Insider threat prediction, defined as identifying users whose behaviour patterns suggest approaching malicious activity before an incident starts, offers more practical value than reactive detection in East Africa, where fraud incidents are often over within hours. This paper reviews published machine learning approaches to insider threat detection, draws a clear operational line between reactive detection and genuine pre-incident prediction, and assesses how well each approach fits the East African deployment environment given its specific infrastructure constraints. East African financial institutions, mobile money operators, and government agencies face a specific threat pattern: organised criminal groups recruiting employees to carry out targeted, time-limited fraud. This co-option pattern differs from the gradual personal escalation that published predictive models are trained to identify, which means those models may not generalise well to the regional context. The paper further identifies four structural barriers to deploying predictive models across East African organisations: partial activity log coverage, limited labelled incident data, high staff turnover that destabilises behavioural baselines, and regulatory uncertainty around employee monitoring. Based on these findings, a five-stage deployment framework is proposed, covering log infrastructure audit, user behaviour baselining, model selection, dual-threshold calibration for early warning, and operational governance. The framework is designed to be entered at any stage, so that organisations with limited resources can still achieve partial protection. The paper concludes with recommendations for ML researchers, security practitioners in East African financial and government institutions, and policymakers, identifying the design of co-option-aware threat scenarios and standardised pre-incident evaluation protocols as the most pressing research priorities.