How does auditing itself prevent a present or future attack? Auditing and what you fix during audits are reactive.
Auditing, post mortems, whatever diagnose the situation afterwards.
At the end of the day Uber can't stop a driver from kidnapping people, but it can provide documentation and gps coordinates to police.
My point is companies need reasonable records and audit policies and when _really bad stuff happens_ you call in the big guns for the arm of the law.
At some point you also need to trust staff and weigh that against mistakes and malicious intent.
In short, security remains an imperfect balance of practicality