During the provisioning user Active Roles service respects the maximum length for CN. The Check Policy compliance gets executed during User provisioning which checks for the maximum length and other rules. However, during the Deprovision operation, these rules will be not evaluated, which means Check Policy compliance is not getting evaluated.
During deprovision operation, user is deprovisioned first and then properties will be modified. When an user is deprovisioned the Check Policy option will not be available which is an expected behavior.
That being said, when an object is deprovisioned, Check Policy compliance is not performed, Active Roles does not check schema limits ignoring what have been imposed.