I mean, what's a "proper audit"?
most audits my company does are a complete smoke and mirrors sham. But they do get certifications. Is that "proper"?
I'm pretty confident that the code-quality of linux is, on average, higher than that of the windows kernel. And that is because not only do other people read and review, the programmer also knows his shit is for everyone to see. So by and large they are more ashamed to submit some stringy mess that barely works