An Explainable Adaptive Hybrid Artificial Intelligence Framework for Insider Threat Detection in Financial Institutions

Financial institutions depend on trusted employees, contractors and service accounts, yet this trust creates an attack surface that conventional perimeter controls cannot observe adequately. This paper develops an Explainable Adaptive Hybrid Artificial Intelligence (EAHAI) framework for insider threat detection and for assessing whether security awareness training is reducing measurable insider-risk behaviour. The framework combines Isolation Forest filtering, bidirectional long short-term memory sequence modelling, Shapley Additive explanations, adaptive behavioural risk scoring and Zero Trust policy enforcement. A socio-technical assessment layer is added to link training inputs to observable outcomes, including knowledge gain, phishing susceptibility, policy-violation rates, reporting delay, behavioural-risk reduction and analyst-confirmed events. The paper defines the measurement scales, evaluation criteria, validation procedures and analytical techniques required for institutional replication. Because production banking telemetry and labelled insider incidents are rarely available for publication, the empirical component is presented as a transparent synthetic proof-of-concept based on CERT-style behavioural variables rather than as evidence from a real bank. In a deterministic simulation of 17,280 user-day records and 2,880 test windows, the proposed hybrid score achieved an F1-score of 0.944, ROC-AUC of 0.993 and false-alarm rate of 0.017, while producing interpretable feature attributions and training-effectiveness estimates. The study contributes a scalable, explainable and ethically governed design for insider-risk analytics, and identifies the conditions under which it should be validated before operational deployment.

Keywords: insider threat detection; explainable artificial intelligence; adaptive risk scoring; security awareness training; Zero Trust; financial cybersecurity.