This chapter defines a common process and vocabulary for managing and implementing enterprise risk management in an organization. The process is common to all types of risks and is applied in the remaining chapters of the book. This eliminates semantic differences between chapters and topics so that the reader can focus on the substantive aspects of each type of risk and how it relates to other types of risk and enterprise risk management as a whole. The main elements of the process are establishing the context for risk management, risk assessment, risk treatment, risk monitoring, and risk review. Reasoning about probability, probabilistic reasoning, uncertainty, and likelihood, as well as the challenges of “measuring” risk, are also covered.