Google Ads governance & compliance security checks
Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.
On Google Ads, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Ads connector needs.
Checks (7)
severity: medium Account Budget Without End Date fix difficulty: easy #
Set an end date on all Google Ads account budgets to prevent uncapped spend
- Sign in to Google Ads and navigate to Tools & Settings > Billing > Account Budget
- Identify budgets without an end date
- Click Edit on each budget and set an appropriate end date or spending limit
- Review budget amounts to ensure they align with approved marketing spend
- Save changes and set up budget alerts for proactive monitoring
severity: high Budget Without Spending Limit fix difficulty: easy #
Set a spending limit on all Google Ads account budgets to cap maximum spend
- Navigate to Tools & Settings > Billing > Account Budget
- Identify budgets without a spending limit
- Click Edit on each budget and set a total spending limit aligned with approved marketing spend
- Enable billing threshold alerts to receive notifications when spend approaches the limit
- Review and approve all budget changes with the finance team
- Save changes
severity: high Billing Setup Pending fix difficulty: easy #
Resolve the pending billing setup to ensure payment authorization is in place before ad spend occurs
- Navigate to Tools & Settings > Billing > Settings
- Locate the billing setup showing a PENDING status
- Complete the payment verification steps requested by Google Ads
- Confirm a valid payment method is linked and approved
- Contact Google Ads support if the pending state persists after completing verification
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Canceled Account in MCC Hierarchy fix difficulty: easy #
Remove cancelled accounts from the MCC hierarchy to keep the account structure clean and avoid confusion
- Navigate to the MCC manager account in Google Ads
- Go to Accounts > Overview and locate the cancelled account
- Confirm that the account is no longer needed and all campaigns have been archived or migrated
- Unlink the cancelled account from the MCC via Account settings > Unlink
- Document the removal in your change management system
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC8.1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: high Billing Setup Without Payments Account fix difficulty: easy #
Link a valid payments account to the billing setup to ensure all ad spend is properly tracked and billed
- Navigate to Tools & Settings > Billing > Settings
- Locate the billing setup that has no linked payments account
- Click Edit and associate the correct Google payments account
- Confirm the payments account has a valid payment method (credit card, bank account, or invoicing)
- Save the changes and verify the billing setup status transitions to APPROVED
- Set up billing threshold alerts to receive notifications when spend approaches defined limits
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Cancelled Billing Setup fix difficulty: easy #
Review cancelled billing setups and clean up stale billing configurations
- Navigate to Tools & Settings > Billing & Payments
- Locate the cancelled billing setup identified in the finding
- Determine why the billing setup was cancelled
- If the account still needs billing, create a new billing setup with a valid payment method
- If the account is no longer in use, consider closing the account
- Document the billing change for financial audit purposes
severity: low Pending Account Budget fix difficulty: easy #
Review and approve or reject pending account budgets
- Navigate to Tools & Settings > Billing & Payments > Account Budgets
- Locate the budget in pending status
- Review the budget amount, period, and requesting party
- Approve the budget if it aligns with planned spending
- Reject or modify the budget if it does not meet approval criteria
- Document the approval decision