@GossiTheDog I was wondering, actually. Where does it say that?
Side note: I have personally seen large ISO27001-certified orgs use this exact method to e-mail sensitive info. It's security theater and checkbox compliance, mimics the practices of credit card companies, mailing cards and PINs separately. However, real-life analogies rarely work, and vice versa. If an adversary has capabilities to exfil _one_ e-mail, they could exfil _all_ e-mails.