Reminds me of the famous "Our security auditor is an idiot. How do I give him the information he wants? [1]
[1] https://serverfault.com/questions/293217/our-security-audito...
Is there some part of PCI auditing requirements that is getting misinterpreted by some auditors to demand this? Though in my experience with standards like this what auditors want to see and what the standards say often have only loose overlap anyhow.
That is crazier than any old dailywtf stories, and that site felt like everyone tried to one-up each other.