Earlier quoted context omitted.
For my bank they just send a verification request to the app (or web page using your one time code book if you prefer that) to verify who you are. So basically the same process as logging into the bank and/or verifying payments.
Correct me if I misunderstood, but that sounds insecure. I imagine an attack where someone attempts to log in to your Internet bank account, and at the same time calls you and tells you that they are the bank and that they have sent you a notification on the phone to confirm this. You accept the notification on the phone and all of a sudden they're not just logged in to your Internet bank, but also on the phone with…
Basically in the app you see if the verification is for logging in, providing strong auth for some service, approving transfer of X euros from Y account to account Z, etc
In general we have had really well working online banking since the late 90s here in Finland (first versions are actually from the early 80s where you dialed directly to the bank instead of your ISP with your modem). Haven't really heard of any major security flaws ever so they do have a really good track record. This is also why the governments attempt at creating their own strong auth service failed. The banks already effectively provide that and everyone is used to using them.