Suppliers and third-party service providers operate or supply parts of the organisation's Asset base on its behalf โ cloud hosting, software vendors, or a sub-processor handling personal data under a Data Processing Agreement. Their own Controls (or lack thereof) become part of the organisation's own risk surface.
This is why supply-chain risk is treated as its own category of Threat in this compendium (see the failure or disruption of service providers and supply networks threat pages), and why supplier due diligence, contractual security requirements and sub-processor registers are common Controls in their own right.