"Then he resets the password everytime he wants to log in."
Provided nobody else has access to his email account, that isn't too insecure.
But how does he log in to his email account?
For a few annoying companies that I trade with perhaps once a year and that want me to set up an account, I admit I often do this. But then the email account I use follows good password practice.