The problem was traced to the vas_computer_is_member function in the QAS API, that is the call that was reporting group memberships incorrectly to Privilege Manager.
This problem was caused by a known issue in the version of QAS that he was using:
Defect #635280 api: Fix an issue in an old API function that could incorrectly show a user as belonging to a group.