Additional factors are of course always safer, but everything is a trade-off between security and usability, and users should have control.
Funny that. The PSD2 regulations in Europe do.[0]
The downside is that they don't mandate properly secure 2FA, so we have a mishmash of SMS, time-based tokens and whatever else passes for various banks under the regulations.[ß]
0: https://www.bankinfosecurity.com/psd2-authentication-require...
ß: My UK bank requires locally generated, time-based reader/app tokens, and has done so as long as I've lived here. My Finnish bank uses SMS.
The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties. Financial institutions offering Internet-based products and services to their customers should use effective methods to authenticate the identity of customers using those products and services. The authentication techniques employed by the financial institution should be appropriate to the risks associated with those products and services. Account fraud and identity theft are frequently the result of single-factor (e.g., ID/password) authentication exploitation. Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks.