I would check first the client logs to see that it did receive the information of having the webfilter in place.
Also make sure the webfilter itself classifies the sites as this category (so it would block the selected category).
This look up will help to make sure the site in question is categorized correctly.
I do not know how the FCT does this, but I am guessing it needs to connect to FortiGuard or maybe EMS cloud to crosscheck the webfilter as it also needs to check the site against a category to block.
The client will only have the webfilter as DB and instruction list, but every single site needs to be checked against FortiGuard or EMS Cloud as there is no DB of websites on the client.