Re: real question - why can't they do email with PGP ?
Because outside the geek community nobody knows what PGP is? For the matter S/MIME would be better, as banks have no issue to buy certificates, it is supported by most mail clients, unlike PGP which often need specific plug-ins.
In my country we have "certified email" (it is a governmental standard, and mandatory for some tasks) , and it's S/MIME based, not PGP, sorry.
Tracking PGP keys and their revoking is even worse than with a X.509 certificates.