Coming from a background of having to deal with the highest level of PCI-DSS scrutiny, this makes total sense. It would have been soooooo much easier to just point the auditors to the managed hosting service and say, "ask them, they're the experts." Leaving myself and the other devs to just worry about software security.