I have audit log enabled for all services at org level, but violations are still reported by Forseti in CSCC for a lot of projects and folders. I took a look at the CAI export and it seems the project level (probably folder level as well, but I didn't check), the audit_log_configs block is not present in the exported data, and I guess that's why it causes the forseti to still report violations.
(note this is not the same issue as GoogleCloudPlatform/policy-library#367). This issue might need to be solved in CAI export data or how config validator collect project/folder level audit log information.