Why does the design business case keep losing?

Directors round a boardroom table with a set of scales at its centre, drawings pinned behind
Published

2026-01-28

Author

Nural Choudhury

Quality arguments lose because quality reads as discretionary. Map design exposure onto the Basel operational-risk taxonomy and it becomes a funded control.

You made the case. Better experience, higher conversion, improved satisfaction. The executive nodded, thanked you, and funded the platform migration instead.

Design quality is hard to sell because quality is an argument about taste, and taste has no losing side. Exposure is different. It has a register, an owner, and a line in the operating plan, and organisations are built to fund controls against it.

Which risk taxonomy should you use?

Use the one your organisation already recognises, which in most regulated firms is the Basel operational-risk event taxonomy maintained by ORX and used by more than a hundred financial institutions [6]. Inventing a private set of design risks is the most common way this approach fails, because a category the risk function does not recognise cannot be entered into the register.

Design work maps mostly onto one Level 1 category and touches two others.

Basel Level 1 event typeHow design exposure presentsControl
Execution, delivery and process managementRework, unclear handoffs, inconsistent interpretation between design and buildGoverned design system, quality gates, decision rights
Clients, products and business practicesInaccessible journeys, unclear disclosure, mis-selling through interface designAccessibility conformance, disclosure patterns, evidenced user testing
Employment practices and workplace safetyKey-person dependency, no career pathway, attrition of scarce capabilityDocumented standards, contribution model, progression framework

That mapping does more than tidy the language. It puts design exposure into a taxonomy the second line already reports on, which means somebody other than you is now carrying the number.

ORX website page titled Event Type Operational Risk Reference Taxonomy with a network graphic
ORX, Event Type Operational Risk Reference Taxonomy, live screenshot, orx.org.

Why do quality arguments fail with executives?

Because quality reads as discretionary and risk reads as mandatory. Nobody decides to ship bad design. They decline to fund the thing that would have prevented it, which produces the same outcome through a defensible-looking decision.

Quality also carries no agreed unit. When you say the experience improved, the finance director hears a claim they cannot audit, cannot compare against the other four proposals in front of them, and cannot defend if it turns out wrong. A risk claim survives all three tests, because the organisation already has machinery for recording exposure and evidencing controls.

The shift is not a rebrand. It is choosing the frame in which your evidence is admissible.

Round tower of the Bank for International Settlements rising above Basel's rooftops
Bank for International Settlements tower, Basel. Photo by Fred Romero, CC BY 2.0.

What happened when I reframed it

At a UK retail bank I was brought in to transform design operations across 52 sub-teams. The pitch already on the table was efficiency, and it had stalled: “design ops will make our teams more efficient” had earned “efficiency is nice, what is the ROI?”

I put the same programme forward as uncontrolled exposure across seven categories, with a proposed control against each. The reply changed to “show me the controls.” The investment was approved, and every deliverable we built mapped to a named risk rather than to a capability.

Nothing about the work changed. The register it was recorded in did.

The sharpest version of this I have used was at a wealth platform sitting at 40 per cent accessibility coverage, in a market with two regulators watching. What I said to the executive committee, roughly: “I can show you that as a design problem or as an audit finding. It’s the same number either way, and only one of those versions has a budget line.”

WebAIM website page titled The WebAIM Million with a lit lightbulb graphic
WebAIM, The WebAIM Million, 2026 report, live screenshot, webaim.org.

Where is the hardest evidence?

Accessibility, because it is the one design exposure that is already law and already being enforced. The European Accessibility Act has applied since 28 June 2025, its harmonised standard EN 301 549 carries WCAG conformance into that obligation [3], and UK public sector bodies are monitored against WCAG 2.2 Level AA [4].

The compliance position is getting worse rather than better. WebAIM’s 2026 survey of the top million home pages detected WCAG failures on 95.9 per cent of them, up from 94.8 per cent, reversing six consecutive years of small improvements [5]. Enforcement is rising while conformance falls, which is the precise shape of an exposure that is about to become somebody’s incident.

One caution before you use that number. It measures automatically detectable failures on home pages, so it understates real-world conformance in both directions. It is evidence of a widening gap, not an audit of your product.

Carbon Design System homepage describing it as IBM's open source design system
IBM Carbon Design System homepage, live screenshot, carbondesignsystem.com.

Do the delivery numbers hold up?

They hold up better than most design claims, because engineering has been measuring rework for two decades.

A word on the baseline everyone quotes. The 20 to 40 per cent rework range is routinely attributed to NIST’s 2002 planning report, and I could not find those figures in the report itself. What NIST did publish is that identifying and correcting defects accounted for roughly 80 per cent of development cost, and that inadequate testing infrastructure cost the US economy 59.5 billion dollars a year, of which about 22.2 billion was avoidable through earlier testing [1]. Treat the 20 to 40 per cent as industry convention rather than as a NIST finding.

The cleanest controlled evidence for a design system is smaller and better run. Sparkbox timed eight developers building the same form from scratch and then with IBM’s Carbon design system: median 4.2 hours against 2 hours, a 47 per cent reduction, with familiarisation time included in the Carbon figure [2]. Eight developers is a small sample, and it is a real experiment rather than a vendor estimate.

Against that, the results I have measured sit inside the published range rather than above it. A design system with governed handoffs at a global specialty chemicals company cut rework by 25 per cent and deployment time by 40 per cent. At that same wealth platform, conformance went from 40 to 94 per cent WCAG AA once it was funded as regulatory exposure rather than as craft.

I am not claiming these are attributable to design alone. Each sat inside a wider programme, and no control group was run.

How do you make the switch?

Rewrite each ask as an exposure with a control and a measure, then take it to the risk function before you take it to the budget holder.

Translate the ask. “We need a design system for consistency” becomes “we carry brand and execution exposure across fifteen product teams; a governed system is the control; component reuse and rework rate are the measures.”

Get it into the register. An exposure that lives only in your deck is a preference. One that lives in the operational risk register has a review date and an owner, and it gets revisited without you asking.

Report reductions rather than improvements. “Accessibility conformance moved from 40 to 94 per cent, closing a regulatory exposure” lands differently from “accessibility improved.”

There is an honest limit to this. Risk framing wins budget for the things that genuinely reduce exposure, and it is useless for the work whose value is that the product becomes better than it needed to be. That work still has to be argued for on its merits, and I have not found a way to smuggle it through a risk register.

So before your next funding conversation, one test. If your proposal were declined and the worst case arrived eighteen months later, could you point to where you recorded the exposure, and who signed the decision not to control it?

References

Grades: primary means the issuing body’s own publication; secondary means a third party reporting it; first-party means my own measurement.

  1. NIST, Planning Report 02-3: The Economic Impacts of Inadequate Infrastructure for Software Testing, 2002. Primary. The widely quoted 20 to 40 per cent rework range is not located in this report and is treated here as industry convention. https://www.nist.gov/system/files/documents/director/planning/report02-3.pdf
  2. Sparkbox, The Value of Design Systems Study: Developer Efficiency and Design Consistency. Primary, n=8. https://sparkbox.com/foundry/design_system_roi_impact_of_design_systems_business_value_carbon_design_system
  3. European Accessibility Act, Directive (EU) 2019/882, applicable from 28 June 2025, with EN 301 549 as the harmonised standard. Primary. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L0882
  4. GOV.UK, Understanding accessibility requirements for public sector bodies. Primary. https://www.gov.uk/guidance/accessibility-requirements-for-public-sector-websites-and-apps
  5. WebAIM, The WebAIM Million, 2026 annual accessibility analysis of the top one million home pages. Primary. https://webaim.org/projects/million/
  6. ORX, Operational Risk Reference Taxonomy, event types. Primary. https://orx.org/resource/event-type-operational-risk-reference-taxonomy

First-party figures in this piece, measured on engagements I led and without a control group: 52 sub-teams and the seven-category reframe at a UK retail bank; 25 per cent rework reduction and 40 per cent faster deployment at a global specialty chemicals company; accessibility conformance from 40 to 94 per cent WCAG AA at a wealth platform.