If you do it right, it won't. Many security audit companies are asked to do test audits, and I've seen security audit contracts starting with responsible disclosure of vulnerabilities. Of course, certain amount of trust is necessary so the sides have to behave in a way that is conductive to the establishment of the trust.
"We found these issues, and we can fix them all. Pay us for finding them or pay us some more for fixing them, too." sort of thing.
Why don't you see QA shops popping up like this?