That's kind of the entire idea behind an auditor.
Auditors work with privileged information in order to provide assurances to third-parties that the audited entity is operating in a legitimate way. Sometimes they receive a sampling of data to spot-check things, while other times their review necessitates more-broad access. Both of these approaches necessitate some level of access to what would otherwise be considered confidential information, but audits are performed with the understanding that the firm conducting the audit has as-much to lose by compromising the data privacy of a client as the client. It makes no sense for a reputable auditor to expose the information they're analyzing because it would destroy their firm's reputation, and put them out of business.
No, but there should have been. Access to personal customer data should be strictly controlled, with access being granted only to those who need it for their work, and only for as long as they need it.
I would never expect them to do that, but they should do that.
You're just creating hoops, but you're not stopping anyone.