These are the links for 9.1 - but the details on those pages still apply for 9.0
Audits in the controller are logged to a single file. No file size limit option exists for this. The absolute maximum file size will depend on the operating system/filesystem. The auditing could be disabled using the policy in the target if you prefer that these files are not generated, however this will disable audit logs in both the controller and target.
Target Audits are logged to the system log - this is either the Event Viewer in Windows, or syslog in linux. These are system-controlled, so those maximum sizes/etc are controlled by system settings.