> How common is it for financial institutions to require the use of a mobile app?
In .cz, about third of banks require a smartphone app, about third allows SMS authorization at an extra fee and about third has SMS authorization free. However, this all happened in the last few years and every few months some bank announces it's moving towards the app group.
The spicy part is that most banks use the app as the only factor, not as a second factor (as it was with the SMS, where you had password for web banking + SMS authorization as a 2FA). You therefore cannot use a noname-brand Android with vendor-provided crapware, as your security depends on it. I don't know what I would do if I didn't have an employer-provided iPhone.
How do they do it? For example, there is no "authorization" app, only a full-blown mobile banking with full permissions that has the "authorization" as one of the features. Or there is no password for the web banking (wtf!), only a username which is your national identity number and therefore widely known.
The even spicier part is that many banks give you pre-approved loans which are impossible to reject, and therefore if someone hacks your account, not only they steal your balance, but even overdraw.