The controller needs to be be well positioned in accordance with data protection law, not just in his own company. In order to be able to provide evidence of compliance with legal obligations, companies are also obliged to closely scrutinise their processors when transferring data to any external service provider.
Engaging a service provider, data is passed on to external parties. A service provider not only supports your processes, but also spreads the risks of data breaches.