Rules are applying within the corporate network for all devices, no matter if they are workstations, personal laptops, desktop PCs, or mobile phones. BUT, for example in my company, I am not able to plugin my personal laptop to the network, or to connect my mobile phone to the company wireless.
If your roommate is using his/her personal laptop at work, I don't believe it is infected or unsecured, because in that case, he/she would infect the whole office network and would be fired, that is for sure
What do you think this particular laptop is the issue? Did you experience any problems so far?
However, if he/she uses laptop in your home network to download inappropriate material, browse child pornography and so on, he/she could get your network infected at some point.
I am afraid you can't do much here (if you said you tried with a good approach), but to login to your router and disable the access directly on the router for his/her laptop (you can do this by filtering the access via MAC address).
But I believe you two can work things around and make a deal
