Hi @miohtama,
Thanks for sharing your thoughts.
This is the OpenZeppelin recommended checklist to follow before an audit:
I recommend everyone tests like a rockstar:
One final point, is that Trail of Bits did a 3 day security assessment which is not the same as an audit.
There is also a list of post-mortems: