Yes, if someone were sitting on the LAN at the ISP, that could be done. I've done it already to catch an evil haxor.
With most of the Mom&Pop ISP's gone now, that kind of thing really doesn't go on much, unless the ISP itself is looking for something in particular. But you wouldn't have a random employee at the ISP doing it.
A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.