Martech audit checklist: stack, data quality, consent and the records a client owns

A martech audit checklist should cover the tool inventory, adoption, integrations, data quality, consent and contracts, then add one more section: where CRM, call recording, support and content records live, how many years they cover and who controls them. That records section shows a fractional CMO whether a client may hold licensable operating history.

Why a martech audit needs a records section

A martech audit checklist should cover the tool inventory, adoption, integrations, data quality, consent and contracts, and then one thing most audits skip: the history the stack has accumulated. Where do CRM, call recording, support and content records live, how many years do they cover and who controls them?

That last section earns its place for two reasons. It protects the client, because history is easy to lose in a tool switch. And it shows whether the client might hold licensable operating records of the kind AI labs and data buyers license through SourceX. You can answer it from admin screens and contracts alone: system names, date ranges and admin ownership, never the records themselves.

The checklist

1. Stack inventory and ownership

  • List every tool: CRM, marketing automation, ad platforms, analytics, CMS, conversation intelligence, help desk, live chat, survey and enrichment tools.
  • Record a business owner and a technical admin for each.
  • Compare seats purchased with seats active in the last 90 days.
  • Capture renewal date, term length and notice period.
  • Flag tools bought on a card outside procurement.

2. Adoption and process fit

  • Map each tool to a documented process, such as lead routing, lifecycle stages or the sales handoff.
  • Identify overlapping tools doing the same job.
  • Interview two or three heavy users per tool about workarounds.

3. Integrations and data flow

  • Name the system of record for contacts, accounts and opportunities.
  • Map every sync, with its direction and frequency.
  • Find broken, duplicated or orphaned integrations.
  • Check campaign and UTM naming conventions against what is actually used.

4. Data quality

  • Estimate duplicate contacts and accounts.
  • Check that lifecycle stage and lead status definitions are written down and followed.
  • Confirm closed-lost reasons are captured consistently.
  • Turn on field history tracking for stage, owner and amount if it is off.

5. Consent, privacy and compliance

  • Locate where consent and opt-outs are stored, and confirm suppression lists sync across tools.
  • Record how people are told that calls are recorded, and in which states the client records calls.
  • Compare the privacy policy with how data is actually used, including AI features.
  • Collect the data processing agreement for each vendor.

6. Contracts and exit

  • Note export rights and formats on termination for each tool.
  • Note what each vendor deletes after cancellation, and when.
  • Read each vendor's own data use rights, including aggregated-data and AI training clauses.

7. Records and data asset section

  • CRM: the earliest record date, and whether won and lost outcomes and reasons are recorded for most opportunities.
  • Previous CRMs and marketing platforms: whether full exports still exist and who holds them.
  • Call recordings and transcripts: the retention setting, years kept and the notice used.
  • Support and help desk: when ticket history starts and whether resolution codes are used.
  • Content library: years covered, and whether the company or an agency owns it.
  • Email campaign history: how far back sends, results and creative are archived.
  • Retired tools: what happened to their data when they were switched off.
  • Control: who holds admin and export rights for each system.
  • Subject matter: whether records mostly concern businesses or consumers.
  • Size: whether the company reached 50+ full-time employees at peak (contractors excluded).

The data inventory builder can help turn section 7 into a tidy list of systems and years.

Recording and privacy rules behind sections 5 and 7

Call recordings are where marketing data most often carries legal limits. Federal law lets a person who is a party to a call, or who has one party's prior consent, record it under 18 U.S.C. 2511(2)(d). California's Penal Code section 632 prohibits recording a confidential communication without the consent of all parties, so the notice a client uses matters.

Consumer marketing lists raise separate questions. The CCPA gives California consumers the right to opt out of the sale or sharing of their personal information, one reason records that are mainly consumer personal data make weak licensing candidates.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

How to read the results

ResultWhat it meansNext action
Five or more years of CRM or support history, outcomes recorded, company-owned content, 50+ full-time employees at peakPossible fit for a licensing conversationRaise an owner-approved introduction with the CEO
Long history with gaps, such as an old CRM never exported or recordings deleted after a short windowFixable before more value is lostPreserve exports now, then revisit
Rights unclear, such as agency-produced content or client data mixed inNeeds a contract reviewHave counsel read customer and agency agreements
Mostly consumer personal dataWeak candidateKeep the audit in its marketing scope
Never reached 50+ full-time employees at peakNot eligibleDo not raise licensing

Raising it with the CEO

Present the records section as part of the audit readout, not as a separate pitch. One slide covering systems, years and owners is enough. If the CEO is interested, offer an introduction to SourceX and disclose any referral relationship in the same breath.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee; no reward is guaranteed. The fractional CMO playbook covers the rest of the referral side, and the CEO's likely first question, whether this is a real market, is answered in is AI data licensing legitimate.

Red flags in the records section

  • Contact databases built from purchased lists.
  • Call recordings made without a clear notice.
  • Content and campaign assets owned by an agency under its contract.
  • Records that salespeople imported from previous employers.
  • History padded with AI-generated content.
  • A retired platform whose data was deleted at cancellation.
  • Customer agreements that restrict use of customer information; the guide to customer contract data use restrictions explains what counsel reads.

Next step

Add section 7 to your next audit and check the result against who qualifies. When a CEO wants to explore, register as a partner and share your referral link, or have the company apply directly at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

How often should a company run a martech audit?

At least once a year, and before any major renewal, platform migration or change in marketing leadership. Annual audits keep seat counts and integrations honest. Audits before a migration matter most for the records section, because that is when history is most likely to be left behind in a system that is about to be switched off.

Who should own the martech audit?

A marketing leader, such as a fractional CMO or head of marketing operations, with a technical admin for each tool and input from sales, support and finance. The records section needs the CEO or CFO as sponsor because it touches contracts, retention decisions and any later conversation about licensing the company's history.

Does the records section require access to customer data?

No. Everything in it can be answered from admin settings, retention policies, contracts and system metadata: tool names, earliest record dates, retention windows, who holds admin rights and whether outcomes are recorded. Auditors should not open, export or describe the content of records, and anyone making a referral must never share them.

Why does CRM history with outcomes interest AI developers?

Because it shows multi-step work and how it ended. An opportunity record with stage changes, notes, emails and a won or lost result is an example of a real business process, which is what developers training AI agents need. Years of such records, linked to support and finance systems, are scarce on the public web.

Can marketing records alone make a company a licensing candidate?

Rarely on their own. SourceX looks at data breadth across many systems, such as email, chat, CRM, finance, support, engineering and operations tools, along with years of history and clear rights. Marketing systems are a useful window into that breadth. Records that are mainly consumer personal data are a weak basis for a license.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment