Unless you are using a custom or 3rd party product, password policies can only be set at the domain level for domain accounts.
If you are using the GPMC (group pol mgmt console) as recommended, you can right click on the domain and specify which domain controller to read the policies from. If replication is functioning correctly, then the policies will all be the same. If you have had a problem with replication, the policies could be different.
This is not very common but I did just have it happen to me.
Other option could be that his user acct is somehow corrupted. Depending on how many resources he has directly assigned rights to (as opposed to group memberships) you may want to just create a new acct for him and move on. The profile (Documents and Settings) will need to be copied as well.