Service dependencies are consistently documented and reviewed for security and availability risk
Keeping the service dependency register current, and reviewing it for single points of failure, is what stops A.5.19's supplier risk view from going stale as vendors change.
A current service dependency register is what A.5.22's review process checks against; without it there is no reliable list of what to monitor.
This process control maintains a current register of service dependencies with owner and criticality, reviewed for single points of failure, the currency A.5.9 expects.