ISO cert compatibility audits are very different from a proper security audit.
And weather they do anything to check if depends on which you high, many of the slightly more expensive ones have the reputation to be "fast" and "overlook most issues".
But that doesn't apply to all security audits (but most audits for ISO compatibility, like really it's bad).
Anyway see my way to long answer about the on a sibling comment.