In the absence of commitment to auditing, we study the optimal auditing contract when collusion between an agent and an auditor is possible. We show that the auditor can be totally useless if the auditor's independence can be compromised with relative ease. Even very stiff sanctions on fraud will be unable to make auditing optimal. We then derive a demand for independent external auditing. We endogenize collusion cost as the cost from the risk of future detection. We also derive a justification for the focus of the recent audit reforms on penalties on CEOs in cases of audit fraud.