Adding a security measure knowing that it is insufficient or is relatively easily circumvented, just because, 'hey, it can't hurt!' is really dangerous.
You MUST ensure that ALL involved parties are aware that the secondary measure is a 'bonus' and CANNOT be used to consider the entire system safe.
For example, let's say someone calls the helpdesk and says: I forgot my password, but, I can answer the 2FA thing for you. Maybe the helpdesk operator makes a reasonable judgement here: That's pretty good, the party on the other end of the line sounds pretty convincing, okay, I'll reset their password for them. Whoops: Now JUST a SIM jack gets you in, whereas if there was no SIM based 2FA whatsoever, the helpdesker wouldn't have reset the password.
Another example: During a security audit, some pentester figures out that there is no rate limit on trying passwords, there are no logs or any other detection for figuring out that some system is trying a ton of passwords, and a password check is very fast (let's say no bcrypt or similar system in place either) and the server is hosted in a virtual datacenter, and it is not too difficult to spool up a (virtual) server in the same place: That would allow an attacker (because latency has now been reduced to next to nothing) to have guessed many billions of passwords over the past 6 months. The team analyses this potential leak and concludes that, due to the existence of the secondary system, there's really no need to go public or otherwise spend any further resources. However, you don't even need to be all that capable or motivated to do a targeted attack here; SIM jacking is easy enough, and getting a server under your control that is latency-wise extremely close to the target is pretty easy for, say, AWS ec2 servers. Had the 2FA not been there, this issue would have received more appropriate attention.
Generally, I advise to never add a security feature just because 'hey, can't hurt': It confuses the authentication pipeline and muddies discussion and understanding. Either a feature is adding real security, and any circumvention of said security is definitely something that should be escalated, or, it's useless and should not be added.
With that mindset, I'd prefer to just get rid of SMS based 2FA vs. keeping it around (I'd _strongly_ prefer to fix it and make it 2FA that isn't sim-jackable, for example by using TOTP protocol, but let's hypothetically posit that that's somehow not an option).