One of my banks embeds their login form, which asks for a portion of your login credentials (probably secure enough in recent browsers, but still a bit yucky). My other bank requires transactions to be approved in the account management interface (either via their mobile app or by logging into their website in another tab). Other banks use one-time-password generators for their website, and reuse that system as their second factor.
as in physically getting hold of a SIM card and putting it into another phone? That's what SIM PIN codes are supposed to protect against, but nobody uses them anymore because they are disabled by default now and set to 0000. But you can still do it, every SIM has a PIN and PUK codes.
But SMS isn't 100% secure for different reasons though.