Why is keeping the key in .env risky when encrypting sensitive financial data — what do KMS/Vault give you?
Take the key out of .env, keep it in KMS or Vault and use envelope encryption; for national IDs and card data, prefer tokenization wherever you can.