From an Administrative Command Prompt on an affected client, run the following:
gpresult /h gpo.htm
and share the result with your favourite method or pastebin it so that we can see it.
Verify the clients are actually reporting back to WSUS properly
https://www.ajtek.ca/wsus/client-machines-not-reporting-to-wsus-properly/
Are you performing the proper WSUS maintenance including but not limited to running the Server Cleanup Wizard (SCW), declining superseded updates, running the SQL Indexing script, etc.?
https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-8-wsus-server-maintenance/