The consent drift detector: how to spot when your banner stops matching your tags
Most consent banners start life accurate. Someone configures the consent tool, maps every tag to a category, tests the banner, and ships it. Six months later the banner says one thing and the site does another. Nothing broke. Nothing was hacked. The site simply changed: marketing added a new analytics tool, a plugin updated, a vendor script arrived inside a tag container. Each change was small. Together they add up to a banner that no longer describes reality.
Regulators have a name for this problem, even if they do not use it on their websites: drift. The setup you approved is not the setup running today. In the privacy notices and enforcement decisions published across the EU, the pattern repeats. A company shows an auditor a screenshot of a correct banner from launch day. The auditor loads the site today and finds trackers firing before any choice is made. The screenshot does not help. What matters is what the site does now.
What drift looks like in practice
Drift takes a few familiar forms. The most common is the orphaned tag: a script that was categorized and blocked at launch, then re-added later through a different route. A marketer drops a retargeting pixel directly into the site header instead of through the tag manager where the consent rules live. The consent tool never sees it. The banner keeps its promise for everything routed through the tag manager and stays silent about the pixel in the header.
Second is the category slide. A tag starts in the strictly necessary bucket, which is reasonable at the time. A vendor update adds analytics to that same script. Nobody re-reads the vendor changelog, so the tag keeps its necessary label while doing marketing work. The banner now tells visitors the script is essential when it is no longer just essential.
Third is the consent-mode gap. Sites running consent mode often rely on tags to respect the denial signal. Most do. Then one tag, added quickly for a campaign, fires in its unconsented form because nobody checked its default behavior. Everything else behaves. One tag does not. Spot checks of the banner will not catch it because the banner is fine. The tag is the problem.
Build a drift detector, not another audit
A full consent audit every quarter is good practice and not enough. Drift happens between audits. What you need is a lightweight detector that runs on a schedule and tells you when today looks different from last week. It does not need to be fancy. It needs to be consistent.
Start with a baseline inventory. Load your key pages, a homepage, a product page, a checkout or form page, in a clean browser session with the banner dismissed by rejecting everything. Record every third-party request and every cookie set. That inventory is your baseline: what a visitor who said no actually experiences on your site.
Then repeat the same scan weekly and diff the results. New third-party hosts, new cookies, or cookies appearing before the banner choice all trigger an alert. The alert does not need to be perfect. It needs to answer one question: did anything change since the last scan?
What to do when the detector fires
Treat every alert like a small incident, not a false positive. Someone changed something on purpose, and that change may be fine. The job is to route it back through consent review. Three questions resolve most alerts.
First, what is the script and why is it here? If nobody on the team can name the owner, it should not be on the site. Second, what consent category does it belong in, honestly, based on what it does today rather than what it did at launch? Third, is the blocking mechanism still catching it? If the tag was added outside the tag manager, the consent tool may need a new rule or the tag may need to move back into managed territory.
Keep a log of these resolutions. When an auditor asks how you maintain compliance, the log is your answer. It shows that consent is an ongoing process on your site, not a launch-day artifact.
Where to run the scans
Run the detector on the pages that matter, not just the homepage. Consent behavior often differs between page templates. A checkout page may load payment scripts that the homepage never touches. A blog template may load social embeds that product pages skip. Scan each distinct template.
Run the scans from the locations that matter too, if your site geolocates its banner. A banner that shows in the EU and stays hidden in the US is two different sites from a compliance perspective. Scanning only one region tells you about half the picture.
The habit that prevents most drift
Detectors catch drift. Habits prevent it. The single most effective habit is a consent review step in the change process for anything that touches the site. New plugin? It goes through consent review. New marketing tool? Consent review. Agency edits the header? Consent review. The review takes minutes when the detector provides the before and after. It takes weeks when an auditor provides it.
Banners do not decay because people are careless. They decay because websites are alive. A drift detector treats your consent setup like the living thing it is, and that is the difference between a banner you can defend and a screenshot from launch day.