Some obligations are not satisfied by a project. Supplier due diligence, risk reassessment, control evidence checks, and monitoring have to keep happening, and the common failure is not that they are done badly but that they stop being done at all once the person who owned them moves on. A managed service turns a recurring control into a workflow with a defined trigger, a defined output, and a record that it ran.
Outsourcing the work does not outsource the position in law. Where personal data is involved, the provider becomes a processor and Article 28(3) requires a written contract stipulating eight specific terms, from processing only on documented instructions through to making information available for audits. Those are not negotiable boilerplate; a supervisory authority will read them, and the catalogue below lists all eight.
The same logic reaches further up the chain. NIS 2 Article 21(2)(d) makes entities in scope responsible for the security of their supply chain, and ISO 27001 devotes five Annex A controls to supplier relationships, from A.5.19 through A.5.23, including the specific case of cloud services. An organisation buying a managed service is therefore also acquiring an item on its own supplier register, which its auditors and customers will ask about.
What stays inside is the decision. A provider can collect evidence, assess it against agreed criteria, maintain records, and escalate what falls outside the normal path — but accepting a risk, approving an exception, and committing budget remain management acts. A service definition that does not name who decides simply relocates the bottleneck, and exceptions accumulate quietly until an audit finds them.