Rowville Consulting

Frequently Asked Questions

Clear answers about delivery, professional experience, data handling and working with a Botswana-based finance team.

Named Roles

Preparation, review, approval and backup responsibilities agreed before delivery

Clear Scope

Fees and service levels reflect volume, complexity and review requirements

6+ hrs

UK Overlap

Same-day collaboration with UK business hours

Due Diligence

DPA, SLA, transfer safeguards and control information available for review

Security & Data Compliance

Is my financial data secure when processed in Botswana?

Security depends on the systems, access model and controls agreed for the engagement. Rowville documents these before processing begins:

  • Contractual safeguards: The engagement includes a DPA and the appropriate international-transfer mechanism.
  • Approved systems: Client information is handled through the platforms and locations agreed during onboarding.
  • Access controls: Access is limited by role and supported by multi-factor authentication where required by the control schedule.
  • Due diligence: Clients can review the applicable controls, subprocessors and incident commitments before engagement.

Botswana is not currently covered by a UK or EU adequacy decision. Restricted transfers therefore require an appropriate safeguard and assessment. View our security and data-handling summary.

How do you handle HMRC and Revenue submissions securely?

Submission responsibilities are agreed during scoping:

  • Approved authority: Access is used only under valid client or agent authorisation.
  • Secure gateways: Filing portals and authentication methods approved for the engagement are used.
  • Final approval: The named authorised person approves submissions before filing.
  • Audit trail: Submission dates, references and supporting documents are retained as agreed.

UK and Irish processes are scoped separately. Rowville does not treat the two jurisdictions as interchangeable.

What happens if there's a data breach?

We have a formal Incident Response Plan aligned with GDPR requirements:

  • Client Notification: The affected client is notified without undue delay and within any shorter period agreed in the contract.
  • Containment & Investigation: Immediate action to contain the breach and investigate root cause.
  • Regulatory Support: We provide the information the client needs for its assessment and any required controller notification.
  • Full Transparency: You receive a clear report on what happened, what data was affected, and our remediation steps.

Current insurance evidence, where applicable to the engagement, is supplied during due diligence rather than asserted generically.

Still Have Questions?

Our team is ready to address any specific concerns about your business's transition to offshore accounting.

Get a Custom Quote Ask a Specific Question