Such audit logs are very much dependent on the integrity of the system generating them, and the vendor themselves is certainly in the best possible position to compromise that integrity.
I suppose that switching from a vendor-operated system to an independently-operated system would simplify the implementation of trusted audit logs for mitigating the remaining insider threats, though.