Feedback from our auditor:
For recertification the following things are interesting:
  • how many new risks have been added
  • how many of them high risk
  • which mitigations have been planned (and executed)
  • how did risk ratings change over time?
a report about these things would be very handy