Came across this post by accident. Bert, you're saying that the database could be accessed directly, thus bypassing logons,encryption, and the audit log?
While that is conceptually possible, a forensic analysis of the database and the audit log would reveal those inconsistencies.
That is in part why we recommend practices hold onto a backup from each month (the first one of the month), as this will allow a forensic analysis to disprove tampering if it is ever alleged.