You carry the liability. They run the systems.
You signed for a control you cannot watch execute. Someone else runs it, on data you will never hold, inside systems your auditors will never log into — and when the examiner arrives, the question lands on your desk, not theirs.
Three things are true at once, and all three hold wherever this problem is worth solving. You cannot inspect their systems. They cannot hand you the data — it is sensitive, or too large, and receiving it would make the exposure yours. And you cannot simply take their word for it, because their word is precisely what is in question.
This is not a diligence failure, and it is not a trust problem between decent people. Everyone in the chain is acting in good faith with the tools available. There is simply no mechanism — so the gap gets papered over with attestations, and everybody signs, and everybody hopes.
And when hoping fails, the name on the order is yours.