But that's exactly the point. The bank doesn't know what you've granted root. It doesn't know if you're a security researcher, or somebody installing pirated apps with spyware.
The bank can't enforce that on desktop web browsers, but at least it can on mobile.