There is no need for sIdentity to exist at all. They should have used the industry-standard TOTP to implement 2FA.
Unfortunatly banks in general and Erste Bank in particular could not implement 2FA and online banking properly even if their life depended on it. Actually it seems to only get from bad to worse. The old online banking was functional, but they replaced it with a garbage SPA that requires Javascript to function and is a total PITA to operate. Old paper TANs were inconvenient, but they worked well, unlike the crappy photodiode-based hardware tokens that replaced them. The hardware tokens were a total usability disaster, but at least they were secure unlike the SMS-based 2FA. And now we get... this garbage.
Unless Erste Bank implements a TOTP-based authentication system (that could use *ANY* TOTP-based implementation, including ones based on HSMs or ones running on Linux workstations) they will have lost me as a customer.