An AI visibility and GEO audit should show where your business appears, whether those answers describe it accurately, which website or external-information problems can be demonstrated, and what to fix first. You should receive the evidence behind the conclusions and a practical action plan, not just a visibility score.
Before buying an audit, agree the services, locations, languages, platforms and pages being assessed. A public website scan, a small answer sample and an investigation with analytics and Search Console access are different products. A useful report makes its coverage and limits clear enough for another person to act on it.
Start with the decision the audit must support
Define the commercial problem before selecting tools. A business might need to understand whether its priority service is missing from relevant recommendations, whether AI answers quote obsolete terms, or whether a redesigned website has lost accessible service information.
Those questions need different evidence. For a Dubai business with several branches, the audit may need branch-level checks rather than one company-wide score. Where English and Arabic pages serve different audiences, confirm that both contain the correct current offer. A page for Dubai-wide delivery should not be treated as equivalent to a branch available only for collection.
The brief should specify:
- Priority services, customer types and actual service areas.
- Included languages, platforms and consumer or API testing methods.
- The pages and question groups to sample, including how repetitions and failures will be handled.
- Required account access, who supplies it and what remains publicly assessable without it.
- Deliverables, implementation exclusions and any included follow-up checks.
Use authorised account access rather than sending passwords. The auditor should state when a finding depends on information the business has not yet supplied.
Request evidence across six areas
| Audit area | Evidence to request | Decision it should support |
|---|---|---|
| Observed AI answers | Exact questions, dated answers, conditions and supporting URLs | Which commercially relevant appearances or errors need attention? |
| Technical access | Findings for named priority pages and platform-specific controls | Is there a demonstrated access or eligibility problem? |
| Business information and content | Current approved facts and buyer questions mapped to actual pages | Which facts or pages need correction, improvement or creation? |
| External sources | Relevant profiles, listings or cited pages inspected directly | Which independent or third-party information needs investigation? |
| Measurement | Available reporting, definitions and identified gaps | What can be measured, and what access or setup is missing? |
| Prioritised findings and handoff | Actions, owners, dependencies and completion checks | What should be implemented first, and how will it be accepted? |
This is a recommended buying framework, not an official certification standard. The depth should match the business question and agreed scope.
1. A retained sample of actual AI answers
The report should preserve the questions, full answers, platform or mode, date, language and known testing conditions. It should identify where your business was mentioned, positively recommended, cited through its own website, or described incorrectly. Those outcomes are not interchangeable.
Ask how questions were selected. If every prompt includes your company name, the audit tests branded recognition, not whether customers discover you unprompted. Competitors should be assessed on comparable questions, not on a separate set chosen to make your results look worse or better.
A failed collection attempt should remain visible. So should a valid answer that names no suitable business. A percentage needs its question count, usable-answer denominator and collection limits beside it.
The auditor should inspect cited pages to see whether they support the relevant statement. A source list is not a complete explanation of the system's private selection process. An absence from a few answers establishes an observation, not its cause.
2. Technical checks tied to the correct platform
A technical finding should identify the affected URL, test date, observed behaviour and relevant control. Checking only the homepage cannot establish that every important service page is accessible.
For ChatGPT Search, distinguish OAI-SearchBot from GPTBot, which concerns potential model training. A recommendation to “allow all AI bots” ignores that these settings serve different purposes. OpenAI's crawler documentation.
For Google's AI Search features, inspect index and snippet eligibility as well as the effective Search generative AI setting, including inherited settings where relevant. Record the actual state rather than assuming every business must manually enrol. Eligibility does not guarantee appearance. Google's AI Search guidance and Search generative AI control.
Where the investigation includes hosting or security restrictions, request the relevant response evidence. A crawler name in a log does not by itself establish a successful page retrieval or a citation.
If Search Console access was unavailable, the correct report entry is not verified, with the required next check. It should not become a green tick or a confirmed failure.
3. Current business facts and useful content
The audit should compare public claims with a current factual reference approved by the business. Check trading names, branches, service areas, contact details, availability and commercial terms relevant to the questions being tested.
Then ask whether the website actually helps the customer choose. A list of missing keywords is less useful than identifying that a service page omits a material limitation, an essential comparison or evidence supporting a claimed capability.
Recommendations should say whether to improve an existing page, merge overlapping pages or create something genuinely missing. Do not accept automatic instructions to create a new article for every prompt variation.
Where structured data is assessed, check it against visible, current page content. Google's guidelines reject misleading markup and information that does not represent the page. A technically valid schema test is not evidence that an AI assistant will recommend the business. Google's structured-data guidelines.
4. Relevant external information
Inspect sources connected to the actual business and observed answers: important business profiles, specialist directories, publications and other relevant pages. A spreadsheet of every possible directory is not a substitute for explaining why a specific source matters.
Separate an inaccurate listing from a proposed opportunity for additional coverage. Also distinguish a business-controlled profile from an independent editorial page. The owner may be able to edit the former but only request a correction to the latter.
If the auditor recommends “more authority”, ask what evidence is missing, which customer decision it affects and what legitimate action is proposed. Do not treat a paid listing, a review count or a competitor's citation as proof of a universal AI ranking formula.
5. Measurement that matches available access
The audit should establish what can currently be measured and where the gaps are. That may include dated answer samples, available native search reporting, identifiable assistant referrals and tested enquiry tracking.
Keep these units separate. A screenshot of an AI recommendation cannot validate a claimed number of leads. Equally, an empty report or missing account access does not prove that the business has never appeared anywhere in AI Search.
The measurement handoff should name the report or dataset, its period, definitions and owner. Detailed tracking implementation may be a separate task; the audit should identify the dependency clearly.
6. Prioritised findings someone can implement
Each important finding needs an affected asset, evidence, business consequence, proposed action, responsible owner and a check for completion. Label a confirmed defect separately from an observation or a hypothesis.
Prioritise according to demonstrated harm, commercial relevance, confidence, effort and dependencies. A wrong branch address can misdirect customers today. A proposed wording experiment may be worth testing, but it should not outrank that correction merely because a tool assigns it a larger score.
What a useful finding looks like
Consider a hypothetical Dubai event-catering business. Its English service page gives the current minimum order, while the Arabic page still gives an old minimum. An observed AI answer cites the Arabic page and repeats the old term.
Evidence: retain both page URLs, the conflicting passages, capture dates, the exact AI question and answer, and the business-approved current minimum. Without the approved reference, the discrepancy is confirmed but which term is correct remains unresolved.
Conclusion: the public information is inconsistent and the sampled answer repeats the outdated term. This does not prove that the discrepancy caused the business to be omitted from other recommendations.
Action: correct the Arabic page using the approved offer, review dependent downloadable menus and identify other pages carrying the same obsolete term.
Responsibility: operations confirms the term, an Arabic content reviewer checks the wording, and the authorised publisher updates the affected assets.
Acceptance: the corrected live pages and documents match the approved offer, with the changes checked and dated. A later AI-answer retest records whether the old term still appears. The website correction can be complete even if an external system has not yet reflected it.
That distinction prevents two bad outcomes: accepting an unimplemented recommendation as finished, or withholding acceptance of a real correction until an independent platform gives a preferred answer.
Agree what happens after the report
Before accepting delivery, check that another person can locate the evidence, understand the priorities and start the first agreed task. Request a walkthrough of unresolved findings and confirm which fixes require content approval, development, profile access or third-party cooperation.
Keep the audit, implementation and recurring monitoring distinct in the proposal. An audit can identify work without including every correction. A follow-up check should specify what will be retested, rather than promising a particular recommendation or score increase.
Lunasol offers a free manual AI visibility audit covering current visibility, competitors appearing and recommended next steps. Use it to discuss the business questions that matter. If you need the deeper technical, content or measurement investigation described here, agree that scope and the subsequent implementation responsibilities explicitly. The value is a clear route from evidence to useful work.
