Pavle
CRO

CRO Audit Checklist: 30 Checks With Numbers Attached

Pavle Lucic
Pavle LucicJuly 14, 2026 · 8 min read
Key takeaways
  • Below roughly 100 conversions per variant per month, an A/B test usually cannot reach a clear result. Fix obvious issues and monitor before and after instead.

  • Check your tracking before anything else. A duplicated conversion event makes every later finding wrong.

  • Every check in this list is a yes or no statement with a number attached, not a tactic to try.

  • A CRO audit checks funnel economics. A UX audit checks whether the task can be completed at all. Run both, do not confuse them.

On this page

A CRO audit checklist is a list of yes or no checks you run against a funnel: a pricing page, a checkout, a signup flow. Not a list of things to try. Each check carries a number, a load time, a pixel size, a field count, so two people running the same audit land on the same answer.

Here is what most checklists skip. If your funnel gets fewer than about 100 conversions per variant each month, an A/B test will not tell you much. You will watch two versions of a page tie for weeks, then guess anyway.

Below that traffic level, skip the split test. Use the checklist below instead. Fix what it finds, then watch the before and after numbers.

How much traffic you need before A/B testing means anything

Every company selling testing software has a reason to avoid this number. Tell a small site it cannot test yet, and that site will not buy the tool.

Here is the honest version. A split test needs enough conversions per variant to separate a real winner from noise, in a reasonable time. As a rough rule of thumb, aim for at least 100 conversions per variant per month before you trust a result.

Below that, a test can run for two months and still land on a coin flip.

Say a SaaS trial page gets 40 signups a month. Split that across two variants and each side gets 20. That is not a test. That is noise.

An ecommerce store selling one product might see 60 orders a month. That is 30 conversions per variant, well under the threshold too.

If you are below the threshold, skip the test. Run this checklist instead. Fix what it flags. Then compare your conversion rate before and after, over a full month. Compare against the same period last year too, if seasonality is a factor.

It is less rigorous than a real test. It is also not a wasted month, and a low powered test usually is.

Check zero: is your tracking even right?

Skip this and every other finding in your audit is a guess.

Before you look at a single page, confirm four things about your analytics.

  • [both] The conversion event fires once per completed action, not once per page load.
  • [both] No tag fires twice: once on the button click, again on the confirmation page.
  • [both] Test purchases and internal team sessions are excluded from the reporting view.
  • [both] Bot and crawler traffic is filtered out of the conversion count.

The pattern shows up often enough to be worth naming. A "Buy Now" button fires the same purchase event twice, once from the click handler and once from the thank you page loading, and the reported conversion rate looks inflated for months before anyone notices.

Warning

If any of the four checks above fail, stop here. Fix tracking first. Every other number in this audit depends on it.

An audit built on broken tracking does not just miss things. It confidently points you at the wrong page.

The checklist: 30 checks, each answerable yes or no

Everything below is testable. It is either true of your funnel right now, or it is not. Each check is tagged [ecom] for ecommerce, [saas] for software, or [both].

The money page (above the fold)

  • [both] The value proposition is understandable within 5 seconds of landing.
  • [both] The primary call to action is visible without scrolling, at a 667px viewport height.
  • [both] Only one primary call to action appears per screen, not two competing options.
  • [both] The headline names the specific outcome, not a category.
  • [both] Product or service imagery appears above the fold, not text alone.

A project management tool with the headline "Powerful Software for Teams" fails this check. "Plan a launch in one board, not five spreadsheets" passes it.

Trust and risk

  • [both] A guarantee or return policy is stated within one scroll of the primary call to action.
  • [both] At least one specific customer review or rating appears on the page, not just a badge.
  • [ecom] A security badge or payment icon set sits near the checkout button, not only in the footer.
  • [both] The refund or cancellation policy is a visible link, not buried inside the terms page.
  • [ecom] Tax and shipping costs show before the final checkout step, not after.

The form or checkout

  • [ecom] The checkout form asks for 8 fields or fewer before payment.
  • [ecom] Guest checkout is available, without forcing account creation.
  • [saas] The trial signup form asks for 4 fields or fewer.
  • [both] Inline validation names the specific field with an error, not a generic "form invalid" message.
  • [ecom] At least 2 payment methods are offered beyond a single card processor.
  • [both] A visible progress indicator shows how many steps remain in checkout or signup.

Speed and mobile

These thresholds are not unique to CRO. They match the Core Web Vitals and accessibility guidelines used across web performance generally.

| Metric | Threshold | Applies to | |---|---|---| | Time to first byte | Under 0.8 seconds | Both | | First contentful paint | Under 1.8 seconds | Both | | Largest contentful paint | Under 2.5 seconds | Both | | Cumulative layout shift | Under 0.1 | Both | | Mobile tap target size | At least 44 by 44 pixels | Both | | Default body text size | 16px or larger | Both |

A checkout page with a looping hero video routinely fails largest contentful paint on mobile, even on fast connections.

Pricing clarity

  • [saas] Plan names describe who they are for, not just tier labels like "Pro" and "Plus" with no context.
  • [both] The pricing page states whether tax, VAT, or fees get added at checkout, so nothing surprises the buyer.
  • [saas] A default or recommended plan is visually marked, so the buyer is not choosing cold.
  • [saas] Per seat or per unit pricing is shown, not only a bundled total.

The leak points

  • [both] An exit intent message appears once per session, not on every attempt to leave.
  • [both] Abandoned cart and abandoned trial emails send within 24 hours.
  • [both] Each checkout or signup step has a page level exit rate someone on the team can name.
  • [both] The single highest drop off step in the funnel has a written hypothesis for why.

What this checklist does not cover

This list never asks whether someone can actually finish the task. That is a different question, and a different audit.

A CRO audit checks funnel economics: pricing clarity, trust signals, and whether the tracking behind them can be trusted. A UX audit checks whether a person can complete the task at all, whether or not money changes hands.

A pricing page can pass every check on this list and still lose the sale. Maybe the signup form has a bug that blocks submission on mobile. That is a UX problem, not a CRO one, even though it costs the same revenue.

The two overlap in places, like page speed and form length. But they answer different questions. For the usability layer, run a 40 point usability checklist alongside this one, then log what you find in a ready-made findings template. For the fuller breakdown of where a CRO audit ends and a UX audit begins, read the guide on how the two differ.

Run both. Just do not let one stand in for the other.

How to actually run this audit

Work one funnel at a time. A homepage, a checkout, and a pricing page are three audits, not one.

Score every failed check by revenue at risk, not by how bad it looks. A slow load time on your highest traffic landing page outranks a missing badge on a page nobody visits.

Fix tracking first, always. Then fix the cheap items with wide reach: field count, tap target size, a missing guarantee. In practice, a five minute fix like widening a tap target usually beats a two week redesign. It ships today and affects every visitor right away.

Test only what you have the traffic to test, using the threshold from earlier. Below it, monitor before and after instead.

For a longer walk through of scoring and prioritization, read the full CRO audit guide. If you run a store, the [ecom] checks above sit inside a bigger sequence, and the ecommerce version of this audit walks it end to end, starting with what your platform actually lets you test.

If you would rather hand this off, that is exactly what the CRO audit service is for.

Frequently asked questions

What is a CRO audit checklist?

A CRO audit checklist is a list of yes or no checks you run against a funnel: a pricing page, checkout, or signup flow. It finds where revenue leaks. Each check has a number attached, like a load time or a field count, so two auditors reach the same answer.

How much traffic do you need before A/B testing is worth running?

As a rough rule of thumb, aim for at least 100 conversions per variant per month before trusting a split test result. Below that, a test can run for months without a clear winner. Fix obvious issues from a checklist instead, then compare conversion rates before and after.

What is the difference between a CRO audit and a UX audit?

A CRO audit checks funnel economics: pricing clarity, trust signals, and tracking integrity, to find where revenue leaks. A UX audit checks whether a person can complete the task at all, regardless of revenue. The checks overlap, but they answer different questions.

Is a CRO checklist different for ecommerce and SaaS?

Yes. Ecommerce funnels involve cart, checkout, shipping, and payment methods. SaaS funnels involve trial signup, seat based pricing, and plan selection. A useful CRO checklist tags each check as ecommerce only, SaaS only, or both, instead of defaulting to one.