CRM Health Checklist: Can You Trust Your Data?
By CodexierPublished 7 min read
Every CRM starts clean and drifts. Two records for the same company, deals that have been "in negotiation" since last spring, a field called Source with forty spellings of "website". The forecast stops being believed, and once it is not believed, people stop updating it. This checklist finds the rot in an afternoon and gives you a routine that keeps it from coming back. It applies to HubSpot, Pipedrive, Salesforce and most others.
Duplicates and merges
Duplicates are created by good intentions: a colleague adds a contact from a business card without searching, a form integration creates a new company because the name was typed differently, an import brings in a list that overlaps the existing base. Swedish companies have a reliable key that most CRMs ignore: the organisation number. Add it as a field, fill it from Bolagsverket data where you can, and match on it before creating anything. For contacts, the email address is the key. Run your CRM's duplicate tool, then merge with the rule that the record with the most activity survives and the other's data is folded in, never deleted outright.
Stale deals and pipelines
A pipeline is only a forecast if the deals in it are alive. Sort all open deals by last activity date. Anything older than your longest realistic sales cycle is not a deal; it is a hope, and it inflates every number derived from the pipeline. Close it as lost with a reason, or move it to a nurture stage that is excluded from forecasts. Then look at the stages themselves: if there are more than six, or if nobody can say what has to be true for a deal to move from one to the next, the stages are decoration. Write a one-line exit criterion for each.
| Check | How to find it | Fix |
|---|---|---|
| Deals with no activity beyond the sales cycle | Filter open deals by last activity date | Close-lost with reason, or move to nurture |
| Deals with no close date or a date in the past | Filter on close date | Set a real date or close the deal |
| Deals with no amount | Filter on empty amount | Estimate or mark as unqualified |
| Stages with undefined exit criteria | Ask two sales people what stage three means | Write one sentence per stage; remove unused stages |
| Won deals with no linked company | Report on won deals grouped by company | Link them; they feed customer lifetime value |
Do this before any pipeline review meeting. A meeting spent arguing about dead deals is the most expensive form of data cleaning.
Required fields and definitions
Field bloat is the quiet killer. Each new report or integration adds a field, nobody removes one, and after two years the contact form has sixty fields of which eight are filled in. Export the field list with fill rates. Anything below a low fill rate and not used in a report, a workflow or an integration gets archived. For the fields that remain, decide three things: is it required, is it free text or a pick-list, and what does each value mean. Free text fields such as Industry or Source are the source of most reporting failures; convert them to pick-lists with a short, agreed set of values and map the old text onto them once.
- Required at creation: company name, organisation number, owner, source, lifecycle stage.
- Required to move a deal past qualification: amount, expected close date, decision maker contact.
- Pick-lists, not free text: source, industry, deal type, lost reason.
- A one-page data dictionary that says what each stage and value means, linked from the CRM's home screen.
Ownership and permissions
Records owned by people who left the company are invisible in everyone's views and never followed up. Run a report of records by owner and reassign anything belonging to former staff. Then check the permission model against the roles people actually have today. Sales should not be able to delete companies; marketing should not see deal amounts if that is not their job; the integration user should have exactly the rights the integration needs. Under GDPR, permissions are also a security measure: personal data should be reachable only by those who need it, and your CRM's access log is what you will be asked for if something leaks.
One owner per record
Companies, contacts and deals each have exactly one owner who is currently employed. Team queues are fine for unassigned leads, not for active deals.
Roles, not people
Permissions are set per role and people are assigned to roles. When someone changes job, you change their role, not thirty settings.
Integration users
Each integration has its own user with minimum rights, so a leaked API key cannot export everything and so you can see what each system changed.
Deletion and retention
Contacts with no activity for years and no active relationship are personal data you have no basis to keep. Decide a retention period and enforce it.
A quarterly clean-up routine
The checklist above is a reset. What keeps a CRM trustworthy is a short routine, run every quarter by a named person, taking half a day. Put it in the calendar with the steps written out, and report the numbers afterwards so the team sees the effect.
- Run the duplicate tool for companies and contacts; merge or dismiss every suggestion.
- Close or move all deals with no activity past the sales cycle; note the count.
- Check fill rates for required fields; chase the owners of records missing them.
- Reassign records from anyone who left; review permissions for anyone who changed role.
- Archive fields nobody used this quarter; update the data dictionary.
- Delete or anonymise contacts past the retention period.
- Spot-check five records from each integration for correct mapping.
When you do not need any of this: a team of two with a hundred contacts can keep a CRM clean by habit, and a spreadsheet may honestly be enough. Where a CRM setup and integration audit earns its fee is when several systems write into the CRM, when the pipeline drives hiring or cash decisions, or when nobody in the company owns the data model. If the integrations are the source of the mess, start with APIs explained for business owners to see why. Which situation you are in is a short call.
- CRM setup and integration auditWe run this checklist against your CRM, fix the structure and hand you the quarterly routine.
- CRM implementationWhen the honest answer is that the CRM needs to be set up again properly.
- Book a free 15-minute callTell us which CRM you run and what nobody trusts in it; we say where to start.
Frequently asked questions
How often should we clean the CRM?
A structural reset once, using the checklist above, then a half-day routine every quarter. Duplicate prevention, required fields and pick-lists do most of the work between routines, so the quarterly pass stays short.
Should we delete old contacts?
Contacts with no activity and no relationship for a long period are personal data you probably have no legal basis to keep under GDPR. Decide a retention period, anonymise or delete past it, and make it part of the quarterly routine. Keep what accounting law requires in the accounting system, not the CRM.
Which fields should be required?
Only the ones that drive a report, a workflow or an integration. Typically company name, organisation number, owner, source and lifecycle stage at creation, and amount plus close date before a deal leaves qualification. Every extra required field lowers the chance that people create records at all.
Our integrations keep creating duplicates. What do we do?
Give each integration a unique key to match on, usually email for contacts and organisation number or domain for companies, and configure it to update rather than create when a match exists. If the integration cannot do that, put a deduplication step in between. This is the most common finding in our audits.
Want the checklist run for you, with the routine handed over?
Fifteen minutes with an engineer: tell us which CRM you use and what the team stopped trusting, and we say whether a clean-up, an audit or a fresh setup is the right next step.
Book a free 15-minute call