In your fantasies. It is of course in the responsibility of the bank to check if this is virus free. I am using Linux anyway.. No autorun.exe here. Is this still a thing with Windows?
The problem isn't the bank verifying that the USB stick is clean; the problem is that the bank is distributing info in the exact same way that APTs would try to compromise an important target.
Hyperbole, but it's like a bank employee calling you from an unknown number and asking for your email password so they can make sure their communications about your mortgage application don't go to the spam folder.