ABOUT EVENSTAR ADVISORY GROUP

An Independent AI Advisory Firm for Financial Institutions

Evenstar Advisory Group is a practitioner-led AI advisory firm helping financial institutions adopt AI with confidence —
providing the governance, controls, and frameworks that turn AI into a strategic advantage backed by discipline.

Built by a Practitioner

John Humphrey, Founder of Evenstar Advisory Group

John Humphrey Jr.

Founder & Principal

John Humphrey is Vice President of Information Technology and Information Security Officer (ISO) at First Resource Bank, a $1 billion community institution. He owns the bank's AI governance program end to end, having built it from the ground up — risk classification frameworks, board-ready policy, vendor due diligence, committee oversight, board reporting, and the examiner conversations that test all of it.

He founded Evenstar Advisory Group to bring that same work to other community banks. To that end, he authored The AI Governance Handbook and its companion Toolkit — giving every community bank access to institutional-quality governance infrastructure without the six-figure consulting engagement.

Beyond First Resource Bank, John is active in community bank peer groups and industry forums, sharing governance practices, regulatory perspectives, and hard-won lessons with peers facing the same challenges. He speaks regularly on governance and cybersecurity, most recently presenting at the CAI North Gulf Coast Chapter Expo on translating cyber risk into board-level governance action.

His expertise spans information security governance, regulatory compliance, risk assessment, incident response, vendor risk management, and business continuity planning. Earlier in his career, he advised organizations across other regulated industries — insurance, wealth management, and healthcare — giving him a governance perspective that translates across regulatory regimes. He chairs First Resource Bank's IT Steering Committee, serves on its Enterprise Risk Management Committee, and directs IT examination strategy and regulatory readiness, runs penetration testing programs, and leads enterprise-scale technology transformation.

Four Principles, One Practice

What shapes every policy, template, and recommendation.

01

Built to Withstand Scrutiny

Written for the examiner's desk.

Every document is structured to demonstrate intent, oversight, and rigor when regulatory scrutiny arrives.

02

Proportionate to Scale

Sized for community-bank realities.

Programs fit the staffing, budgets, and risk profiles of community institutions under $10 billion in assets.

03

Shaped Inside the Program

Drawn from the operator's seat.

Every framework reflects real examiner conversations, real board questions, and real resource constraints.

04

Board-Ready Language

Plain words for the boardroom.

Technical AI risk translated into language directors without technology backgrounds can act on.