every model spec’d & versioned · harness ✓ greenchangelog →

Writing · Buyer & leadership

January Stops Breaking Your Product: A CFO-Legible Argument

For CFOs and COOs: the specific annual cost of maintaining calculator constants in-house, framed as maintenance risk and reputational exposure.

By Worthune Staff · 2026-08-14

Every January, a class of financial product breaks. The breakage is quiet, cumulative, and preventable. This is what the ledger looks like when you name it.

Consumer financial products depend on constants that move on schedules the operating team does not set. Retirement contribution limits move each fall when the IRS publishes its cost-of-living notice (Notice 2025-67 for tax year 2026),[2] and income thresholds move with the annual inflation-adjustment revenue procedure (Rev. Proc. 2025-32).[1] Social Security benefit factors and the cost-of-living adjustment move on SSA schedules that overlap the same window. State agencies publish property-tax and unemployment-insurance figures on their own calendars. Occasionally, entire regulatory regimes are repealed — the Windfall Elimination Provision and Government Pension Offset were both repealed by the Social Security Fairness Act, signed on January 5, 2025, retroactive to January 2024.[3] Every product whose numbers depend on these constants faces a specific operational choice each cycle: catch the changes, or drift into wrong.

The category of risk

The risk is not obvious in the way most operational risks are. A payment failure produces an incident within minutes. A stale contribution limit produces a wrong recommendation on January 2 that no user reports until, at best, a support ticket weeks later or, more commonly, never. The mode of failure is slow, quiet, and cumulative. Products with more users have more instances of the failure; products with older calculators have more constants at risk of drift; products with less rigorous editorial or engineering discipline have more surfaces where a constant is embedded rather than referenced.

For a CFO looking at this from a portfolio perspective, the important property is that the risk is not zero and it is not naturally bounded. A product that avoids drift for four years is a product that maintained a specific discipline for four years; the drift was still possible in each of those years and was prevented by the ongoing cost of the discipline. The cost of the discipline is what the ledger should capture.

The specific line items

The annual cost of maintaining calculator constants in-house has five line items most finance teams do not itemize.

Engineering. Translating each cycle's IRS publications into code changes. This is engineer-hours; a reasonable planning figure runs from days to weeks per calculator per year, depending on how many constants each one embeds.

QA and test authoring. Verifying that the new constants produce the expected outputs across the calculator’s test surface. Also engineer-hours; typically a smaller line than the engineering itself, but not zero.

Compliance review. The updated calculator gets a compliance pass to confirm the new constants have not introduced disclosure or scope issues. This is compliance-hours at a loaded internal rate; the range varies with the calculator’s risk profile.

Incident risk. The expected annual cost of a correctness incident — disclosure, customer communication, remediation, reputational recovery. This is the load-bearing line item and the one most often left off. A modest expected value here, treating each customer-facing calculator as carrying a small annual probability of a correctness incident with a specific remediation cost, produces a figure that dominates the engineering and compliance lines.

Opportunity cost. The engineering capacity spent on annual updates is capacity not spent on features the product needs. This is invisible in the finance ledger and real in the product roadmap. The Two-Month Build That Became an Afternoon (/writing/two-month-build-afternoon) develops this line in more detail.

Line itemWhere it usually appearsWhere it hides
Engineering hoursEngineering budgetRolled into general velocity
QA hoursEngineering budgetRolled into general QA capacity
Compliance reviewCompliance functionAd hoc, not typically itemized
Incident riskNot itemizedThe load-bearing missing line
Opportunity costNot itemizedProduct roadmap slippage

The compounding across a portfolio

A financial-services firm with a single customer-facing calculator faces this cost at one instance. A firm with two dozen faces it at twenty-four instances, with correlation — the same October and November are the load-bearing window for most of them — HSA limits are the notable exception, arriving each spring in their own revenue procedure — and the same engineering team is often responsible. Portfolio-scale operating risk is not linear in the number of calculators; it is nonlinear because the maintenance window is a shared resource across the whole calculator surface.

The nonlinearity produces a specific failure mode. A firm with three calculators can maintain them all in the window each year with attention. A firm with twenty-three tries to and misses one or two. The misses are silent — the calculators keep producing numbers — and the operational cost is deferred until an incident surfaces the miss. This is the pattern most CFOs have not seen itemized on any budget document.

How externalization changes the ledger

Externalizing the constant layer moves the maintenance cost out of the firm and into a vendor that runs the discipline as its core product. The engineering, QA, and compliance-review lines shrink toward zero for constants; they do not shrink to zero for the calculator UI, which still requires attention when a constant changes visibly (a new age band appearing in a display, for example). The incident-risk line shrinks proportionally to the shift in responsibility; incidents can still occur, but their source is upstream, and a caller with a stored envelope can produce the specific artifact that traces the incident back to a specific version.

The opportunity-cost line converts. Engineering capacity previously spent on annual updates becomes available for other work. Whether the firm captures the recovered capacity depends on how the freed hours get allocated; a portfolio-scale externalization can free multiple engineer-quarters per year if the calculator surface is large enough.

The annual cost of maintenance is real, largely invisible, and cumulative. Externalization does not make it disappear; it moves it to a vendor whose whole business is running the discipline.

The reputational half of the ledger

A stale constant is a specific reputational exposure. Users who make decisions based on a wrong number and later discover the error do not always report it, but they generally remember. Consumer financial trust is expensive to build and cheap to lose; each incident that would have been prevented by up-to-date constants is a small withdrawal from the trust account, and the withdrawals compound at least as fast as the deposits.

This is the line the finance function is least equipped to itemize and the line executive leadership most needs to consider. Reputational damage does not appear in the P&L in the quarter it occurs. It appears in customer acquisition costs six quarters later, in retention rates two years later, in referral patterns that never fully recover. The CFO looking at this ledger is looking at a set of costs whose timing is misaligned with the fiscal reporting cycle.

The framing that holds up in an executive meeting

For an executive audience, the argument reduces to three sentences. Constants that guide customer decisions move on schedules outside the firm’s control. The firm either invests continuously to catch each move, or it drifts. Externalization converts the continuous internal investment into a vendor relationship with terms the CFO can price and terms the risk function can audit.

The choice is not obvious in every case. Firms with specialized internal financial-math capacity may capture more value by maintaining it than by externalizing. Firms without that capacity are typically paying the cost anyway, without capturing the benefit that would justify it. The ledger this piece describes is what makes the difference between the two cases visible.

A specific historical example

The WEP and GPO repeal in early 2025 is a useful case. Firms with Social Security calculators referencing those provisions faced a specific remediation project during 2025 to remove the rules from live-rule treatment. Firms whose Social Security tools externalized the underlying registry would have inherited the update from the vendor with little or no engineering effort. Firms whose tools embedded the rules faced a per-calculator rewrite, a per-article editorial pass on any content referencing WEP or GPO, and a compliance review to confirm the changes were complete.

Both approaches converged on the same end state: tools that correctly reflected post-repeal law. The paths to that state differ substantially in engineering hours. The repeal itself is not a hypothetical; it is a specific event from the recent past that CFOs and COOs at any firm with a Social Security tool can cross-reference against their own 2025 remediation cost. The ledger produces itself if the firm looks at it honestly.

Sources

  1. [1] IRS Rev. Proc. 2025-32 (TY2026 inflation adjustments). https://www.irs.gov/pub/irs-drop/rp-25-32.pdf
  2. [2] IRS Notice 2025-67 (TY2026 retirement plan cost-of-living adjustments). https://www.irs.gov/pub/irs-drop/n-25-67.pdf
  3. [3] Social Security Fairness Act, Public Law 118-273, signed January 5, 2025 (WEP and GPO repeal). https://www.congress.gov/bill/118th-congress/house-bill/82