The current implementation of the Password Policy Subentry is only supporting settings that are defined in the internet-draft document. Anything outside this scope, defaults to the settings of the Default Password Policy.
Password validators, password generators and password storage schemes are 3 of such properties.
An issue exists to complement the current implementation and give full flexibility : https://bugster.forgerock.org/jira/browse/OPENDJ-286.
However, a fully fledge feature is unlikely to be suitable for a patch or maintenance release.
As an intermediate solution, we could support referencing directly password validators from within the configuration by DN. Such solution is lightweight and will allow a service provide to pre-define a number of password validators, and let each tenant to select among them.