The policy services node (radius server) cannot be more than 200-300ms from the administration and monitoring nodes due to database synchronization
With such high latency and such lower user count at remote office, then recommendation would be to centralize your deployment
Radius and Dot1x are much more susceptible to higher latency so the separation of the network access devices from the service node is acceptable
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/install_guide/b_ise_InstallationGuide22/b_ise_InstallationGuide22_chapter_00.html