Most lists of banner requirements restate principles. Principles are hard to act on, because the gap between a site that is compliant and one that is not is almost never a disagreement about principle. It is a tag that fires too early or a record nobody keeps. This is the same set of obligations rewritten as things you can check on your own site in about fifteen minutes.
Before any interaction
Load the site in a clean private window and look at client storage and the network tab before touching anything. Nothing should be written except your strictly necessary entries, and there should be no requests to analytics or advertising endpoints. If either fails, stop here: this is the requirement, and nothing further on the list can compensate for it.
The choice on offer
Refusing has to be available in the same place and with the same ease as agreeing, which in practice means a reject control on the first screen with comparable prominence to accept. Categories have to be visible without leaving the box, and nothing may be pre-selected beyond strictly necessary. Check the actual rendered page rather than the tool's configuration screen, because the two disagree more often than you would expect.
After a refusal
Refuse, then reload, and compare. The storage list should not grow and the advertising and analytics calls should not appear. Then browse to a second page, because a common defect is a banner that gates the landing page and not the rest of the site. A refusal that survives one page and not two is worse than none, because it documents a promise the site breaks a click later.
The way back
There has to be a persistent control that reopens the choice after it has been made, and it has to change the outcome. Find it, use it to withdraw, and verify that the tags stop. Withdrawal being as easy as giving is an explicit requirement and it is the most commonly missing item on otherwise decent implementations.
The record and the text
Somewhere there should be a durable record of the decision with its categories and its moment, and it should be readable by you rather than only by the banner vendor. And the text on screen has to describe what the site does today: read the category descriptions against your actual tag list, because the descriptions shipped with the tool describe a generic site and yours is not generic.
Questions people ask about cookie banner requirements
Is there an official checklist?
Not a single one, because the requirements come from several instruments and from regulator guidance rather than from one document. The tests above are derived from them and are what an audit actually looks at.
Does the banner have to name every cookie?
No, but the categories have to be honest and the recipients have to be identifiable. A by-name list on a site with a large ad stack goes stale within weeks.
How often should I check?
Whenever the tag stack changes, and on a schedule regardless, because tag stacks change without anyone telling the person who owns the banner.