Why a two-step login?
I think one of the *other* things it prevents is that, and also what some banks refer to as aggregation — you give the one bank your login credentials and they go out, scrape the other site, and return the results to your login at X-so-whateverbank.com. But the Regulatory requirement would be consumer-protection driven.