They need your card pin to transfer money out of your account.
Also, there’s advanced security methods that Monzo added that you can enable, which will protect your account further, with limits you can choose above which these checks are invoked.
I’ve just tested it twice and I can log into the app using my iPhone pin. From here I can create a payment link by hiding my face, Monzo app fails to authenticate me and asks for a pin. Put in iPhone pin and link is created.
Your iPhone passcode is the same as your card pin by the sounds of it. They ought to be different (and your iPhone passcode should really be 6 digits or longer). Monzo asks for your card pin for making payments if FaceID fails. iPhone passcode is used as the fallback only for app access.