The EU has that covered as REGULATION (EU) No 260/2012 imposes 2FA.
But for me personally, I do not trust closed-source apps from surveillance advertisers running on a Google or Apple proprietary platform, no matter how well they do the 2FA. Even if the endpoint were impenetrable, I do not trust the bank itself not to snoop -- in part because I do not trust the GDPR, which is scantly enforced and regularly disregarded to a laughable extent. And from the ecocide PoV, I refuse to throw away good hardware and support designed obsolescence. They can pry my old phone from my cold dead hands.
No, not anymore. They became app exclusive. Customers must become an Apple or Google patron, or just use the bank card. They also closed their shop doors and terminated their phone number. If you call them on their unpublished phone number, they insist: “email us” and they refuse to give any service over the phone. And their email goes through gmail (and no PGP key given). Paper letters are ignored. They also refuse manual transfers. The app is the sole means for transfers.