In my experience, this is not always the case. Some banks treat their mobile devices as more secure than website. For example, some actions would prompt an SMS MFA (I know, I know) if initiated from the website, but go right through if initiated from the app. It makes some sense, as on the app, they have access to things like location which they can use to make a better assessment on whether a request is fraudulent.