Technical controls monitor third party access and activity
Giving third parties named, individually attributable accounts with logged, reviewed access is A.5.18's provisioning and review discipline applied to non-employee access rights.
Logging and reviewing what third-party accounts do gives A.5.22's monitoring requirement something concrete to review, beyond trusting that access is used as intended.
Logging and reviewing what third parties do with their attributable accounts is a direct application of the activity logging A.8.15 requires, focused on external access.
Logging and reviewing third-party account activity is a specific application of the network and system monitoring A.8.16 requires, focused on external access.