Testers found the User’s policies setting (Role changing, User management..) does not enforced immediately after an authorizer at the bank side has been approved the change. Depicted scenario; User has been changed roles from bank but that does not enforced immediately but an user is able to authorized as previous until a session is not terminate.