs it lists, whether made-up URLs correctly return a 404, whether the www and non-www addresses settle on one canonical address, language targeting tags, internal link count.

AI readability

Whether the page's content is in the raw HTML or only appears after JavaScript runs, whether a recognised business schema type is declared, whether robots.txt blocks search and AI crawlers, whether an llms.txt file is published.

Content & structure

Word count, image alt text, Open Graph tags, favicon, declared page language, whether an FAQ page exists.

Tracking & analytics

Google Analytics 4, Google Tag Manager, and whether advertising is running with no analytics behind it.

Advertising

Which advertising and remarketing tags are actually on the page — Google Ads, Meta, TikTok, LinkedIn, Pinterest, Snapchat, X, Microsoft (Bing) UET.

Performance & platform

PageSpeed score, mobile viewport tag and its configuration, CDN in front of the site, and hints about the framework, hosting and database platform in use.

A check that cannot be completed — a request that times out, an endpoint that refuses to answer — is recorded as unknown, with the reason it failed. It is never quietly converted into a failure.

What you have to answer yourself

Sixty questions across eleven areas. Most are deliberately blunt and answerable in a few seconds — the useful signal is usually in which ones you cannot answer at all.

Company & Goals5 questions
Revenue & Business Visibility6 questions
Website & Hosting7 questions
Online Presence & Search5 questions
Tracking & Analytics7 questions
Marketing Spend & ROI7 questions
Sales & Customer Journey6 questions
CRM & Automation5 questions
Ownership & Security5 questions
Operations & Reporting3 questions
AI Readiness4 questions

The kind of question it asks

  • “If your web developer or agency disappeared tomorrow, could you personally log in and take control of your domain name and website?”
  • “If asked which marketing channel made you the most money last month, could you say for certain — with numbers to back it up?”
  • “When someone submits a form or makes a booking on your website, does that information land directly in your CRM without anyone re-typing it?”

How findings are scored

Weighted, not counted

Every check carries a weight and a severity. A missing SSL certificate and a missing llms.txt file are not the same event, and a score that treats them as one each is not telling you anything. A pass earns full weight, a warning earns half, a failure earns none.

What could not be measured is excluded, not failed

This is the part most tools get wrong. If a check could not be completed, its weight is removed from the denominator entirely rather than counted against you. A score is a statement about what was actually measured — inflating the failure count with things nobody could see would make the number meaningless in exactly the cases where it matters most.

So that this cannot be used to hide anything, a separate coverage figure is reported alongside the score: how much of the total possible weight was measurable at all. A high score with low coverage is a signal to look harder, and you can see that immediately instead of having to work it out.

Two checks are reported but never scored

Language targeting tags are only relevant if you run separate versions of the site for different countries, and llms.txt is an emerging convention with no official backing yet. Both are shown for information and neither is counted against the score.

How recommendations are prioritised

Findings are sorted by severity first — critical, then high, then medium, then low — and by weight within each band. Related findings are then grouped into weak points written in commercial terms rather than technical ones.

Two rules constrain what can be recommended:

  • 1

    Every weak point must cite the specific checks that triggered it. No recommendation is made without evidence from the scan behind it.

  • 2

    Every recommended service must exist in the real services catalogue. Recommending something outside it would mean pitching work that cannot be scoped or priced.

What the report contains

The website scan produces its results on screen straight away and as a downloadable PDF. The score in that PDF is recalculated on the server from the findings — a score sent up from a browser is never trusted.

What happens after

  1. 01

    You get the findings whether or not you do anything else with signalIQ. The website scan results appear on screen immediately, with no signup and nothing held back pending a reply.

  2. 02

    A conversation about what was found — what it means, which parts matter, and what it would realistically take to fix. Nothing is proposed before there is a finding to base it on.

  3. 03

    Only then does scope and pricing get discussed, against the specific weak points the audit surfaced.

  4. 04

    If signalIQ is not the right fit, or is at capacity, you will be told that directly rather than pitched anyway.