Tesco is not a bank any more than a mobile phone operator. The banking licence and presumably the systems are operated by a real bank (RBS from memory - OK, not quite a real bank!). So it is bizarre that Tesco appear to require this but the actual guardians of the bits, RBS do not (assuming that the absence of similar stories about RBS is not merely absence of proof of this). I suspect it is an overly stringent spec issued by the app design consultant to the app developers.