Security responsibilities between the company and its cloud providers are formally understood and documented
Documenting which security duties a cloud or SaaS provider covers, and which remain the company's, is A.5.19's supplier risk requirement applied to the specific case of cloud services.
The shared-responsibility policy facet documents, provider by provider, exactly which security duties are the company's, the starting point A.5.23 requires before anything else.