Guides · 8 min read

How the SEO and AI Readiness Audit Runs

The audit method check by check, from intake and crawl to AI visibility testing, scoring and the roadmap, so you know what is measured and how before you book.

By Umit Caybas, Founder and SEO Consultant. Published .

The SEO and AI Readiness Audit runs as a test suite in eight phases, with fixed checks, recorded evidence and severity ratings. It crawls the site twice, baselines indexation and rankings, reviews content and AI readiness, tests prompts across the AI engines in fresh sessions, and scores everything into a roadmap any developer can act on.

Key takeaways

  • 01The method is the same at both tiers; the Extended tier runs it in full where the Standard tier samples.
  • 02The prompt set comes from your own answers about what you sell, who buys it and what they ask, never from us.
  • 03Every AI visibility run is a fresh session, logged as structured data, and repeated three times, because a single check is an anecdote.
  • 04Every finding carries a severity, an effort estimate, an owner and an expected impact, and the roadmap sits on page two of the report.

Why the audit is a test suite

An audit that depends on who ran it cannot be repeated, and an audit that cannot be repeated cannot measure change. So the Standard and Extended audits are built as a test suite: fixed checks with pass conditions, evidence recorded for every finding, a severity on each, and a score computed from published weightings. Anyone following the script gets the same result, which is what lets the same audit run again in 90 days and report the difference rather than an impression.

The eight phases below are the script. The Standard tier samples where sampling is sound; the Extended tier runs every check in full. The technical SEO guide explains the underlying concepts the checks rest on; this page explains what the audit does with them.

Phase 0: intake and baseline

Nothing is measured until we have read access to four accounts: Google Search Console, GA4, Google Business Profile and Bing Webmaster Tools. The last is not optional. ChatGPT and Copilot lean on Bing's index, so Bing is one of the few sources of real citation data, and most businesses have never opened it.

Intake also records your answers to three questions: what do you sell, who buys it, and what do they type or ask when they are looking. Those answers become the prompt set tested in Phase 5. We do not invent the prompts, because a prompt set written by the auditor measures the auditor's assumptions rather than the market.

Phase 1: crawl and technical

A crawl connected to Search Console and the PageSpeed API checks each of the following, with a pass condition for every one:

  • Indexable page count matches what is expected, with no unintended noindex.
  • Status codes: no 4xx in internal links, no redirect chains longer than one hop.
  • Canonicals self-referencing or correct, with no conflict against hreflang.
  • Robots directives with no accidental blocks on CSS, JavaScript or key sections.
  • An XML sitemap that is present, submitted and lists only indexable URLs returning 200.
  • Titles and meta descriptions with no duplicates and none missing, within display limits.
  • Exactly one H1 per page that describes the page.
  • Internal links with no orphan pages and every key page within three clicks of home.
  • Core Web Vitals from field data, not lab data alone: loading, interaction and layout shift.
  • Content parity between mobile and desktop.
  • Raw HTML compared against rendered HTML.

The rendering comparison matters most on headless and client-rendered builds. The crawl runs twice, once with JavaScript off and once with it on. Content that exists only in the rendered version is a finding in its own right, because most AI crawlers do not execute JavaScript and will never see it.

Phase 2: indexation and performance baseline

From Search Console: indexed against submitted pages, coverage errors by type, queries and pages by clicks and impressions over sixteen months, and the split between branded and non-branded searches. From GA4: organic sessions, conversions, and referral traffic from the AI engines themselves, which most sites have never segmented. We build the segment if it does not exist.

The baseline also captures rank positions for the commercial terms and, for local businesses, local pack presence in every service suburb. Local pack rankings are the asset most often destroyed in a rebuild and the one least often inventoried beforehand, so they are recorded before anything is recommended.

Phase 3: content and on-page

The Standard tier reviews the top twenty pages by traffic and commercial value. The Extended tier reviews every template and then spot-checks instances, because on a large site the template decides the outcome for hundreds of pages at once. Each page or template is checked for five things: it targets one clear intent, it answers the primary question in the first hundred words, it has a scannable structure with real headings, it carries original information rather than paraphrased competitor content, and it shows a visible date and author.

Then the gap analysis: terms competitors rank for that the site does not, and questions with real demand that have no page at all. The second list is usually the more valuable, because it names pages that do not exist yet.

Phase 4: AI readiness

This is the technical layer answer engines depend on, and it is checked in five parts.

AI crawler access is checked in robots.txt for GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, PerplexityBot, Google-Extended and Bingbot, and then in server logs and firewall rules, because blocking often happens there rather than in robots.txt. Many sites blocked these crawlers in 2024 and never reversed it.

Structured data is validated for Organization, LocalBusiness, Service, Product, FAQPage, Article and Person, using the Schema.org validator and Google's Rich Results Test. Missing sameAs links are the most common entity failure.

Entity consistency means the business name, address and phone are identical across the site, the Google Business Profile and the major directories. Inconsistency is the single biggest reason an AI system cannot confidently say who a business is.

The llms.txt file is checked and reported honestly: adoption is contested and Google has said it does not use it, so it is a low-cost hedge, not a ranking factor.

Content extractability asks whether the key answer can be lifted as a clean paragraph, or whether it is buried in an accordion, a tab or an image.

Phase 5: AI visibility testing

This is the phase that either builds a credible measurement or produces a folder of screenshots. The prompt set from intake is arranged across three stages of intent: problem-aware, such as "why is my hot water going cold"; solution-aware, such as "best plumber Parramatta"; and brand-aware, such as "is this business any good". The Standard tier uses fifteen prompts, the Extended tier forty.

Three rules are not negotiable. Every prompt runs three times, because the engines return different answers to the same question and a single check does not represent citation probability. Every run is a fresh session with no conversation carried over. And every run is logged as structured data, not a screenshot: the prompt, the engine, the run number, the timestamp, whether the brand was mentioned and in what position, the competitors named, the sources cited, whether the description of the business was accurate, the sentiment, and the raw response verbatim.

The Standard tier tests four engines: ChatGPT, Gemini, Perplexity and Google AI Overviews. The Extended tier adds Claude. The headline metric is citation rate, the share of tested queries in which the brand appears, reported per engine and blended. The same calculation for the named competitors gives share of voice, which is the number clients react to. Because engines rewrite, summarise and occasionally invent, the log also records hallucinations and sentiment, not just presence.

One honesty note that goes in every report: results gathered through the engines' APIs are a close proxy for what the consumer products show, not identical to them. We say so rather than let a client discover it.

Phase 6: off-site authority

Backlinks and referring domains are weighted toward the sources answer engines draw on: directories, industry associations, review platforms, and above all the third-party sources that keep appearing in the Phase 5 citation logs. If a review site or a trade directory is repeatedly cited when an engine recommends a competitor and the client is absent from it, that is a finding with an obvious action attached. The Standard tier delivers this as a summary; the Extended tier maps every cited source.

Phase 7: scoring and the roadmap

Every finding is scored against weightings that are published in the report: technical health 20, indexation and rankings 15, content quality 20, AI readiness 20, AI visibility 15, authority 10. A defensible score that can be re-run in 90 days is worth more than any single finding, and it is the natural baseline for the Signal retainer, which repeats the measurement monthly.

Every finding carries a severity from critical to low, an effort estimate, an owner, whether developer, content, client or us, and an expected impact. The roadmap sequences them: quick wins and critical items in weeks one and two, structural and technical fixes in weeks three to eight, content and authority in weeks nine to twelve, and on the Extended tier a phased content architecture from week thirteen to twenty-six. It sits on page two of the report, because nobody reads a forty-page audit from the front.

How long each phase takes

On a Standard site the phases add up to roughly ten to fourteen hours of work, which is why the turnaround is ten business days rather than two: intake and baseline take about half an hour, the crawl and technical checks two to three hours, the indexation baseline an hour, content two to four hours, AI readiness one to two, AI visibility testing two to four, off-site authority an hour, and scoring and the roadmap the rest. The Extended tier runs longer because every template is checked and forty prompts run on five engines, so it is quoted at fifteen business days. Neither tier is rushed to fit a shorter promise, because the evidence is the product.

What you receive

Four things. The audit report as a scored, severity-rated PDF with the roadmap up front and the evidence in appendices. The findings register as a spreadsheet, one row per finding, filterable by severity and owner. The AI visibility log with the full run data, so you can see the working. And a recorded walkthrough call, 45 minutes on the Standard tier and 90 minutes with written questions and answers on the Extended tier.

The roadmap is written so any developer can act on it, including one who is not us. The audit is a complete deliverable and its fee is not credited against later work, which is what keeps it honest: nothing in the report is there to sell the next engagement. The questions clients ask before booking are answered in the audit FAQs, and the tier qualifiers and prices are on the Standard and Extended pages.

In this guide

  • FAQs

    SEO and AI Readiness Audit FAQs

    The questions businesses ask before booking the SEO and AI Readiness Audit, from access and turnaround to how the tier is decided and what happens after.

Next step

Book the Standard Audit.

Fixed-price SEO and AI readiness audit for sites of up to 50 pages. Crawl, rankings baseline, AI visibility testing and a 90-day roadmap for $1,950 + GST.

Book the Standard Audit