It's a good idea. CBC without verification is vulnerable as well. An attacker can modify the IV and the value will still decrypt. It's quite easy to change a what plaintext will pop out the other side and the client will be none-the-wiser.
Depends on what kinds of data you're encrypting but if its anything to do with money or health data authenticity is a must.