I personally think they should just go ahead and drop their AV completely. Sure it catches things here and there but after all these years of it being absolutely awful with very little improvement, I feel like they're just wasting their time, energy and cash investment on it.
Well, first of all it's good to have a signature detection for free even for commercial purposes.
CIS is a great overall suite, I don't feel the need of a superb and heavy AV, the built-in one is enough for me, just light and basic. I always saw it as a strategic component in the product design too, I don't know why
IMO it allows to immediately/temporary block some malwares (that may bypass other layers) by signatures. In this way the delivery team can breathe during releases and fixes, covering developer's back for days/weeks to find the right solution. It would be a dream for me, as a developer.
Anyway if they really want to improve detection scores, the best way would be to collaborate with a third-part company (es: Bitdefender) to include their signatures.
But I don't feel it as a must-have, I prefer to use the AV as a simple layer.