We disable SA on all DB servers but still generate a random 32 character SA password that is recorded nowhere just to be safe. Except of course for the Great...
The last I knew you couldn't Audit individual actions in SQL if you used AD groups. We have resorted to a PowerShell script which reads the membership of the groups...