2) If we were really investigating change-related risk, we would review checks (and requirements and specs and user documentation...) for their relevance, accuracy, precision, etc., with respect to the now-changed production code. It seems to me that rarely happens.