Every Marketo instance I've audited has looked different on the surface — different naming conventions, different program structures, different levels of chaos. But the underlying checklist is almost always the same eight areas. If you want to run your own first-pass audit before bringing someone in, start here.

1. Database Health

Pull your bounce rate, your hard-bounce list, and your duplicate count first. Then look at how many contacts haven't opened, clicked, or engaged with anything in 12+ months. That number — the percentage of your database that's actually marketable, not just present — is often the single most revealing metric in the whole audit.

2. Lifecycle Stage Definitions

Ask three people on your team to define "MQL" without looking anything up. If you get three different answers, your lifecycle has drifted from what's actually written in your smart campaigns. Map every lifecycle stage back to its Marketo logic and confirm they still match.

3. Lead Scoring

Pull a sample of your highest-scored leads from the last quarter and check what sales actually did with them. If your top-scored leads aren't converting to opportunities at a meaningfully higher rate than your average lead, the model isn't reflecting real buying intent anymore.

What usually causes scoring drift

4. Programs & Smart Campaigns

Export your full program list and sort by last-activated date. Anything untouched in over a year is a candidate for archiving. While you're in there, check for smart campaigns with overlapping trigger logic — these are the quiet cause of duplicate emails and confused contacts.

5. Salesforce Integration

Check your sync error queue. Most teams are surprised how many records are silently failing to sync. Then confirm your field mappings still make sense — fields get added on the Salesforce side constantly, and Marketo mapping is rarely revisited to match.

6. Compliance & Deliverability

Confirm your subscription center actually unsubscribes people from everything it should, that you're honoring GDPR and CASL consent requirements where applicable, and that your sending domain authentication (SPF, DKIM, DMARC) is correctly configured. Deliverability problems are almost always compliance problems wearing a different hat.

7. Reporting & Attribution

Pick three numbers your leadership team looks at regularly and manually verify them against raw Salesforce data. If the dashboard and the source data disagree, you've found where trust in your reporting is quietly breaking down.

8. Governance

Is there a documented process for who can build a new program, and how? If the answer is "whoever needs one, however they want," that's not a criticism — it's just where most instances start. It's also exactly what turns into the mess the next person has to audit.

What to do with what you find

Write it down, even the small stuff. A findings list with rough severity ratings is more useful than a mental list of "things that feel off." If the list gets long, or you're not sure how to prioritize it, that's the point where an outside audit usually pays for itself.