Replica volumes do not inherit the host initiator group permissions on the DR side. When you promote the DR array in a failover situation (or create a clone to test the volumes for data integrity), you will need to give the appropriate initiator group(s) permission to the mounted volumes/clones. The DR hosts should have a static IQN, which is what you'd use to popular the igroup. Hence, you should be able to create the igroups in advance on the DR array so they are ready in the event of a failover. Once you promote the DR array, you can either manually add the igroup permissions to the volumes or run a script to automate this process.
Does that help at all?
You are correct that downstream replica volumes have a different target IQN to the upstream production volumes. Therefore failover will require scripting to change the target's your hosts point at. Your request, to have the same target IQN on downstream replicas, to remove the need to script has been requested before. Please can you engage your local Nimble SE who can add you to internally tracked request. Likewise for any other customers who would like the same functionality.
Just to add to Brandon's reply above, you can add the ACL to the downstream replica prior to failover, however this can only be done via the CLI not through the UI.