Yes, absolutely. Every microservice where I work is architecturally scrutinized by multiple groups over things like PCI, GDPR and SOX, with major features requiring review. And then third party auditors get to review stuff occasionally. PII is radioactive and PCI data is hard siloed.
If you work at a company that deals with education or HIPAA stuff, there's going to be even more of that.
Presumably Google aren't morons or criminals.