2 - When finishing the code review, try to think holistically about what it's trying to do and whether it's doing it in the right way or not. Check the level of abstraction where the code is being added/removed and think whether it's right or not? Or whether it should be at some other level of abstraction?
3 - Any security concerns that might arise with the new code that's going in?
4 - Anything which involves a call to a network / filesystem can fail? Check if those cases have been handled properly.
5 - Are variable names, function names, class names descriptive and yet concise? Do they follow your company's coding standards?
6 - Try to think from a perspective of "single responsibility principle".
7 - For all the new flows, replay each flow in your head and try to see if it can be optimized or not? Can we make it faster? Will the code that has been added/removed degrade performance to an unacceptable degree?
8 - Always be on the lookout for logical bugs. Never assume that the coder will have done it right. Always be critical.
9 - Last, but not the least, take out proper time to do the code review and think deeply about the code that's going in.