If the company wants to risk their data like this, that's fine by me
What will stop certain users from rooting or jailbreaking, how secure are the apps that supposedly create a tunnel into protected content, et cetera? Can a 3rd party keyboard be used on top of the app that creates the tunnel and siphon off data?
The fun is about to begin... but don't blame the users for giving them the responsibility because you let trained staff go out the door to "save costs" by going this route.
(I've barely scratched the surface as to reasons why nobody should think it's "fine", but whatever...)