Standard disclaimer should apply: Talk to your corporate legal counsel first.
What are you going to do when a user goes on vacation for 1-2 weeks and can no longer remember their password to boot up the system? What you going to do in a similar situation if the person is a "road warrior"?
How are you going to ensure access to the data during a legal compliance exercise (order of preservation or a subpoena for specific records)? If each user selects their own password/phrase to secure the drive, now what?
How will you handle shared workstations? Share passwords? How will you "revoke" access or force a rekeying when someone leaves the organization?
Given the current administration, let's take this assertion to the next logical level. If anything or anyone traversing a US "border" is subject to warrantless search by US agents, then all network traffic is subject to similar search. By extension, you must provide the keys necessary to effect said searches.
Sounds entirely reasonable to me.
"Take that, you hostile sons-of-bitches!" -- James Coburn, in the finale of _The_President's_Analyst_