The solution is to install FSRM role on writeable DC and let "Access-Denied Assistance Users" group replicate to RODC.
Another option is to create the "Access-Denied Assistance Users" group on writable DC and let it replicate to RODC. After the group is replicated to RODC it is possible to install FSRM on RODC.
However it is not possible to uninstall FSRM from RODC if you don't remove "Access-Denied Assistance Users" from writable DC.
Add RODC computer in member.
Power Shell
install-windowsfeature -name fs-resource-manager -includemanagementtools
File and Resource manager prior rodc