Skip to content

Google Ads governance & compliance security checks

Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.

On Google Ads, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Ads connector needs.

Checks (7)

severity: medium Account Budget Without End Date fix difficulty: easy #

Set an end date on all Google Ads account budgets to prevent uncapped spend

  1. Sign in to Google Ads and navigate to Tools & Settings > Billing > Account Budget
  2. Identify budgets without an end date
  3. Click Edit on each budget and set an appropriate end date or spending limit
  4. Review budget amounts to ensure they align with approved marketing spend
  5. Save changes and set up budget alerts for proactive monitoring

Vendor docs ↗

severity: high Budget Without Spending Limit fix difficulty: easy #

Set a spending limit on all Google Ads account budgets to cap maximum spend

  1. Navigate to Tools & Settings > Billing > Account Budget
  2. Identify budgets without a spending limit
  3. Click Edit on each budget and set a total spending limit aligned with approved marketing spend
  4. Enable billing threshold alerts to receive notifications when spend approaches the limit
  5. Review and approve all budget changes with the finance team
  6. Save changes

Vendor docs ↗

severity: high Billing Setup Pending fix difficulty: easy #

Resolve the pending billing setup to ensure payment authorization is in place before ad spend occurs

  1. Navigate to Tools & Settings > Billing > Settings
  2. Locate the billing setup showing a PENDING status
  3. Complete the payment verification steps requested by Google Ads
  4. Confirm a valid payment method is linked and approved
  5. Contact Google Ads support if the pending state persists after completing verification

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Canceled Account in MCC Hierarchy fix difficulty: easy #

Remove cancelled accounts from the MCC hierarchy to keep the account structure clean and avoid confusion

  1. Navigate to the MCC manager account in Google Ads
  2. Go to Accounts > Overview and locate the cancelled account
  3. Confirm that the account is no longer needed and all campaigns have been archived or migrated
  4. Unlink the cancelled account from the MCC via Account settings > Unlink
  5. Document the removal in your change management system

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC8.1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: high Billing Setup Without Payments Account fix difficulty: easy #

Link a valid payments account to the billing setup to ensure all ad spend is properly tracked and billed

  1. Navigate to Tools & Settings > Billing > Settings
  2. Locate the billing setup that has no linked payments account
  3. Click Edit and associate the correct Google payments account
  4. Confirm the payments account has a valid payment method (credit card, bank account, or invoicing)
  5. Save the changes and verify the billing setup status transitions to APPROVED
  6. Set up billing threshold alerts to receive notifications when spend approaches defined limits

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Cancelled Billing Setup fix difficulty: easy #

Review cancelled billing setups and clean up stale billing configurations

  1. Navigate to Tools & Settings > Billing & Payments
  2. Locate the cancelled billing setup identified in the finding
  3. Determine why the billing setup was cancelled
  4. If the account still needs billing, create a new billing setup with a valid payment method
  5. If the account is no longer in use, consider closing the account
  6. Document the billing change for financial audit purposes

Vendor docs ↗

severity: low Pending Account Budget fix difficulty: easy #

Review and approve or reject pending account budgets

  1. Navigate to Tools & Settings > Billing & Payments > Account Budgets
  2. Locate the budget in pending status
  3. Review the budget amount, period, and requesting party
  4. Approve the budget if it aligns with planned spending
  5. Reject or modify the budget if it does not meet approval criteria
  6. Document the approval decision

Vendor docs ↗

More Google Ads checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial