If we consider that your network remains exactly as depicted on your diagram, there is probably nothing wrong with just configuring a single IPsec tunnel per ISP link on the remote site. For as long as you keep NAT-T enabled all should work just fine.
If you are not too familiar with any of this, don't worry. You can try the FortiOS built-in SD-WAN wizard that will configure it all for you. In case you need to troubleshoot the functionality afterwards, it will probably be most efficient to open a support ticket.