Ask the direct supplier for information that supports a decision, not an unlimited list of every subcontractor. Depending on risk, this can include named critical sub-suppliers, dependency categories, service and data locations, access roles, component or service inventories, assurance coverage, incident dependencies, continuity arrangements, and the process for notifying material changes.
ISO/IEC 27036-2 includes subcontractor transparency in supplier selection criteria, including use of subcontractors, access to the acquirer's information, personnel, changes, assurance, audit, and confidentiality. The specific contract should define which of those items apply and what the acquirer may do after an unacceptable change.
If direct visibility is unavailable, reduce the uncertainty with independent assurance, technical isolation, telemetry, tested portability, alternative sources, inventory and provenance controls, or a time-limited risk acceptance. Do not describe an unknown dependency as controlled.