If someone has compromised your electronic systems, they can probably solve whatever electronic recovery means you've implemented, and they can probably do so on a large scale, re-compromising all the new accounts.
Adding an in-person step makes things harder for the attackers in two ways:
1: It relies on existing ID cards, which presumably the attackers can't telekinetically change while they sit in people's pockets or something.
2: It's hard to attack at scale. Conceivably someone could make a fake ID and pose as a staff member or something, but the same person wouldn't get away with that more than a few times before someone in the office noticed that they looked familiar. And it's slow -- humans work at a finite speed, so brute-forcing 38,000 visits to an office isn't as practical as spawning a bunch of threads to attack login sessions or something.
I think despite the inconvenience, this is a sane way to respond to a compromise, if your users are local and can visit an office to pull it off.
At a major automaker who I won't name, they have an interesting way of handling password resets: They generate a new random password for you, and send half of it by SMS to the mobile phone in your employee record. Then they email the other half to your manager. Managers have instructions that when an employee calls to retrieve this (or if the manager has a moment to call the employee first), they should spend a moment in conversation first, really make sure they recognize the employee's voice and stuff, and if there's any doubt, ask them to meet at the personnel building badging office, where the administrative folk can check IDs and stuff. It works pretty well -- it would be _very_ hard to attack this system, especially at scale.