This document provides an overview of enterprise risk management (ERM). It defines ERM as a process that helps companies manage risks across their entire business to increase shareholder value. The document outlines a framework for ERM with four steps: assessing risks, shaping risks through mitigation strategies, exploiting opportunities from risks, and continuously monitoring risks. It proposes a rational, analytic approach to implementing each step of ERM using techniques like risk modeling, linking risks to financial metrics, and optimizing risk mitigation investments. The goal is to help companies adopt ERM through a comprehensive yet practical process.