Why don't we just stop allowing users to choose their passwords?
The main reason is that, if IT chooses the user passwords, then the users simply forget the password. Thus, the system for resetting a lost password becomes part of the default login process. In which case, you might as well having a password in the first place.
So the system could basically fall back to being OTP?