How Agencies Run Giveaways for 10 Clients Without Losing the Audit Trail

Published on October 05, 2026
Updated October 05, 2026

The giveaway itself takes an afternoon. The problem arrives six months later, when a runner-up complains to a platform, a client's legal team asks how the winner was chosen, or a regulator wants evidence that the draw was random. If you ran one giveaway, you probably remember what you did. If your agency ran forty across ten clients that year, memory is not a record, and the person who ran the draw may have left.

An audit trail is the set of records that lets someone who was not there reconstruct exactly what happened: which rules applied, which entries were eligible, how the winner was picked, and what happened to the prize and the data afterward. This guide covers what that trail should contain, how to organise it so ten clients do not blur together, and where the legal weight sits when something goes wrong.

Why agencies carry more risk than a solo creator

When a brand runs its own giveaway, one team owns the whole process. When an agency runs it, responsibility gets split across the client, the agency, sometimes a creator, and sometimes a prize supplier. That split is exactly where records fall through.

The UK advertising regulator is direct about this. The ASA's guidance on prize draws in social media says promoters are responsible for all stages of a promotion, and that this applies whether brands or influencers run it alone or work together as joint promoters. Handing the mechanics to an agency does not hand off the accountability, which means a client who is asked for evidence will turn to you, and you will need to have it.

The ASA also spells out what evidence it expects a promoter to hold. That list includes evidence that the winner was selected randomly, evidence that the prize was actually awarded, records showing that valid entries were included, documentation of reasonable attempts to contact winners, and, where bonus entries were offered, proof that they really changed the odds. An agency that cannot produce those five things for a given giveaway has a gap, regardless of how well the giveaway itself ran.

What a regulator actually does with a missing record

The clearest example comes from an ASA ruling against a festival that ran a comment-to-win draw on Instagram. The festival said it had used an online comment picker. The ASA still upheld the complaint, because the promoter could not produce evidence that the selection was random or explain how the tool worked, and because the terms and conditions had to be requested rather than being included or linked in the post.

Two lessons sit in that single ruling. First, using a tool is not the same as being able to prove what the tool did, so the output has to be captured at the time of the draw. Second, the rules have to be reachable from the post itself, and a version of them has to be kept so you can show what applied on the day. The same guidance makes clear that picking a winner by scrolling through comments and choosing one by hand fails the independence requirement, and that staff members do not count as independent observers when a draw is run manually. A tool with a verifiable random method, plus a saved record of its output, is what closes that gap, which is the reason the mechanics behind a draw matter, as explained in this look at how comment pickers work and whether they are really random.

Other jurisdictions add their own clocks. In the ACT, a trade promotion permit holder must keep all documents relating to the lottery for at least twelve months after the result is determined, must notify winners within 21 days, and must make results available within seven days of a request. In the US, practitioners commonly advise keeping winner records for at least four years, and in states that require bonding, such as New York and Florida, a winners list may need to be filed with the authorities. These are not identical rules, which is the whole point: an agency running clients in several countries cannot rely on one retention habit.

The seven records every giveaway needs

Whatever the client or country, the same core set of records covers most of what a regulator, platform, or client will ask for. Treat these as one pack per giveaway.

The first is the rules as published, saved as the exact version that was live when the giveaway opened, with a date. If you edit rules mid-campaign, save each version and note when it changed, since many regimes restrict changes after launch.

The second is a capture of the live post: a screenshot or screen recording showing the caption, entry instructions, and the visible link or text for the rules, so you can prove what entrants saw.

The third is a snapshot of the entry pool at the close of the giveaway. For a comment-based draw, that means the comment list as it stood at the deadline, ideally exported, so a later complaint about a deleted or edited comment can be checked against what existed at the time. If you need a way to pull that list, the guide on exporting TikTok comments to Excel covers it.

The fourth is the draw settings and output. This is the filter configuration (keyword, duplicate removal, whether replies counted, number of winners and backups) together with the tool's result and any report it produces. TT Picker shows a report of the eligible comments and the selection process after a draw, which is the sort of output you want to save rather than just glance at.

The fifth is a recording of the draw itself. A short screen recording of the filters being set and the result appearing is cheap, and it covers the moments between "settings" and "output" that a static report cannot. The walkthrough on screen recording your TikTok winner pick shows how to do this cleanly.

The sixth is the winner verification and notification record: who checked the account, what they checked, when the winner was contacted, how many attempts were made, and what the outcome was, including any redraw. The guide to verifying a giveaway winner is real lists what to look at.

The seventh is the fulfilment and closure record: proof the prize was delivered, the date the winner was announced, and the date entrant data was deleted under the client's retention schedule.

Organise it so ten clients never blur together

The records are the easy part. Keeping ten clients' records separate, findable, and consistent is where agencies actually fail, so build the structure before the first giveaway rather than after the tenth.

A simple folder convention works better than a clever one. Use a single top-level folder per client, then a year, then one folder per giveaway named with a fixed pattern, such as client code, platform, month, and a short description. A giveaway folder called something like BRANDA-TT-2026-10-SPRING-LAUNCH tells anyone where they are without opening it. Inside, use the same seven numbered subfolders every time, so a colleague who has never touched the account can find the draw output in the same place.

Add one master register on top: a single sheet with a row per giveaway. Useful columns are client, giveaway ID, launch and close dates, countries covered, which rules version applied, who ran the draw, who reviewed it, the date the pack was completed, the retention end date, and the date entrant data was deleted. The register is what lets you answer "what do we hold for this client" in a minute, and it doubles as your deletion tracker when retention windows expire. A giveaway is not closed until its row is complete.

Build one repeatable process, then localise it

Ten clients do not need ten processes. They need one process with a short list of variations, and the variations should be driven by where the entrants are.

Start from standard rules rather than a blank page each time. A rules generator gets you a consistent skeleton quickly, and the giveaway rules generator is a reasonable base to adapt per client. The question of whether you need written rules at all is covered in the guide on official rules for a giveaway, and for an agency the practical answer is always yes, because the rules are the first record in the pack.

Then add a jurisdiction layer to the client's brief. A UK-facing client needs the CAP Code points covered in the guide to TikTok giveaways in the UK. A Canadian audience needs the skill-testing question step before the prize is confirmed. An Australian campaign may trigger a permit depending on prize value and state, and a US one has its own state-level thresholds. Record on the client's brief which of these apply, so the person running the draw is not guessing.

Use a two-person rule for every draw

The simplest control that holds up under scrutiny is separating the person who sets up the draw from the person who checks it. One team member configures the filters and runs the draw. A second reviews the settings against the published rules before the draw, and confirms the saved output afterward. Both initial the register row.

This does not satisfy a requirement for an independent observer if you were drawing by hand, because staff are not independent for that purpose. What it does is catch the errors that actually happen in agencies: the wrong keyword applied, duplicates left in, replies counted when the rules said they would not be, or the wrong client's video linked. Those mistakes are far more common than deliberate rigging, and a second pair of eyes catches them before a winner is announced rather than after.

Keep each client's data in its own lane

An audit trail made of entrant data is itself personal data. Usernames, comments, and winner contact details collected for one client should not sit in a shared folder alongside another client's, and they should not be reused for a different client's campaign. For UK and EU audiences, the points in the guide on what brands can legally collect from entrants apply to the pack itself: collect only what you need, hold it only as long as you need it, and delete it on the date the register says.

The tension is obvious. Regulators want records kept, and data law wants personal data deleted. The usual way through is to retain the parts that prove the process (rules, post capture, settings, the tool's report, verification notes, the fact and date of the award) for the longest period any applicable regime requires, while deleting the full entrant list sooner under the client's retention schedule. Agree that split with each client in writing at the start, since the client is usually the data controller and the agency is acting on its instructions.

Put the responsibilities in the contract

The records are only useful if everyone knows who holds them. A short section in each client agreement saves a difficult conversation later. State which party is the promoter for regulatory purposes, which party holds the master copy of the audit pack, how long it will be kept, who responds if a platform or regulator makes a request, and what is handed to the client when the engagement ends. An agency that offboards a client without handing over the pack, or without keeping its own copy for the agreed period, creates exactly the gap this guide is trying to prevent.

Running many giveaways at once

Concurrency is where the system gets tested. A few habits keep it manageable. Stagger draw days so one operator is never running two clients' draws back to back, since mixed-up links and settings usually happen in the gap between them. Name every export with the giveaway ID before it leaves the browser, not afterward. Close each pack the same day as its draw, while the details are fresh, rather than batching the paperwork at the end of the month. And assign a single owner per giveaway, so there is always one name against the register row.

If a winner does not respond or fails verification, the redraw needs its own entries in the pack: the reason, the new draw output, and the new verification note. The guide on picking a backup winner explains how to do this without it looking like you swapped the result.

A one-page checklist

Before launch: client brief states the countries covered and which rules apply, the rules version is saved, the register row is created, and a post capture is taken once it is live.

At close: the comment pool is exported or captured at the deadline, and the second person reviews the filter settings against the rules.

At the draw: the draw is run with a verifiably random method, the screen is recorded, and the tool's report and output are saved into the giveaway folder.

After the draw: the winner is verified and notified with attempts logged, any redraw is documented, the prize delivery is confirmed, and the winner announcement is saved. Announcing well is covered in the guide on how to announce a giveaway winner.

At closure: the pack is marked complete, the retention end date is set, and the entrant list is deleted on schedule.

The bottom line

A client does not hire an agency to run a giveaway and then be unable to prove it was fair. The audit trail is part of the deliverable, even if nobody asks for it in the brief. Seven records per giveaway, one folder structure, one register, a second person on every draw, and a clear split of responsibilities in the contract is not a heavy system. It is what turns ten clients' worth of giveaways from ten separate memories into ten packs that anyone on the team can open and defend.

Frequently Asked Questions

What is a giveaway audit trail?

A saved set of records showing the rules, entry pool, draw settings, result, winner checks, and prize delivery, so someone else can reconstruct what happened.

How long should an agency keep giveaway records?

It depends on the country and the client. Some regimes set minimums, such as twelve months after the result in the ACT, and US practitioners often suggest at least four years for winner records.

Does using a comment picker count as proof of a random draw?

Not by itself. The ASA upheld a complaint where a promoter said it used a comment picker but could not show how the selection was random, so save the tool's output and a recording of the draw.

Who is responsible if an agency runs the giveaway for a client?

Usually both. The ASA treats promoters as responsible for all stages and applies the same logic to joint promoters, so the contract should say who holds the records and answers requests.

Do I have to keep entrant data as part of the record?

Keep what proves the process for as long as required, but delete the full entrant list on your retention schedule, and agree that split with the client in writing.