Is there any advantage in using this method over HMAC with the key stored in the HSM, without pepper or salt? It seems overly complex to me but I'm not a cryptographer.
If you go beyond peppering and also use encryption to protect the whole password database you can get additional benefits like keeping the list of usernames secret.
It can be useful as a "defense in depth" thing, but it's not a particularly meaningful improvement to practical security.