I think this is a better aphorism than "trust, but verify".
I work in the information security assurance field, I swear that 90% of the issues I see at companies with external service providers comes back to the fact that their contract does not have anywhere enough ability to hold the service provider to task...
Get everything you need in the contract / agreement, then hope you never have to use it.