Absolutely. I really like the risk you pointed out.The thing is if we treat the Quality Management System as a System then we move beyond teh quality department as the police…and we have a more effective and involved organization.
But ISO 9001 is a bit different from ISO 17025. Its annex says "The controls required for external provision can vary widely depending on the nature of the processes, products and services. The organization can apply risk-based thinking to determine the type and extent of controls appropriate to particular external providers and externally provided processes, products and services." The OP is about ISO 17025. So, this is a matter of choice, indeed.