I think it would be a good idea. TLS and X.509 would work better that way. Actually, both sides should have a certificate (the bank might issue a certificate to the customer).
It won't do for all circumstances (as some other comments mention), but when it is possible, it would be a good idea.