Social engineering was my initial suspicion as well. However, that really doesn't fit with the auditor's obstinate response. At this point an intelligent auditor should be coming clean so that this doesn't go public (and so that his company doesn't lose the contract and get further heat).
I have the same concern you do that he shouldn't need this information. Reading some of the other comments here, though, leads me to believe that there really are people who feel like this is "security". I've definitely encountered sites and password systems that require you choose drastically different passwords from any you've chosen in the past. This may be what the auditor was getting at (though in my opinion it's a weak, even counter-productive security measure)
I have the same concern you do that he shouldn't need this information. Reading some of the other comments here, though, leads me to believe that there really are people who feel like this is "security". I've definitely encountered sites and password systems that require you choose drastically different passwords from any you've chosen in the past. This may be what the auditor was getting at (though in my opinion it's a weak, even counter-productive security measure)