They delegate to a userland process for most things and apparently have had multiple audits on this driver, according to what they've said about the same thing that they run in their game Valorant.
"Multiple audits" from Gus over in QA to Bob in accounting. Despite all of their assurances I can't help but to feel that it is only a matter of time until this is exploited.
So are you accusing them of lying when they say they've had external security audits done, or are you commenting without any knowledge of the topic at hand?
I'm taking their claims with a large dose of salt.
Without external confirmation from the firms that did the audit and the details of them, you can trust riot's statements about audits no further than you can trust any of their other statements.
I did a security audit last week, which was mostly the managers writing a runbook for weaseling out way out of trouble if a data breach happened. Actually looking at overall system architecture, the specific encryption services, etc was not a popular topic.