There is no feature in ASA, which can automatically police the dynamically changing ports in passive FTP, however just a few tweaks like:
++ Either apply policing on the entire ip range
++ Or you can match the entire port range to police:
hostname(config)# class-map FTP-DATA
hostname(config-cmap)# match port tcp range 1024 65535
You can also tie the ports if you have settings on your FTP server to
restrict the port usage to a certain pool. If you can do that, then you can
apply policing to those certain ports only.
Otherwise there are no other options to do it.
Hope this helps,