Yes it's an interesting point. At first I was horrified that it is so, but then the alternative is to require proof that a system is reliable, which no one could provide. It would need to be somewhere between, talking about best endeavours or something. It sounds messy however you approach it.
It is very tricky. In some industries you see things like device certification and regular external testing requirements (e.g. weights and measures) but applying that to the very fast moving world of software would be .... tricky, to put it mildly.
It would not be tricky it would just cost a little money and annoy someone who is incompetent because you would force competency on them. Open source projects by volunteers have better testing than systems like this.