The organisation should define criteria for when an incident, or a series of related incidents, is considered significant enough to require a new risk assessment. This ensures that the understanding of threats and vulnerabilities is updated after serious or repeated security deviations.
A process should also be in place to assess the effectiveness of corrective actions after they are implemented, and a control to ensure that the documented deviation reports are appropriately secured, especially when containing personal data.