# What should an AEO/GEO Audit include?

> A practical checklist for evaluating prompts, citations, technical readiness, content, authority, and the final action plan.

By Marius C. Paun · Reviewed by Joey Kudish · Published 2026-07-30

An AEO/GEO Audit should explain how answer engines currently represent the business and give the team a specific plan for improving that representation.

The report needs more than prompt screenshots. It should connect AI answers with the website, the source pool, the business's real identity, and the buyer decisions that matter.

Use this checklist when comparing providers or designing an internal review.

## A documented prompt set

The Audit should show which questions were asked and why they belong in the set.

A balanced set normally covers:

- Branded questions about the company itself
- Category discovery questions
- Comparisons and alternatives
- Evaluation questions about fit, quality, price, or risk
- Problem-aware questions asked before a buyer knows the category name
- Market or location-specific questions where relevant
- Questions that reveal whether the engine understands important offers

Prompt selection controls the result. A report built from generic keywords can look precise while measuring the wrong buying journey.

## Multiple answer surfaces

Different AI systems use different indexes, search partners, retrieval methods, and citation behavior. The Audit should identify every measured surface and preserve the response evidence.

The provider list does not need to include every AI product. It should cover the surfaces the audience is likely to use and distinguish direct measurements from inferred conclusions.

## Presence, accuracy, and citations

For each important prompt, the review should answer three separate questions:

1. Did the business appear?
2. Was the description accurate and complete?
3. Was the business or one of its pages cited?

A mention without a citation still matters. A citation attached to an inaccurate description is not a win. Keeping the measures separate prevents a single score from hiding the real problem.

## Competitors and source pools

The Audit should record which competitors appear and which third-party sources influence the answers. This is where the report moves beyond the company's own site.

Useful source analysis identifies directories, publications, review sites, associations, partner pages, datasets, and community sources that recur in the category. Each important source should lead to a concrete decision: correct a profile, earn coverage, publish missing evidence, or accept that the source is irrelevant.

## Technical readiness

The technical layer should verify that important content can be discovered and interpreted. At minimum, review:

- `robots.txt` rules for search and AI user agents
- XML sitemap coverage and truthful modification dates
- Canonical URLs and redirects
- Server-rendered access to identity, offers, and proof
- Organization, Person, Service, and page-level structured data
- Consistent names, URLs, and profile relationships
- Page performance and mobile usability
- Freshness signals and visible dates where dates matter

These checks are deterministic. The report should show the observed signal and the rule used to reach the verdict.

## Content and authority

The Audit should inspect whether pages answer buyer questions clearly enough to be retrieved and quoted. It should also examine whether the claims have named authors, first-party evidence, specific outcomes, and links to supporting sources.

Authority includes the surrounding web. Strong profiles and credible third-party references help engines confirm that the business is the entity it claims to be.

## A prioritized implementation plan

Every important finding should become work someone can assign. A useful recommendation includes:

- The page, source, or system to change
- The observed gap
- Why the change comes now
- The expected movement
- A clear definition of done

The final plan should separate urgent access or identity problems from longer-term content and authority work.

## Method and limitations

The report should state the dates, providers, prompt set, known collection failures, and the limits of any third-party metric. AI responses are variable, so the evidence needs a measurement window rather than a claim of permanence.

Agentsy Report's [complete Audit](/audit/) follows this structure and adds founder review, a walkthrough call, and a 30-day comparison re-scan. Start with the [free Scan](/#hero-scan-form) if you want to inspect the first layer before commissioning the full review.