The maths of accessibility debt in pharma
A button component with a contrast ratio of 3.2:1 is a single fix at the source. That same button, reused across a corporate site, three brand sites, an HCP portal and a patient microsite, becomes 80 fixes. Each one retrofitted under deadline pressure. Each one reviewed. Each one re-tested.
This is the reality most pharma teams face now that Directive (EU) 2019/882, the European Accessibility Act, has been in force across all 27 EU Member States since 28 June 2025.
The design system is where accessibility either lives or dies. Not the live page. Not the launched campaign. The tokens, the components, the patterns that get copied across every asset your team produces.
Why fixing accessibility in Figma is cheaper than fixing it in production
Every accessibility issue found after launch costs more than the same issue found in the component library. More developer hours. More QA cycles. More coordination across markets, medical review and legal sign-off. The closer you get to an EAA audit date, the less room you have to make those fixes cleanly.
Fixing at the source flips the economics:
- Contrast ratios, focus states and semantic structure are corrected inside the library, before a single page is built.
- Designers work with components that already pass WCAG 2.2 AA. No guessing. No last-minute patching.
- The live audit at launch becomes a validation exercise, not a rescue operation.
The alternative is a compounding tax. Every new campaign inherits the same broken tokens. Every market adaptation drags the same bug into a new language and a new regulatory review. That is the 80-fix problem.
How to audit a pharma design system for WCAG compliance
A proper design system accessibility audit does not start with pages. It starts with tokens, then components, then patterns, then instances. The order matters because pharma design systems tend to fail in a very specific way: the same handful of shared values repeated hundreds of times.
In a Promedia design system audit conducted in March 2026, covering 1,098 nodes across three pages, the overall system score was 78/100. The accessibility dimension alone scored 33/100. The audit surfaced 132 critical findings and 57 warnings. Yet those 189 issues traced back to only four root causes. Two token changes, one to color/content/secondary and one to a Red brand token, would resolve roughly 90% of all findings, about 150 issues, and lift the system from 78 to a projected 90+/100.
That pattern is not unusual. It is the signature of a design system that was architecturally sound but had never been audited against WCAG at the token level. The architecture was solid. The problems were targeted, repeated, and fixable at the source.
A workable audit sequence looks like this:
- Extract every color, typography and spacing token and test each combination against WCAG 2.2 AA thresholds.
- Audit master components for focus states, keyboard operability, name/role/value and touch target size.
- Map every critical finding back to its root token or component, not the instance where it surfaced.
- Prioritise fixes by propagation, the change that resolves the most instances goes first.
How does a design system audit reduce EAA compliance risk
Enforcement is no longer theoretical. The first EAA lawsuits in Europe were filed in France in November 2025, and authorities in the Netherlands and Germany have confirmed enforcement activities are ramping up in 2026. Financial penalties vary sharply by Member State: fines range from €60,000 in Ireland up to roughly €900,000 in Sweden and €1,260,000 in Hungary. Authorities can also order product withdrawal or ban non-compliant services from national markets.
The precedent for severity is already on the books. Spain's Audiencia Nacional upheld a €90,000 fine against Vueling Airlines in 2024 for website accessibility failures, and imposed a six-month ban on competing for official aid. Beyond fines, EAA enforcement authorities can require public disclosure of non-compliant organisations, and in some jurisdictions competitors can pursue unfair competition claims.
For pharma, the exposure sits across a wide surface: corporate sites, HCP portals, patient support platforms, disease awareness campaigns, adverse event reporting forms. Auditing the design system reduces that surface to a single, controlled artefact. Fix the library, and every downstream asset inherits compliance. Skip the library, and every downstream asset inherits the same violation.
What happens when you audit design tokens for accessibility before launch
Token-level auditing changes the shape of the compliance conversation. Instead of a rolling backlog of page-by-page fixes, the team gets a small, ranked list of source changes. In the Promedia audit case, updating two token values would have moved the accessibility score from 33 to roughly 75+/100 without touching a single page.
That also changes how Medical, Regulatory and Legal engage. A token change is a governed, versioned decision made once. A retrofit across 80 live pages is 80 review cycles. One is a structural decision. The other is operational chaos disguised as compliance.
Running a full accessibility audit on your design system, structured to identify root causes in tokens, components and patterns before a single page is built or deployed, is now the baseline for any pharma team producing digital assets in the EU.