I don't like this argument. It's not necessarily you who has to audit your software. You can pay other people to do it. Big companies can pay for it. Your government's institutions can pay for it. If on the other hand the software is closed-source, then that's not an option. And especially for governments and for big companies Windows is a security liability.
In the case of software vendors, you have to trust the vendor.
You cannot independently verify everything. You do not have the expertise nor the bandwidth.
Edit: and if you have the software audited, are you not then trusting the auditor?