If it is inconvienient people will by pass it. People want higher transaction limits. Good security requires the project manager to actually think intelligently about the problem for 5 minutes. ( Collectively all the project managers in the world have never had 5 minutes of intelligent thought). NIST has only just changed their rules to explicitly dissallow password rules like a Capital, small, number, symbol and rotate your password every X days. They finally also dissallowed SMS as a 2FA. Every app wants you to have an account and password. Guess what, most apps aren't important enough for me to create a unique password for, so most people use the same password for everything. (and putting some spin on the app or website as a prefix for you password doesn't add much entropy to your password).
If I make a more secure app people will use my competitors. My app could even be easier to use but if it doesn't follow the user flow they are used to they won't use it.
I would recomend banking from home but my bank has a $2000 transfer limit on the web app and a $15000 limit on the phone app. My rent is $2500, guess which I have to use.
People are dumb. Regulations will likely make it worse as people will all use similar work arounds to make their lives easier.