Well, first of all enable an admin password in BIOS.
If you enable it on system startup, there's no way to reset the password other than opening the computer, flipping a jumper switch.
Or, you can enable passs to disallow him from BIOS, then make the first bootup system your OS (not floppy or CD, you can boot from those, get a prompt and get into the system). Then make sure that when he's in WINXP he can't use a password recovery disk.. that should be it, I don't think you can get into a system via that method.