Worst-Case vs Statistical Tolerance Analysis: Choosing on Purpose
Worst-case and RSS are not two tools that compute the same thing with different precision — they answer different questions. Worst-case asks can this assembly ever fail with conforming parts? RSS asks how often will it fail in production? Choosing between them is a business and risk decision that engineers make implicitly every time they reach for a method by habit. This guide makes the choice explicit. (The mechanics and a worked example are in the stack-up guide; this article is about the decision.)
The recap in one line each
Worst-case adds tolerances: T = ΣTi — guaranteed bounds, pessimistic at scale. RSS adds variances: T = √ΣTi² — a statistical band, typically much tighter, that a small fraction of assemblies will still escape. Everything else in this article is about when the guarantee is required and when the fraction is acceptable.
When worst-case is the only honest answer
- Safety and regulatory scope. If a failed stack-up hurts someone or breaches a certification requirement, "about 3 ppm" is not an answer — it is an admission that conforming parts can still hurt someone. Brake travel, medical dosage mechanisms, crash structures: worst-case, full stop.
- You cannot verify the distributions. RSS on a process you have never measured is numerology. First articles, new suppliers, one-off tooling — if you do not know the actual spread, you do not have a statistical model, you have a hope formatted as math.
- The contributors are correlated. Features machined in one setup, cavities in one mould, parts from the same batch drift together. Correlation defeats the independence assumption at the heart of quadrature — worst-case correlation is a real outcome, not a remote one.
- The chain is short and hostile. With two or three contributors, the worst-case penalty is small and the RSS benefit is modest anyway. Do not spend statistical assumptions where arithmetic is cheap.
When statistical analysis legitimately saves money
Manufacturing cost against tolerance is not linear — it is a staircase. Moving a ±0.10 mm requirement to ±0.05 mm rarely costs 2×; it can move the feature off finish-machining and onto grinding, and tightening further forces lapping or selective assembly. Each step on that staircase is a different machine, a different cycle time and often a different supplier tier.
RSS buys room on that staircase. In a chain of n comparable contributors, RSS allocation lets each individual tolerance widen by roughly √n versus the worst-case split — six parts each get about 2.4× more tolerance for the same assembly requirement. Widening ±0.05 to ±0.12 on several features can legitimately move an entire part down a process step. That is real money, and it is why production engineering defaults to statistical methods where they are defensible.
Defensible means: independent contributors, a controlled process (Cpk data you actually looked at), distributions that are at least plausibly normal-ish, and a fallout rate someone has consciously accepted — typically the fraction of assemblies beyond a ±3σ-equivalent band.
Hybrid strategies that work
- WC shell, RSS interior. The safety-relevant loop — the one that opens the brake, unseats the seal — is verified worst-case; the non-critical loops inside the product go statistical. Most real products are exactly this, and making the boundary explicit is what design reviews are for.
- Inflated RSS for non-normal inputs. Where contributors are uniform or skewed rather than normal, a common correction multiplies the RSS band by a factor (about 1.5 for uniform distributions — the Bender/dynamic-RSS style adjustment) before calling it a 3σ-equivalent. It narrows the optimism without abandoning the method.
- Mean-shift budgeting. Processes drift; the classic convention allows about ±1.5σ of mean shift on top of the spread. Folding a shift term into the model is more honest than pretending the mean is pinned forever.
- WC on purchased parts, RSS on yours. Vendor components often arrive with datasheet limits that are true worst-case bounds — treat them as fixed extremes and analyze only your own chain statistically.
The misconceptions that burn people
- "RSS is a loosening budget." It is not free tolerance. RSS moves the risk from "impossible" to "rare" — a real number of real assemblies will fail, and that rate is a commitment, not a rounding error.
- "RSS handles everything if n is large." Independence failures do not average out; they are systematic. Correlated contributors can make the actual spread worse than worst-case predicts if the model assumed they cancel.
- "3σ means impossible." A ±3σ band still leaks roughly 0.27% of assemblies in the ideal normal case — per loop, per unit shipped. At volume, that is a queue at your door.
- "Mean-centred forever." Tool wear, thermal drift and operator differences shift means continuously. A model with no shift term is calibrated to a factory that does not exist.
- "Pick one method for the whole product." The unit of choice is the loop, not the product. Mixed methods are normal engineering.
Five questions before you trust the answer
- What does a failure of this loop cost — warranty, rework, or someone hurt?
- Do I have process data for every contributor, or am I assuming distributions?
- Are any contributors made together, from one die, batch or setup?
- What fallout rate am I accepting, and who else has signed that off?
- If the answer is marginal, which contributor's sensitivity is highest — and is tightening that one cheaper than my fallback?
The last question is where tooling earns its place. SuperNX reports per-contributor sensitivity alongside both worst-case and statistical results, so the "tighten or accept" conversation is about a ranked list of dimensions rather than a single fused number — the decision framework above applied to the actual model instead of to instinct.