Hey IT Pro,
I forwarded your question to one of our DS guys and here is his reply (thanks Gregoire!)
"There is a DSRM account per domain controller (RODC included), which is a local account (in the registry, not in AD).
Note that the DSRM account, and therefore the DSRM password, is different on every domain controller, so if a hacker manages to get the DSRM password of an RODC, only this RODC is compromised."
Hope this helps.
Joey