You figured it out. It's trivial to include a backdoor in a large system of systems, and one placed by a remotely competent adversary will not be found.
So what's the point of a regulation that can't be enforced?
I'm asking how you expect an auditor to confirm the absence of something in a series of black boxes that a determined and skilled adversary would like to hide.
3rd party audit like everything else?