A marketing campaign QA checklist is the last line of defence before you commit budget — and in South Africa, it has to cover territory that most global templates skip entirely. As part of a sound digital strategy for South African businesses, pre-launch quality checks prevent POPIA consent failures, broken attribution, and audience sizing mistakes that global checklists simply were not built to catch. South Africa's digital ad market reached R17.7 billion in 2023, growing 21.5% year-on-year according to IAB South Africa — at that scale, a structured pre-launch quality check is not overhead; it is risk management.

The difference between a campaign that launches cleanly and one that burns budget on broken links, wrong segments, or non-compliant messaging usually comes down to process — not talent. This guide gives you a complete, SA-specific checklist across six check areas, built for teams running paid search, paid social, email, and marketing automation on local budgets.

Quick Answer

A marketing campaign QA checklist covers six areas before launch: legal compliance (POPIA and the CPA opt-out registry), tracking and attribution setup, creative and copy accuracy, audience targeting logic, email and automation workflow, and post-launch monitoring readiness. In South Africa, the compliance layer is non-negotiable — POPIA Section 69 requires prior opt-in consent for electronic direct marketing, and the 2026 CPA opt-out registry adds a mandatory monthly database cleanse. Running through all six areas takes under an hour and protects both your budget and your legal standing.

Not sure your campaigns pass a proper quality check?

Send us your current campaign setup and we will walk through the six check areas with you — showing you exactly where the gaps are before you spend a rand.

Get a campaign flow review

What Does a Marketing Campaign QA Checklist Cover?

A campaign QA checklist is a structured review of everything that can fail between campaign build and campaign live. It is not a creative brief or a strategy document — it is a final confirmation that what you built matches what you intended, and that the infrastructure required to measure and comply with it is in place before a single rand of budget is committed.

Six areas warrant a dedicated check for every campaign type:

Check AreaWhat It CatchesSA-Specific Risk
Legal complianceConsent gaps, missing opt-out mechanismsPOPIA Section 69, CPA opt-out registry
Tracking and attributionBroken UTMs, misfiring pixels, no conversion eventsData gaps compound fast on smaller SA audiences
Creative and copyTypos, broken links, wrong logos, mobile sizingBrand credibility in a market where trust is earned slowly
Audience and targetingWrong segments, overlapping ad sets, excluded lists missingSA audiences are smaller — over-spend exhausts them quickly
Email and automationPersonalization token failures, wrong send lists, deliverabilityPOPIA consent validation on every list
Post-launch readinessNo alert thresholds, no review schedule, no escalation ownerLoad-shedding disrupts real-time monitoring windows

Tracking errors account for a significant share of wasted ad spend globally — campaigns commonly launch without complete UTM markup in place, meaning attribution data is corrupted from the moment spend activates. In a market where Google Analytics 4 is the measurement backbone for most SA businesses, broken attribution is not a minor inconvenience; it means the algorithm optimises toward phantom signals and you cannot see it happening.

South African marketing campaigns face a compliance layer that most global QA checklists treat as a single tick box. It is not. Three distinct legal requirements now govern direct marketing in South Africa, and they apply sequentially — not interchangeably.

The three SA compliance checks before any campaign sends

  1. POPIA Section 69 consent: Electronic direct marketing — email, SMS, automated calls — requires prior opt-in consent, or the recipient must be an existing customer contacted about closely related goods or services. This was tightened by the April 2025 POPIA regulation amendments. Every list must be validated against documented consent records before use.
  2. CPA opt-out registry: The CPA opt-out registry is phasing in during 2026; once operative, it requires monthly database cleansing against the national opt-out list and registration with the National Consumer Commission. Prior opt-in consent does not override a subsequent registry block — a critical distinction when reusing lists built before the registry came into force. Verify the current implementation status with a POPIA-qualified adviser before your next campaign activation.
  3. Unsubscribe and sender identification: Every campaign message must clearly identify the sender and include a functional opt-out mechanism. Under POPIA, these are not best practices — they are legal requirements, and the Information Regulator's 2024–2026 enforcement has shifted to testing whether opt-outs actually work, not just whether they exist.

For POPIA guidance specific to first-party data strategy and POPIA compliance, and for cookie consent and analytics requirements, those posts go deeper into the technical implementation. For campaign QA, the practical check is simpler: before any send or activation, can you produce a timestamp, channel, and consent wording for every contact on the list? If not, the campaign does not launch.

Key takeaway: SA legal QA is a launch gate, not a suggestion

POPIA and the CPA opt-out registry are not equivalent to GDPR or CAN-SPAM — the consent requirements are stricter for electronic channels. Building this check into your standard campaign QA process, rather than treating it as a one-time compliance project, is the only operationally sustainable approach.

Tracking and Attribution Checks

Tracking failures are the most expensive pre-launch oversight because they are invisible until it is too late — the campaign runs, the budget spends, and the data that comes back is untrustworthy. For UTM tracking and conversion measurement, a pre-launch check takes under 15 minutes and protects every Rand of reporting integrity.

Work through this sequence before every campaign activation:

Tracking QA that passes:
✓ UTM parameters follow your naming convention exactly — including capitalisation (Rank Math and GA4 treat "Facebook" and "facebook" as different sources)
✓ Every destination URL resolves — click through manually, do not rely on a preview
✓ Conversion events fire in GA4 or your measurement tool — use a test conversion and confirm it appears in the reports
✓ Meta Pixel and Google Tag are confirmed live on the landing page before spend activates
✓ POPIA-compliant cookie consent is in place on the landing page — tracking must only fire after consent for non-essential cookies
✓ Attribution window matches your reporting setup — a 7-day click window in Meta and a 30-day window in your CRM produce irreconcilable numbers unless you account for it

Tracking QA that fails:
✗ UTM source is "fb" in one campaign and "facebook" in another — your GA4 report now shows the same channel as two separate sources
✗ The landing page redirects to a different URL and the UTM parameters are stripped in the redirect
✗ No conversion event is configured — you will see clicks but the platform optimises toward nothing
✗ Cookie consent blocks the pixel on load but nobody checked whether GA4 fires correctly in consent-denied state

The first-party data tracking guide covers server-side tagging options for South African businesses navigating the 30–40% of attribution data stripped by browser tracking prevention and ad blockers.

Creative, Copy and Asset Checks

A campaign with perfect tracking and full consent compliance still fails if the creative is wrong. Creative QA is the check most teams rush — usually because it arrives last in the production queue. The checklist is short but the consequences of skipping it are not.

For every asset in the campaign, confirm:

  • Headline and offer match — what the ad promises and what the landing page delivers must be the same claim, not a close variation. Message mismatch is the single biggest driver of high bounce rates on paid campaigns.
  • Legal copy is accurate — South African consumer-facing ads must comply with the Consumer Protection Act. Price claims, "free" offers, and comparative advertising have specific requirements.
  • All links resolve correctly — a subscriber who clicks a CTA and hits a 404 page does not just miss the offer; they lose confidence in the brand. Test every link, including social share buttons and unsubscribe links in email.
  • Image dimensions match platform specs — Meta, Google Display, and TikTok each have specific aspect ratio and file size requirements. An asset that renders correctly in Canva may be cropped automatically on mobile.
  • Mobile rendering is tested — the large majority of South African internet access is mobile. Test on a physical device, not just a desktop preview; what renders correctly in a browser window often breaks on a handset screen.
  • Brand elements are the approved versions — logo, brand colours, and font. This is especially important for campaigns using assets from multiple team members or agencies.

Key takeaway: creative QA is a two-person job

The person who built the creative is the least reliable reviewer — familiarity creates blind spots. Assign a second person to click through every link, read every word, and view the campaign on a mobile device before sign-off. This costs 20 minutes and prevents the kind of error that requires a retraction.

Audience and Targeting Checks

Audience and targeting checks confirm segment logic, exclusion lists, and budget-to-audience sizing before activation — errors are harder to recover from in South Africa's smaller addressable pools than in larger markets, where a misconfigured segment simply costs more money. Here, it can exhaust the audience entirely before the campaign has time to optimise.

Before launching any paid campaign, verify:

  • Segment logic produces the expected count — pull the estimated audience size in Meta Ads Manager or Google Ads and check it against your planning assumption. A segment that should reach 50,000 people but returns 5,000 has a logic error somewhere.
  • Exclusion lists are applied — existing customers should be excluded from acquisition campaigns. Recent purchasers should be excluded from re-engagement flows. These exclusions are your first line of budget protection.
  • Lookalike seed quality is confirmed — a lookalike audience built from an uncleaned list (including inactive contacts, bounces, and non-consented records) models on noise. Confirm the seed list was cleansed before building the lookalike.
  • Ad set frequency caps are set for retargeting — without frequency caps on retargeting campaigns, the same person can see the same creative dozens of times in a week. This is wasteful and damages brand perception.
  • Campaign budget is right-sized for the audience — as a practical heuristic, a daily budget that can reach the entire target audience within 48 hours suggests the budget is too high for the audience size, or the audience is too small for the budget.

For context on how to set SA-specific marketing goals and KPIs that audience sizing decisions need to map back to, that post goes deeper into the planning layer that feeds campaign design.

Unsure whether your budget fits your audience size?

Tell us your campaign objective, target audience, and monthly budget, and we will give you a straight assessment of whether the numbers are structurally sound for the SA market.

Book a campaign fit assessment

Email and Automation Pre-Send Checks

Email and automation pre-send checks cover sender authentication (SPF, DKIM, DMARC), personalization token fallbacks, send-list accuracy, and POPIA consent validation for every contact — all of which are invisible until after the send and expensive to recover from.

Run through these checks with a test send before activating any email campaign:

Email pre-send QA that passes:
✓ Test email sent to a real inbox — check rendering in mobile and desktop clients
✓ Personalization tokens tested with a contact that has complete data AND one with missing fields — confirm fallback text appears correctly when a field is blank
✓ Unsubscribe link works and processes immediately
✓ Sender authentication confirmed — SPF, DKIM, and DMARC records are aligned for the sending domain
✓ Send list confirmed — not the segment used for a previous test send, not a placeholder list from a draft
✓ Automation workflow logic stepped through manually — every branch, every wait step, every exit condition
✓ POPIA consent validated for every contact on the send list

Personalization errors — where a contact sees "Hello [First Name]" instead of their actual name — are a leading cause of unsubscribes and spam complaints. Test every token with an incomplete record to confirm the fallback is in place. For campaigns running on Klaviyo, Omnisend, or ActiveCampaign in South Africa, each platform has a preview mode for incomplete records — use it on every send.

Sender authentication (SPF, DKIM, DMARC) is a consequential deliverability factor that many teams treat as optional. Gmail and Outlook increasingly route unauthenticated sends to spam — a global policy that affects any domain without proper authentication records, regardless of where the sender is based. This check takes 30 seconds in your DNS or email platform and protects deliverability for the entire list.

Post-Launch Monitoring: The First 48 Hours

A campaign QA checklist does not end at launch. The first 48 hours require active monitoring to catch errors that only appear under live conditions — budget pacing anomalies, conversion tracking failures at scale, and audience exhaustion signals that a test run could not surface.

Set up these monitoring checks before launch so they are in place when the campaign activates:

  • Budget pacing alert — set a notification for significant overspend against daily planned budget within the first 24 hours. Overspend on day one is usually a bidding strategy or audience error, not an algorithm decision to be waited out.
  • Conversion check at 24 hours — if a campaign has run for 24 hours and recorded zero conversions, the conversion event is either not firing or the campaign is not reaching the right people. Both need immediate investigation.
  • Search term review (Google Ads) — within 24 hours of a search campaign going live, review the search terms report for irrelevant queries. Negative keywords that seemed sufficient in planning often miss the specific local search patterns South African users produce.
  • Frequency check at 48 hours (social) — as a working rule of thumb, if frequency climbs above 2 to 3 within 48 hours on a Meta campaign, the audience is likely too small for the budget or the campaign is running at too high an intensity. Adjust before creative fatigue compounds the problem.
  • Load-shedding schedule awareness — South African campaign managers should check the load-shedding schedule for launch week. Anecdotally, mobile conversion rates deteriorate during Stage 4+ outages as connectivity and device availability drop — build a 24–48-hour buffer into launch timing when significant load-shedding is forecast rather than launching into a known disruption window.

Key takeaway: build post-launch monitoring into the QA checklist itself

A quality assurance process that ends at launch leaves half the risk on the table. The first 48 hours are when tracking failures, budget anomalies, and audience exhaustion signals surface — and catching them early determines whether you correct a manageable error or write off a campaign. Set monitoring alerts before launch, not after the first sign of trouble.

For a structured review process after a campaign ends, the marketing campaign post-mortem template gives you the framework to capture what worked and where the QA process can improve for the next run. And for marketing automation pricing in South Africa, that post covers what it costs to set up and maintain the tools that make campaign QA systematic rather than manual.

Why South African Businesses Choose Growth Pulse Media

Most campaign errors happen not because the marketing team is careless but because quality assurance is treated as a single person's responsibility rather than a built-in process. At Growth Pulse Media, every campaign that goes live through our digital strategy service runs through a documented QA protocol before activation — covering the compliance, tracking, creative, audience, and monitoring layers described above.

Dirk built and scaled a South African ecommerce business before founding GPM. He paid for the broken UTMs, the misfiring pixels, and the campaigns that spent on wrong audiences. The QA process we use is built from real SA campaign failures — not a global template adapted for local use. We work with a deliberately limited number of clients so that senior attention is available at each campaign launch, not just at the strategy stage.

We run campaigns across Meta, Google, TikTok, email platforms including Klaviyo and Omnisend, and marketing automation setups integrated with local CRM systems. Every platform has its own QA requirements, and we know where each one creates SA-specific failure points — from Meta's audience size thresholds that behave differently against the local population, to the load-shedding timing adjustments that affect campaign pacing windows.

Who This Checklist Is NOT For

Teams that prefer to move fast and fix it later
If your standard process is to launch, catch errors under live conditions, and issue corrections — this checklist will slow you down. It is designed for teams who accept that a 45-minute pre-launch review is faster than the 3-day recovery from a compliance complaint or a mis-attributed month of ad spend.

Businesses running campaigns without a measurement setup
A campaign QA checklist assumes you have conversion tracking, a CRM or email platform, and a way to review results. If you are running campaigns without any of these in place, the checklist is not your first problem. The tracking infrastructure needs to exist before QA of that infrastructure has any meaning.

Teams with no designated QA owner
Quality assurance requires someone accountable for the final sign-off before launch. If every team member assumes someone else has reviewed the campaign, nobody has reviewed the campaign. The checklist only works if there is a named person who owns the final pass.

Marketers using purchased or unverified third-party lists
Under POPIA, sending to a purchased list without documented consent for electronic direct marketing is non-compliant regardless of how carefully you complete the rest of this checklist. A campaign QA process cannot make a non-compliant list safe to use — the consent problem must be resolved before any send.

Ready to build a QA process your whole team can run?

We will audit your current pre-launch process and identify the specific gaps — then show you how to close them without adding hours to every campaign build.

Request a pre-launch process audit

Frequently Asked Questions

How long should a marketing campaign QA checklist take to complete?

As a working rule of thumb, a routine campaign — single channel, single audience segment, standard email or paid ad — takes 30 to 45 minutes to work through all six check areas. Complex multi-channel campaigns with automation logic, multiple audience segments, and localised creative versions warrant two to three hours for a thorough QA pass. The time investment is front-loaded: catching a broken UTM or a POPIA consent gap before launch costs minutes; catching it after launch costs days and potentially Rand spent on wasted traffic.

What is the most common failure point in a South African campaign launch?

Based on campaign patterns in the SA market, the most common failure points are broken or inconsistent UTM parameters (which corrupt attribution data from day one) and missing or incomplete POPIA consent documentation on the contact list. Both are preventable with a pre-launch check, and both are invisible in the campaign interface — you have to deliberately look for them. Audience size miscalculation — targeting too narrowly for a campaign budget — is the third most common, and it tends to show up as high frequency and deteriorating CPAs within the first 48 hours.

Does a marketing campaign QA checklist need to include a POPIA check at each launch?

Yes — for each send or list activation. Consent can be withdrawn at any point, and under the 2026 CPA opt-out registry framework, a contact who opts out via the national registry creates a legal block even if they previously gave explicit consent to your specific business. Running a compliance check only at list creation and not at campaign activation is a legal gap. The check itself is quick — it is a confirmation that your consent records are current and that the list has been cleansed against the opt-out registry since the registry came into force.

What should I do if I find an error after the campaign has already launched?

Pause the campaign immediately and fix the specific error before reactivating. For tracking errors (broken UTMs, misfiring pixels), document the gap period and flag it in your reporting so results from that window are not treated as accurate data. For compliance errors — sending to a contact who should have been excluded — consult with a POPIA-qualified legal adviser before continuing. The Information Regulator's enforcement focus has shifted to functional compliance verification, and a documented corrective action taken promptly is treated more favourably than a correction made only after a complaint is lodged.

Is a marketing campaign QA checklist different for email versus paid ads?

The six check areas apply to both, but the specific items within each area differ. For email: the critical checks are sender authentication (SPF, DKIM, DMARC), personalization token fallbacks, and list consent validation. For paid ads: the critical checks are pixel and conversion event verification, UTM parameter consistency, and audience exclusion logic. The legal compliance layer — POPIA and the CPA registry — is mandatory for electronic direct marketing across all channels, so it applies equally to email campaigns, SMS, and any paid channel that uses custom audiences built from first-party contact data.

Launch Your Next Campaign Without the Guesswork

We review your campaign setup across tracking, compliance, creative, and audience — and show you exactly what needs fixing before you spend a rand. Our team works with Meta, Google, Klaviyo, Omnisend, and the SA-specific compliance requirements that most checklists miss. No obligation — we will get back to you within 24 hours.

Get your campaign reviewed
Dirk van Greuning — Founder, Growth Pulse Media
Dirk van Greuning Founder, Growth Pulse Media

Founder of Growth Pulse Media and a specialist in South African search dominance. Dirk translates his experience in scaling South African businesses into high-velocity digital strategies for B2B and retail leaders. He writes about SEO, lead generation, and paid media from an operator's perspective — prioritising pipeline value over impressions.

Connect on LinkedIn