Yes, they still need to audit and whitelist the builds of GrapheneOS. That's what "standard APIs" are - they identify a build of OS, but someone still needs to make sure it's secure.
If you don't want Google to do that for you, then the app developer has to.
If you don't want Google to do that for you, then the app developer has to.