As usual with these things: What about app/server security. Simple token verification is prone to abuse (malware) and spoofing is becoming a bigger issue on mobile only platforms than ever before. Server abuse is difficult, but not impossible and since getting a banking licence usually does not verify any security measures, I'm wondering what they already did (or didn't) do. (I'm well aware of the state-of-the-art, a…
What Mondo is (from my reading) trying to do is very cool but quite ambitious. A new bank in 2016 will be a serious target for quite sophisticated attackers so they're going to have to do app/inf/ops security very well do avoid damage.
On the flip-side they have the once in a lifetime golden opportunity of a green-field deployment to actually get security baked into their systems before they're live without a load of legacy cruft holding them back.