Article
What is the difference between a cookie consent audit and a cookie banner?
A cookie banner collects a choice. A consent audit records cookies and requests under labeled states. ConsentProbe audits runtime and does not replace a CMP.
In brief
A cookie banner, usually part of a CMP, asks for consent and stores the choice. A cookie consent audit checks what the browser loaded: cookies, storage, and third-party requests under labeled states such as fresh, Reject All, Accept All, or GPC on. A polished banner can still fail that check when tags ignore the choice. ConsentProbe records those browser artifacts. It does not replace a CMP. This page is positioning and testing guidance, not legal advice.
Not legal advice
This article explains the difference between a cookie consent audit, which observes runtime behavior, and a cookie banner or CMP, which shows a choice and stores a preference. It is not legal advice. It is not a certification that any banner or audit makes a site meet GDPR, CPRA, or another rule. It is not a substitute for counsel. Tool names below are category examples.
Short answer
A cookie banner, usually part of a CMP, is the UI that asks for consent and stores the visitor's choice. A cookie consent audit is a runtime check of what the browser actually loaded: cookies, storage, and third-party requests under labeled states such as fresh, Reject All, Accept All, or GPC on.
You can ship a polished banner and still fail the audit if tags ignore the choice. ConsentProbe is an audit product. It records those artifacts. It does not replace Consent Pro, an OneTrust-style platform, or any other CMP. Use a CMP to collect consent. Use an audit when you need evidence the network matches the claim. This page is product positioning and testing guidance, not legal advice.
Two jobs
A cookie banner or CMP collects a choice, stores the preference, and, when it is wired through, sends a signal that tags can read. Success for that job looks like a preference the banner can show again and a state other tools can query.
A cookie consent audit observes runtime behavior under a named state and keeps the artifacts: cookies, requests, screenshots. Success for that job looks like a finding you can open back to a request, a cookie, or a screenshot.
Stores keep both. The banner does the asking. The audit checks whether the browser followed. The runtime audit versus CMP guide measures the same split from the evidence side. The CMP claims guide shows how to falsify a specific sentence in the banner against the wire.
Buyer comparison
Use the questions your team already asks. The answers sit in different products.
| Question | Banner / CMP | Consent audit |
|---|---|---|
| Did the user see a choice? | Showing the choice is the job. | A UI screenshot is one artifact among others. |
| Did Reject stop marketing tags? | The configuration claims it should. | Measured on the post-reject network and cookie jar. |
| Can counsel or engineering reproduce it? | Policy text and admin settings. | A state-labeled evidence pack. |
| Does installing this make the site meet the law? | No tool alone does that. | No audit alone does that. Not legal advice. |
We bought a CMP, so we audited
Installing a CMP records that you bought a preference layer. It does not record what the browser sent on a fresh load or after Reject. Teams discover the gap when a pixel host still appears in Network after the visitor declined.
Consent Pro and OneTrust-style products are CMPs: they collect and store consent. Name them as that category, then stop. This page does not rank features, and it does not tell you to remove a CMP you still need.
When a banner sentence and the wire disagree, use the CMP claims guide. It maps honor, reject, and GPC wording onto isolated visits. That is the falsification step. This page only draws the job split so the shopping comparison stays straight.
When you need which
If you need to collect and store consent for an EU or California storefront, you need a banner or CMP. If you need to show that the page was quiet before Accept, or that Reject All changed the pixels, you need an audit. The pre-consent checklist and the Reject All guide are the two passes people usually run first.
Most Shopify and DTC teams need both jobs. Keep the CMP. Add the audit when someone has to show the runtime, not the admin screen. A free US-baseline ConsentProbe visit shows report format on one non-California pass. It is not an EU or California conclusion. The free versus paid guide says when to use paid EU scenarios or a California GPC pair.
Related idea: an evidence pack
Findings are easier to hand off when each one points at a cookie table, a request URL, a screenshot, and an optional HAR, all labeled by consent state. A fuller evidence-pack guide is planned as CP-06. That page is not published. Until it exists, label every artifact yourself: URL, time, state name, cookies, requests, and screenshots. Do not wait on CP-06 to start the labeling.
A useful first pack is three files for one URL: fresh, Reject All, and Accept All. Circle the hosts that appear in more than one file. That circle is the conversation with engineering. The banner copy can sit beside it. It does not replace the circle.
Keep the banner, add the runtime check
Already have a banner and want a runtime record? Run ConsentProbe on the storefront URL. The free US-baseline visit shows the report format. Use paid EU or California GPC scenarios when the comparison has to be regional. ConsentProbe will not replace your CMP, and the report will not certify the shop.
FAQ
Is a cookie consent audit the same as a cookie banner?
No. The banner collects a choice. The audit measures cookies, storage, and requests under a labeled state.
Is ConsentProbe a CMP like OneTrust or Consent Pro?
No. ConsentProbe audits browser behavior. It does not replace a consent collection UI.
Do I still need a CMP if I use ConsentProbe?
If you need to collect and store consent, yes. That is a different job from recording what the browser did.
Can a banner screenshot prove the site meets the law?
A screenshot shows that a UI rendered. It does not show that tags respected the choice. This page is not legal advice.
What is an evidence pack?
State-labeled cookies, requests, and screenshots, plus an optional HAR. A fuller guide is planned as CP-06 and is not a page yet.
Does a free US scan prove EU banner behavior?
No. A free US-baseline visit is not an EU or California comparison. See the free versus paid guide.
Limits of this page
This article separates a cookie consent audit from a cookie banner or CMP. It is not legal advice, not a certification under GDPR, CPRA, or any other rule, and not a reason to remove a CMP you use to collect consent. Tool names are category examples.
Related guides
Open the CMP claims guide for the falsification steps, the free versus paid guide before you quote a region, and the pre-consent checklist for the pass order.
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Pre-consent audit checklist: what to verify before Accept
- Runtime Audit vs CMP: What Each One Measures
- Pre-Consent Cookie Audit: A Storefront Checklist
- Reject All Still Tracking: What to Check After You Say No
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.