Named Roles
Preparation, review, approval and backup responsibilities agreed before delivery
Clear Scope
Fees and service levels reflect volume, complexity and review requirements
UK Overlap
Same-day collaboration with UK business hours
Due Diligence
DPA, SLA, transfer safeguards and control information available for review
Security & Data Compliance
Security depends on the systems, access model and controls agreed for the engagement. Rowville documents these before processing begins:
- Contractual safeguards: The engagement includes a DPA and the appropriate international-transfer mechanism.
- Approved systems: Client information is handled through the platforms and locations agreed during onboarding.
- Access controls: Access is limited by role and supported by multi-factor authentication where required by the control schedule.
- Due diligence: Clients can review the applicable controls, subprocessors and incident commitments before engagement.
Botswana is not currently covered by a UK or EU adequacy decision. Restricted transfers therefore require an appropriate safeguard and assessment. View our security and data-handling summary.
Submission responsibilities are agreed during scoping:
- Approved authority: Access is used only under valid client or agent authorisation.
- Secure gateways: Filing portals and authentication methods approved for the engagement are used.
- Final approval: The named authorised person approves submissions before filing.
- Audit trail: Submission dates, references and supporting documents are retained as agreed.
UK and Irish processes are scoped separately. Rowville does not treat the two jurisdictions as interchangeable.
We have a formal Incident Response Plan aligned with GDPR requirements:
- Client Notification: The affected client is notified without undue delay and within any shorter period agreed in the contract.
- Containment & Investigation: Immediate action to contain the breach and investigate root cause.
- Regulatory Support: We provide the information the client needs for its assessment and any required controller notification.
- Full Transparency: You receive a clear report on what happened, what data was affected, and our remediation steps.
Current insurance evidence, where applicable to the engagement, is supplied during due diligence rather than asserted generically.
Still Have Questions?
Our team is ready to address any specific concerns about your business's transition to offshore accounting.
