I believe the requirement is from the ICO. If a laptop gets stolen your organisation gets fined. You are supposed to use FIPs 140-2 compliant encryption. You still get fined if some data gets out but less. I think a lot of places use truecrypt but its not FIPs compliant. If the user can write data to the laptop, even the internet cache you have the potential for data leakage if someone got hold of the laptop. I think that's the justification for full disk encryption.