Try this gcloud org-policies describe constraints/iam.disableCustomRoleCreation If TRUE, custom role creation is blocked.
gcloud org-policies describe constraints/iam.disableCustomRoleCreation