Recently, describing behavior of web services is becoming more and more important. This behavior can be described by business protocols representing the possible sequences of message exchanges. Since a lot of web services use access control policies to restrict the access to authorized consumers, these policies should be part of the service description. Studying the behavior of web services by analyzing their business protocol after assigning the access control policies is the main contribution of this work. Access control policies will be presented using ontology which eases policy specification and management and add some flexibility in the policy comparison. This paper introduces notions of compatibility and replaceability w.r.t. business protocols with access control policies annotations, together with the corresponding verification algorithms.