I love when people just add comment for pure sake of commenting. The auditing companies don't get a "cyber security expert" with 40 years of experience, but get undergrads, suit them up and sell them as experts. Because of the checklists, that without knowing anything about the context, are almost useless and generate mostly noise.
No I don't know what a VMM is but it's probably not relevant.
Auditing companies absolutely get cyber security experts. Graduates coming out of University obviously don't have the experience of that of veterans but are in a team of experts with experience in that area.
The checklists and workpapers are a way to ensure that there is a level of standardisation in the work that is being performed. If you have assessed a clients firewall or operating system as a veteran you are encouraged to replicate how you did that in a work paper or checklist to cover bases.
Big 4 auditing firms are some of the best in class when it comes to knowledge sharing. Yes sometimes a junior or a senior might miss something without the context, but that is why humans developed lips to talk through it.
I can't count the amount of times I have challenged what a junior has said, or the conclusion a junior has come to based on what a client has said based on my experience.
I was once a graduate myself and found many glaring gaps through the use of simple checklists. If that's all it takes, then the industry needs to write some of their own.
Love tools that help, eg checklists, when used right.
But over time they have a very strong tendency to become set-in-stone dogma, at which time they will create a priesthood and a very large dead zone where thinking and flexibility is no longer allowed.