As Aleksey wrote, there is no own routing instance for the management interface and this interface works same like any other.
To reach other subnets in your management VLANs you can configure routes going out via the management interface. And you can limit the connections via the rulebase.
But if you have to physical seperate you have to use another solution...
Another option will be to use VSX (if it is supported on your appliance and you have the license). With this you can put your management completly an a seperate network and run your firewall as an virtual system with no connectivity to the management.
And additional you have on most of the larger appliances a LOM card which you could connect to the management VLAN.
But you can use the LOM port only to connect to the console of the appliance, It is not possible to have smartcenter connections to the gateway via the LOM port. Maybee this is enough for your requirements.
Wolfgang