In a company I worked some time ago they had a script that:
- closed the actual audit log
- renamed it with the actual date
- compressed it
- moved to another server (nfs or automatic ftp), where security staff could take a look at it, and after some time the logs were moved to TSM and deleted from this server
- restarted the audit process to a new log file
Don't remember the options for audit, but I think man should give you what you need.