Not necesary, it might be an internal system. And no selfie. For example, in Russia it probably would be illegal to send personal and biometric data abroad. But of course in the West the rules might be different and it is ok to send citizens' data to shady foreign companies.
Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.
Yes, but it might go to an internal system, and internal bank systems are protected relatively well compared to mobile apps. And you don't have to do a selfie.